Veridbooks
Privacy Policy
Last updated: 17 August 2026
This Privacy Policy explains how Veridbooks (the “Platform” at veridbooks.com) handles personal and business information. By using the Platform you acknowledge this policy. Individual firms (tenants) process their customers’ books on the Platform.
Google user data
Veridbooks uses Google Sign-In (OpenID Connect scopes: openid, email, profile) to authenticate firm staff and platform admins. When you sign in with Google, Veridbooks receives your Google account name, email address, and profile picture. Veridbooks uses that Google user data only to create and maintain a secure session and to match you to an authorized user record (invite, or a completed self-serve Checkout claim). Staff sign-in does not request Google Drive access.
Optional Google Drive sync (when enabled by the platform operator) uses a separate operator-configured Google account or service account to read bookkeeping source folders that have been shared with that account. Drive content is processed only for bookkeeping workflows under the firm that owns the customer workspace.
Limited use of Google user data
Veridbooks's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Veridbooks does not sell Google user data, does not use Google user data for advertising, and does not allow humans to read Google user data unless (a) we have your affirmative agreement for specific messages, (b) it is necessary for security or to comply with applicable law, or (c) use is limited to internal operations and the data has been aggregated and anonymized.
1. Who this applies to
The Platform is for authorized firm personnel (platform admins, Client admins, and Client users) and for invited end customers who use the customer portal (receipt upload, bank link, and clarify questions). Firm staff may be invited by an administrator, or a firm may create a workspace through self-serve signup when that feature is enabled (Stripe Checkout followed by Google sign-in with the same email). Customer business records are processed on behalf of the firm that owns that customer workspace.
2. Information we process
- Account data: name, email, Google account identifiers (when using Google sign-in), role, firm memberships, and customer assignments.
- Bookkeeping content: receipts, invoices, ledgers, Drive or OneDrive folder links, uploaded files, agent run outputs, chat questions/answers about the books, bank-link related data when Plaid is used, and related audit/version history.
- Usage and entitlements: counts of documents and pages processed for platform subscription allowances, agent run status, execution caps, optional AI token estimates (chat, embeddings, agent runs), and firm-chosen overage preferences (stop at allowance or invoice extras).
- Platform SaaS billing: when self-serve firm billing is enabled, Stripe processes payment methods and subscription charges. Veridbooks stores Stripe customer and subscription identifiers, plan tier, billed customer quantity, subscription status, overage mode, and amounts needed to reconcile usage - not full card numbers or CVV. Card data is handled by Stripe under Stripe’s terms and privacy policy.
- Firm→customer service invoices: optional fee records and uploaded invoice files that a firm stores for its own clients (separate from platform SaaS billing).
- Technical logs: authentication events and server logs needed to operate and secure the service.
- Public-site analytics (optional): when a platform admin enables Google Analytics, Google Ads, and/or Microsoft Clarity, those services may collect page views, clicks, scroll depth, ad conversion signals, and (for Clarity) session recordings on public marketing pages and the login page only. They are not loaded on the authenticated staff app, customer portal, or ledger screens.
3. How we use information
We use information to:
- Authenticate users and enforce role-based, firm-scoped access (invite and/or self-serve subscription claim)
- Run bookkeeping extraction, ledger editing, exports, and reports
- Power optional AI features (Ask the books, embeddings, agent parsers, OCR)
- Bill and administer the platform (subscriptions, trials, document/page allowances, overage invoice items when a firm chooses that mode, caps, and firm→customer service invoices)
- Maintain security, troubleshoot issues, and improve reliability
- Understand how visitors use public marketing pages and measure advertising (when Google Analytics, Google Ads, and/or Microsoft Clarity is configured)
4. AI and third-party processors
When AI features are enabled, prompts and relevant ledger excerpts or document text may be sent to configured model providers (for example Google Gemini, OpenAI, Anthropic, or Vertex AI) to generate answers or embeddings. Scanned pages may use on-server OCR and, if enabled by a platform admin, Google Document AI as a backup. Google Drive, Microsoft OneDrive, Plaid, and QuickBooks Online may be used when configured. Stripe processes platform subscription payments, payment methods, and related invoices when self-serve firm billing is enabled (see Stripe Privacy Policy). Optional Google Analytics, Google Ads, and Microsoft Clarity may run on public marketing pages when configured. Do not enable integrations for data you are not authorized to process with those providers.
5. Sharing
We do not sell personal information. Data may be shared with: (a) infrastructure, payment, and AI vendors acting as processors under your configuration (including Stripe for SaaS billing); (b) platform and firm personnel with appropriate roles/memberships; and (c) authorities if required by law.
6. Retention
Account and bookkeeping data are retained while the firm or customer workspace is active and as needed for audit, legal, billing, or operational purposes. Subscription and usage records may be kept as required for accounting and dispute resolution. Platform admins control suspension and user lifecycle. Contact your platform administrator for deletion requests.
7. Security
Access is gated by authentication (Google OAuth), invite or self-serve subscription provisioning, optional domain allowlists for bootstrap admins, and per-customer membership checks on server routes. Payment card data is handled by Stripe; Veridbooks does not store full card numbers. Secrets should be stored in environment or Admin settings, not committed to source control. No method of transmission or storage is perfectly secure; report suspected incidents to your platform administrator promptly.
8. Your choices
Authorized users can update profile-linked Google data via Google’s account tools. Within the Platform, firm admins manage memberships, customer access, and (when subscribed) billing preferences such as document/page overage mode on Firm → Billing, and may open Stripe’s Customer Portal to update payment methods. You may stop using the Platform by signing out; ask an admin to deactivate your account if needed. Self-serve firms may cancel or change subscription through the billing portal subject to the Terms of Use.
9. Contact
Privacy questions: contact your firm or platform administrator, or email hello@veridbooks.com for Platform hosting matters.
This policy may be updated; the “Last updated” date above will change when material revisions are published.