Legal
Privacy Policy
Last updated: June 6, 2026
This Privacy Policy explains how LedgerPass (“LedgerPass”, “we”, “us”) collects, uses, stores and shares information when you install and use the LedgerPass application (the “Service”). LedgerPass connects your Shopify store to the accounting platform you choose and syncs daily accounting summaries. By installing or using the Service, you agree to this Policy.
1. Who this policy covers
This Policy applies to merchants who install LedgerPass on a Shopify store and to the data flowing through the Service. It does not govern the accounting platforms you connect (such as COUNT, QuickBooks Online or Xero), which are operated by third parties under their own privacy policies.
2. Information we access
With your authorization through Shopify OAuth, LedgerPass reads accounting-relevant data from your Shopify store solely to compute daily accounting totals. This includes:
- Order, transaction and payment data (amounts, gateways, fees, status, timestamps)
- Tax, tip, discount, shipping and refund amounts
- Gift-card sales, redemptions and balances
- Store profile metadata (business name, currency, timezone, country)
We request only the read scopes necessary to build these totals. We do not retain identifiable customer personal information (such as customer names, emails or addresses) beyond what is incidentally required to compute and post a summary, and we do not use it for marketing.
3. Information we store
We store the following to operate the Service:
- Your Shopify access and refresh tokens, encrypted at rest
- Your shop profile (domain, business name, currency, timezone, country)
- The destination connections you create and their OAuth tokens, encrypted at rest
- The daily accounting summaries we generate and a log of sync activity
We never share your Shopify access token with any destination platform. Destination platforms receive only processed daily accounting summaries via their own authenticated APIs.
4. How we use information
We use the information described above only to:
- Compute your daily accounting summary (sales, fees, tax, tips, refunds, tenders, gift cards)
- Post journal entries to the destination platform you connect
- Display dashboards and sync history within the Service
- Maintain security, prevent duplicate processing, and debug issues
We do not sell your data, and we do not use it for advertising or for any purpose unrelated to providing the Service.
5. Sharing and sub-processors
We share data only with the infrastructure providers and destinations required to run the Service:
- The accounting platform you connect — receives the processed daily summary you ask us to post (never your Shopify token).
- Hosting & database providers — used to run the application and store the data described above under appropriate data-processing terms.
We may also disclose information if required by law or to protect the rights, safety and security of LedgerPass and its users.
6. Data retention
We retain your tokens, shop profile, connections and summaries for as long as your store has LedgerPass installed and for a short period afterward to support reinstallation and compliance. Uninstalling the app triggers deletion of your stored Shopify credentials.
7. Security
Connections are established via OAuth, and access and refresh tokens are encrypted at rest. We follow least-privilege access principles, transmit data over encrypted connections, and design our processing to avoid duplicate or unintended writes. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.
8. Shopify compliance webhooks
LedgerPass honors Shopify's mandatory compliance webhooks. When Shopify sends acustomers/data_request,customers/redact, orshop/redact request, we respond accordingly and delete or provide the relevant data. Requests with an invalid signature are rejected.
9. Your rights
Depending on your jurisdiction (including under the GDPR and CCPA), you may have the right to access, correct, export or delete personal information we hold, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We act as a data processor on behalf of the merchant for store data, and as a controller for account and operational data.
10. Cookies
LedgerPass uses a single, first-party, encrypted session cookie to keep you signed in to your dashboard. We do not use third-party advertising or tracking cookies.
11. International transfers
Your information may be processed in countries other than the one in which you reside. Where required, we rely on appropriate safeguards for such transfers.
12. Children
The Service is intended for businesses and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
14. Contact
Questions about this Policy or your data? Email hello@ledgerpass.app. See also our Terms of Service.