Legal
Privacy Policy
Your books are the most sensitive thing you'll put in this product. Here is exactly what happens to them.
Last updated July 27, 2026
The short version
- We collect your email address, the bookkeeping data you choose to enter or import, and basic technical logs.
- We never sell your data, share it with advertisers, or use the contents of your books to train AI or machine-learning models.
- We never see your card details — payments go directly to Stripe.
- You can export everything at any time, and ask us to delete it.
1. Who we are
Rent The North, LLC, doing business as Lifeline Professional Services is the controller of personal information processed through Due North. Contact us at privacy@duenorthledger.com.
2. What we collect
Information you give us
- Account information: your email address, your display name if you set one, and the organizations you belong to and your role in each.
- Your bookkeeping data: accounts, transactions, amounts, dates, memos, classes, payee and customer names, imported files, bank statement lines and reconciliations. Some of this may be personal information about other people — for example a tenant or vendor name you record. You control what goes in.
- Support correspondence: what you write to us, so we can help and refer back to it.
Information collected automatically
- Technical logs: IP address, user agent, request paths and timestamps, and error diagnostics. Used to keep the Service running and to investigate abuse.
- Aggregate usage analytics: page-level traffic measured by Vercel Analytics, which is aggregate and does not use tracking cookies or build cross-site advertising profiles.
- Essential cookies: a session cookie so you stay signed in, and a small preference for your light/dark theme. There are no advertising or third-party tracking cookies.
Information we deliberately don’t collect
- Passwords — sign-in is a one-time emailed code, so there is no password for us to store or lose.
- Card numbers — Stripe collects and stores payment details directly. We receive only a customer reference, the subscription status, and the last four digits and brand for display.
- Bank credentials — statement data is imported from files you download yourself. We do not ask for online banking logins.
3. Why we use it
- To provide the Service: store your books and generate your reports.
- To authenticate you, by sending sign-in codes to your email.
- To take payment and manage subscriptions.
- To send necessary service messages — invitations, billing notices, security notices and material changes to these policies.
- To keep the Service secure, debug failures, and prevent abuse and fraud.
- To comply with legal obligations.
For anyone in the EEA or UK: our legal bases are performance of a contract (providing the Service), legitimate interests (security, debugging, preventing abuse), consent where we ask for it, and legal obligation. We do not rely on consent for essential service emails, and we do not send marketing email to customers who haven’t asked for it.
4. Who we share it with
We share data only with the service providers needed to run Due North — hosting, database, transactional email and payments. Each is listed, with what it processes and where, on the Subprocessors page. They act on our instructions and are bound by contract.
We may also disclose information where legally required, to protect someone’s safety, or to enforce our terms — and if a lawful request for your data arrives, we will notify you unless legally prohibited from doing so. If the business is ever sold or transferred, your data would move with it, and you would be told before that happened.
Other members of your organization can see the books they have access to, according to the role its owner assigned them. That is the point of a shared set of books, but it is worth stating plainly.
5. How long we keep it
We keep your account and bookkeeping data for as long as your account exists, because these are financial records you may need for years. Ask us to delete an organization’s data and we will remove it from production systems within 30 days; encrypted backups age out on a rolling schedule. Technical logs are kept for a short operational window. Payment and tax records are retained as long as law requires, by us and by Stripe.
6. Security
Data is encrypted in transit and at rest, sign-in uses expiring one-time codes rather than passwords, and access controls are enforced on the server for every request. The structural protections around your ledger — including the append-only audit log and the balance constraint — are described on our security page, along with an honest account of what we have not done, such as a SOC 2 audit. No system is perfectly secure; if we discover a breach affecting your data, we will tell you promptly and specifically.
7. Your rights
Wherever you live, you can ask us to access, correct, export or delete your personal information, and you can export your bookkeeping data yourself at any time from within the app. Email privacy@duenorthledger.com and we will respond within 30 days.
If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of. If you are in the EEA or UK, you also have the rights to object, to restrict processing, to data portability, and to complain to your supervisory authority.
8. International transfers
Due North is operated from the United States and your data is stored there. If you use it from elsewhere, you are sending your data to the United States, where privacy law differs from your own.
9. Children
Due North is not intended for anyone under 18 and we do not knowingly collect their information. If you believe a child has given us data, email us and we will delete it.
10. Changes
If we change this policy materially, we will email you and update the date above at least 30 days before the change takes effect.