How BuddyWorkflow protects the confidentiality, integrity, and availability of customer and company information — including financial data accessed through Plaid.
This Information Security Policy defines the controls BuddyWorkflow uses to protect customer and company data. BuddyWorkflow is a cloud bookkeeping application that helps small businesses track income, expenses, and cash flow, and — with the customer's consent — connects their financial accounts through Plaid to import transactions.
This policy applies to all personnel, contractors, systems, and third-party services that store, process, or transmit BuddyWorkflow customer or company data, across development and production environments. Adherence is a condition of access to company systems.
The Founder & Security Lead owns this policy and is accountable for security decisions, subprocessor reviews, access approvals, and incident response. All personnel and contractors are responsible for following this policy, protecting credentials, and reporting suspected security incidents promptly to bryn@buddyworkflow.com.
Access is granted on a least-privilege, need-to-know basis, using unique individual accounts — shared logins are prohibited.
BuddyWorkflow uses Plaid to connect customer financial accounts. Bank login credentials are never received, seen, or stored by BuddyWorkflow — credential exchange occurs entirely within Plaid Link. BuddyWorkflow stores only the resulting Plaid access tokens, held server-side in encrypted configuration and used exclusively by trusted server routes to retrieve transaction data on the customer's behalf. Imported financial data is stored under the same RLS and encryption controls as all other customer data. Customers may disconnect a linked account at any time.
Core infrastructure relies on reputable, independently audited (e.g., SOC 2) subprocessors. Each vendor's security posture is reviewed before onboarding and periodically thereafter.
Authentication events, database activity, and billing webhooks are logged through the underlying managed platforms (Supabase and Stripe). Logs are reviewed when investigating suspected incidents and to support recovery.
BuddyWorkflow maintains a process to detect, contain, investigate, and remediate security incidents. The Security Lead owns incident handling. Affected customers and any required parties are notified in line with applicable legal and contractual timelines, including notification to Plaid where an incident involves data accessed through Plaid. A post-incident review captures root cause and corrective actions.
Customer data is backed up automatically by the managed database provider, with tested restore procedures. The service runs on redundant cloud infrastructure to support availability and recovery in the event of disruption.
Customers accept the Terms of Service and Privacy Policy at sign-up and explicitly authorize account connection through Plaid Link's consent flow before any financial data is retrieved. The Privacy Policy discloses what data is collected, how Plaid is used, how data is stored and protected, and how customers can request deletion. Customers may disconnect accounts and request deletion of their data at any time.
Everyone with data access is bound by confidentiality obligations and follows core security hygiene — phishing awareness, strong unique passwords stored in a password manager, and MFA on all administrative accounts. Security responsibilities are understood before access is granted.
Customer financial data is retained only for as long as the account is active and the data is needed to provide the service. Customers may disconnect linked accounts at any time, which stops further data retrieval through Plaid. On account closure or a verified deletion request, the customer's financial data — including balances, transactions, and Plaid access tokens — is deleted from production systems within 30 days, and purged from encrypted backups on the normal backup expiry cycle. Plaid access tokens are revoked at Plaid upon disconnection or deletion. Full details are in our Data Retention & Disposal Policy.
This policy is reviewed at least annually and after any material change to systems, subprocessors, or data-handling practices. Exceptions require documented approval from the Security Lead.