Privacy Policy

Effective May 31, 2026

myFINANCEdept.ai (“myFINANCEdept,” “we,” “us”) provides multi-tenant accounting and invoicing software. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to use of the myFINANCEdept.ai web application and related services (the “Service”).

1. Information we collect

Information you provide. When you register or use the Service we collect your name, email address, password (stored hashed), organization name, and any data you enter into the application — including clients, vendors, invoices, bills, transactions, journal entries, and uploaded files such as logos or check images.

Information from connected services. If you connect a bank account through Plaid, we receive the account’s name, type, last-four mask, balances, and transactions for that account. If you connect Microsoft Outlook to send invoices, we receive the OAuth tokens required to send mail on your behalf.

Operational information. We collect basic logs (IP address, browser, timestamps) needed to operate, secure, and debug the Service.

2. How we use information

We use the information you and your connected services provide to deliver the features of the Service — render your dashboard, post journal entries, send invoices, sync transactions — and to operate, secure, and improve the platform. We do not sell your personal information.

3. Plaid

When you choose to link a bank account, myFINANCEdept uses Plaid Inc. as a data processor to securely connect to your financial institution. By linking an account, you authorize Plaid to collect, use, and share, on our behalf, information about that account — including account name, type, last-four mask, balances, and transactions — and you agree to Plaid’s End User Privacy Policy.

We use Plaid only to pull the data needed to display your account in myFINANCEdept and to support reconciliation and bank-feed matching. You can disconnect a linked account at any time from the Online Banking screen; doing so calls Plaid’s removal API and deletes the imported account and its transactions from our database. Posted journal entries created from those transactions remain in your accounting ledger.

myFINANCEdept does not request or store full account numbers or routing numbers from Plaid. If you revoke access to an Item through Plaid, we delete the corresponding stored data upon receiving the revocation webhook.

4. Sharing your information

We share information only with: (a) service providers acting on our behalf — for example, hosting (AWS), bank-data aggregation (Plaid), email delivery (Microsoft Graph) — under contracts requiring confidentiality and limited use; (b) other users within your own organization, based on the role you assign them; (c) authorities when legally required.

5. Data security

We follow industry-standard practices to protect your data: TLS in transit, encryption at rest at the storage layer, per-tenant isolation in the database, scoped access controls on every API endpoint, password hashing with bcrypt, and optional multi-factor authentication. No system is perfectly secure, but we work to minimize risk and to respond promptly to incidents.

6. Data retention

We retain your account and the data you enter for as long as your organization uses the Service. When you disconnect a bank account, the connection’s account metadata and imported transactions are deleted from our database within a short period. If your organization deletes its account, we delete or anonymize your information in accordance with our standard schedule, except where retention is required by law or for legitimate business purposes such as audit logs.

7. Your rights and choices

You can update your profile and your organization’s information from the Settings page. You can disconnect bank accounts at any time. To request access, correction, or deletion of your personal information, contact us at the address below. We will respond consistent with applicable law (including the GDPR and CCPA, where they apply).

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them.

9. Changes to this policy

We may update this Privacy Policy from time to time. We’ll change the Effective Date above and, for material changes, notify account owners by email or in-app message.

10. Contact

Questions about this Privacy Policy or our handling of your data? Email privacy@myitdept.ai.