BuddyWorkflowBuddyWorkflow← Back home

Privacy Policy

How BuddyWorkflow collects, uses, protects, and shares your information, including financial data you connect through Plaid, and the choices you have over it.

Effective date: August 7, 2026Version: 1.0Contact: bryn@buddyworkflow.com

1. Who We Are

BuddyWorkflow ("BuddyWorkflow," "we," "us," or "our") provides a cloud bookkeeping and small-business finance application that helps you track income, expenses, and cash flow, send invoices, and, with your consent. Connect your financial accounts to import transactions. This Privacy Policy applies to our website and application (the "Service"). We are the data controller for the personal information described here.

2. Information We Collect

3. How We Use Your Information

We do not sell your personal information, and we do not use your financial data for advertising.

4. How Plaid Is Used

We use Plaid Inc. ("Plaid") to connect your financial accounts. By connecting an account you authorize Plaid, through its own consent flow, to access account and transaction information and share it with us to power BuddyWorkflow. Your use of Plaid is governed by Plaid's own privacy policy. You can disconnect a linked account at any time, which stops further data retrieval and revokes the associated access token at Plaid.

5. Meta / Facebook Data

If you choose to connect your own Meta (Facebook) Ads account, BuddyWorkflow accesses your advertising data through the Meta Marketing API using the ads_read permission. That data includes campaign and ad set details, ad spend, impressions, clicks, conversions, ROAS and other performance metrics for the ad accounts you authorize. We do not access your personal Facebook profile content, friends, messages or posts.

This data is used for one purpose only: to display your own advertising analytics inside your BuddyWorkflow dashboard, including the Marketing Analytics reports that compare ad spend against revenue in your account. We do not sell Meta data, we do not share it with third parties, and we do not use it for advertising or to build profiles.

Meta access tokens are encrypted at rest with AES-256-GCM before they are stored, the metrics we retrieve are isolated to your workspace with database row-level security, and all transfer happens over TLS.

You can disconnect your Meta account at any time in Settings, then Connections. Disconnecting revokes our permission with Meta and deletes the stored Meta data, both the access token and the advertising metrics we retrieved, immediately. Deleting your BuddyWorkflow account removes all of it as well. See our Data Deletion Instructions.

BuddyWorkflow's use of Meta data complies with the Meta Platform Terms and the Meta Developer Policies.

6. How We Share Information

We share information only with service providers ("subprocessors") that help us operate the Service, under contracts that require appropriate safeguards. We may also disclose information where required by law, to protect our rights and users' safety, or in connection with a business transfer.

SubprocessorPurpose
PlaidBank-account connectivity and transaction data
SupabaseDatabase hosting and authentication
StripeSubscription billing and payment processing
Managed hosting / CDNApplication hosting and delivery
Google WorkspaceEmail and business correspondence

7. How We Protect Your Information

We encrypt data in transit (TLS 1.2+) and at rest (AES-256), isolate each workspace's data with database row-level security, enforce least-privilege access with multi-factor authentication on administrative systems, and never store bank credentials. Full details are in our Information Security Policy.

8. Support Access to Your Account

To investigate a problem you report, or a fault we detect, a small number of authorized BuddyWorkflow staff may open a read-only support view of your workspace. This access is strictly limited: it is available only to administrators, it cannot create, change or delete anything in your account, and we never sign in as you or use your password. Every session requires a written reason, expires automatically within 60 minutes, and is recorded in an audit log that captures who accessed the account, when, and why. You are notified in the app each time it happens, naming the staff member and the reason given, and you can request the access record for your account at any time. We do not use support access for any purpose other than supporting, securing or repairing your account, or where we are legally required to.

9. Data Retention

We retain your information for as long as your account is active and as needed to provide the Service. When you disconnect an account or delete your data, we delete your financial data — including balances, transactions, and Plaid access tokens, from production systems within 30 days, and purge it from encrypted backups on the normal backup-expiry cycle. Full details are in our Data Retention & Disposal Policy.

10. Your Rights & Choices

11. Consent

You accept our Terms of Service and this Privacy Policy at sign-up, and you explicitly authorize account connection through Plaid Link's consent screen before any financial data is retrieved. You may withdraw consent by disconnecting accounts or closing your account.

12. Children's Privacy

The Service is intended for business use by adults and is not directed to children under 16. We do not knowingly collect personal information from children.

13. Changes & Contact

We may update this Privacy Policy from time to time; material changes will be communicated through the Service or by email, and the effective date above will be revised. Questions or requests? Contact us at bryn@buddyworkflow.com.

More policies
Information Security →Data Retention →Multi-Factor Authentication →Terms of Service →Data Deletion →