Privacy Policy
Last updated: September 1, 2026
Alice Ledger is a bookkeeping and invoicing product operated by Syntax Code Lab in Hong Kong ("Syntax Code Lab," "we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use Alice Ledger (the "Service"), with Hong Kong's Personal Data (Privacy) Ordinance ("PDPO") in view. It is a description of our practices, not a certification that we are "PDPO-compliant."
Binding acceptance of this Policy is the in-app clickwrap described in the Terms of Service, not merely visiting /privacy or signing in.
1. Scope and Roles
The PDPO uses data user for the person who controls collection, holding, processing or use of personal data.
- Your account information (name, email, and Google profile picture from Google Sign-In) — we are the data user, because we decide how that data is used to operate and secure the Service.
- Business and financial data you enter (clients, vendors, invoices, journals, bank files, receipts, and similar) — you are the data user and we process it on your instructions to provide the Service. See the Terms §5.
This Policy also covers limited technical data (cookies, logs) and data about guest invoice visitors (timestamps only — see §2.D).
2. Information We Collect
A. Google Sign-In (account)
Sign-in is Google only. When you authorise Alice Ledger, we receive from Google:
- Your name
- Your email address
- Your profile picture (if Google provides one)
We request only the Sign-In profile needed to create and secure your account (typically OpenID, email, and profile). We do not request Gmail, Drive, Calendar, or other Google Workspace content. We use this Google user data only to provide and improve sign-in and account security — not for advertising, not for sale, and not to train non-personalised AI or ML models.
B. Business and financial data
Information you enter or upload: business profile (name, address, tax references, invoice defaults), clients and vendors, invoices, bills, journals, chart of accounts, fixed assets, bank transactions you type or import, and files (receipts, logos, chops, optional W-8BEN).
This version does not connect to your bank.
C. Technical data
- IP address and session/authentication tokens
- Device and browser information in logs and error reports
- Aggregated usage and performance statistics (see §5)
- Cookies and similar storage listed in §11
D. Guest invoice page
If you send an invoice email, the recipient opens a private link (/i/{token}). We record only timestamps (opened / PDF downloaded) for you to see in the Service — not the guest's IP, device, or location.
3. How We Use Information
- Create and secure your account and workspace
- Provide invoicing, bookkeeping, tax working papers, and reporting
- Send transactional messages (invoice links, security notices)
- Diagnose faults and prevent abuse
- Operate and improve the Service (see §5)
- Enforce the Terms
We do not sell personal data. We do not use business or financial data to serve advertising. Google user data is limited to the Sign-In uses in §2.A.
4. PDPO Data Protection Principles (how we approach them)
We aim to collect only what is reasonably needed for the purposes above (data minimisation) and not to use it for unrelated purposes without a basis the PDPO allows.
Typical purposes:
- Providing the Service you asked for — account, workspace, invoicing, books.
- Security and fraud prevention — proportionate to protecting the Service and other users.
- Service operation and improvement — aggregated usage and performance metrics to run and improve the Service, not for advertising or cross-site profiling.
- While the workspace is open: posted, paid, or sent records stay on our systems (the app only soft-deletes them) so you have a trail. After you close the workspace: we delete that workspace as described in §6. We do not keep your ledgers as a 7-year archive. IRO s.51C record-keeping stays your duty.
5. Sub-processors and sharing
We do not sell your data. We use:
| Provider | Role | Data involved |
|---|---|---|
| Supabase (Supabase Pte. Ltd. / related entities) | Database, Auth, file storage | Account and business data stored in the Service |
| Vercel (Vercel Inc.) | Application hosting | Request metadata and aggregated usage and performance statistics (such as page views, referrer, device and browser type, general location, and site speed). Cookieless; not used for advertising or cross-site tracking. Sensitive URL paths (for example guest-invoice links) are excluded from page-view recording. |
| Google (Google LLC) | Sign-In | Profile data during sign-in (Google's terms also apply to your Google Account) |
| Resend (Plus Five Five, Inc.) | Transactional email | Recipient email and the minimum content needed to send the message |
Each publishes customer terms and, in most cases, a data-processing addendum that takes effect when we use their product (we do not countersign a separate paper DPA for each). Vercel's DPA is written for Pro and Enterprise plans — if our hosting plan does not include it, we will not claim a Vercel DPA is in force. Confirm current documents: Supabase DPA, Vercel DPA, Resend DPA. Google Sign-In is governed by Google's API terms and API Services User Data Policy; the Cloud Data Processing Addendum applies to Google Cloud products we subscribe to, not automatically to Sign-In profile sharing.
Invoice emails through Resend carry invoice number, amount due, due date, and a link to a time-limited guest page (90-day token). They do not embed the PDF, line items, or FPS/bank details.
We may add or change sub-processors; we will update this section and, for material changes, notify you.
We may disclose information if required by law or to protect the Service, users, or the public from serious harm.
6. Data Retention
- While the workspace is open: posted, paid, or sent records are soft-deleted in the app (IRO s.51C trail). They stay on our systems until you close.
- After you close the workspace: we delete the workspace (books, files in our storage, memberships) so we are not your 7-year archive. IRO s.51C is your duty. You must download the ZIP takeout we require at close and keep whatever else the law requires.
- Anti-abuse after close: we keep a hashed Business Registration Number and a hashed Google email, plus the date the 90-day wait ends — not your ledgers — so the same BRN and account cannot open a new workspace during that period.
- Unposted drafts: deleted with the workspace, or when you delete them in the app.
- Google Sign-In / account data: kept while the workspace is open. After close we delete the Auth user record (name, email, picture as stored by Sign-In). Clickwrap rows for that user are removed with the user.
- Guest invoice tokens: die with the workspace; otherwise they expire after 90 days.
- Technical/log data and aggregated site statistics: kept for a limited period (typically up to 90 days unless needed longer for security investigation), then deleted or anonymised. Aggregated statistics do not include your ledger or invoice content.
7. Export and deletion
- Export: Reports → audit export (posted/reversed journals and invoices in a date range, JSON and CSV). Close requires a ZIP takeout from Settings first (every tenant table we store, Excel CSVs, and files already in storage — including generated invoice PDFs). We do not mint missing PDFs at close. Bank CSV import files are not stored. Google Account data is not in the ZIP.
- Deletion / close workspace: Settings. That deletes books and Sign-In data as in §6. You may also email privacy@aliceledger.com. We will respond within a reasonable time. We cannot restore deleted books.
Closing does not delete your Google Account.
8. Data Security
Practices we apply (not a guarantee that a breach cannot occur):
- Tenant isolation: every finance query is scoped to your workspace via your membership. Row-level security policies exist in the database as defence in depth; the application also enforces membership on every action.
- Encryption: in transit (HTTPS/TLS) and at rest using our infrastructure providers' encryption.
- Access: production administrative access is limited; sensitive mutations are recorded in an audit log where the product already does so.
- Storage: uploaded documents sit in a private bucket, not a public one.
See the Terms §12 on residual risk and backups.
9. Storage outside Hong Kong
Supabase, Vercel, Google, and Resend may process or store data outside Hong Kong (including the United States and other regions they operate in). We rely on our providers' published terms, security documentation, and (where they apply to our plan) data-processing addenda.
10. Your rights under the PDPO
Subject to the Ordinance and to IRO retention:
- Access personal data we hold about you as data user of account data, and (for books data) as processor on your instructions you already see in the app;
- Request correction of inaccurate personal data;
- Request we stop using personal data for a particular purpose, where the PDPO gives that right;
- Export as in §7;
- Close the workspace as in §7.
Contact privacy@aliceledger.com. You may also complain to the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD).
11. Cookies and site metrics
Strictly necessary cookies and similar storage keep the Service running: sign-in session (Google Sign-In), your UI language, language on a guest invoice page, and your signed-in Look preference. Light and dark appearance follows the device (and a session toggle) and is not stored as a cookie.
We may also collect aggregated, cookieless site-usage and performance statistics through our hosting provider (see §5). We do not use advertising or cross-site tracking cookies.
12. Children
The Service is for adults acting for a business. It is not directed at children, and we do not knowingly collect personal data from children.
13. Changes
We may update this Policy. Material changes: email and/or in-app notice, then a fresh clickwrap. Operational banners (for example maintenance) are not a change to this Policy.
14. Contact
Syntax Code Lab, Hong Kong.
- Privacy: privacy@aliceledger.com
- Legal: compliance@aliceledger.com