Alice Ledger

Privacy Policy

Last updated: September 1, 2026

Alice Ledger is a bookkeeping and invoicing product operated by Syntax Code Lab in Hong Kong ("Syntax Code Lab," "we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use Alice Ledger (the "Service"), with Hong Kong's Personal Data (Privacy) Ordinance ("PDPO") in view. It is a description of our practices, not a certification that we are "PDPO-compliant."

Binding acceptance of this Policy is the in-app clickwrap described in the Terms of Service, not merely visiting /privacy or signing in.

1. Scope and Roles

The PDPO uses data user for the person who controls collection, holding, processing or use of personal data.

This Policy also covers limited technical data (cookies, logs) and data about guest invoice visitors (timestamps only — see §2.D).

2. Information We Collect

A. Google Sign-In (account)

Sign-in is Google only. When you authorise Alice Ledger, we receive from Google:

We request only the Sign-In profile needed to create and secure your account (typically OpenID, email, and profile). We do not request Gmail, Drive, Calendar, or other Google Workspace content. We use this Google user data only to provide and improve sign-in and account security — not for advertising, not for sale, and not to train non-personalised AI or ML models.

B. Business and financial data

Information you enter or upload: business profile (name, address, tax references, invoice defaults), clients and vendors, invoices, bills, journals, chart of accounts, fixed assets, bank transactions you type or import, and files (receipts, logos, chops, optional W-8BEN).

This version does not connect to your bank.

C. Technical data

D. Guest invoice page

If you send an invoice email, the recipient opens a private link (/i/{token}). We record only timestamps (opened / PDF downloaded) for you to see in the Service — not the guest's IP, device, or location.

3. How We Use Information

We do not sell personal data. We do not use business or financial data to serve advertising. Google user data is limited to the Sign-In uses in §2.A.

4. PDPO Data Protection Principles (how we approach them)

We aim to collect only what is reasonably needed for the purposes above (data minimisation) and not to use it for unrelated purposes without a basis the PDPO allows.

Typical purposes:

5. Sub-processors and sharing

We do not sell your data. We use:

ProviderRoleData involved
Supabase (Supabase Pte. Ltd. / related entities)Database, Auth, file storageAccount and business data stored in the Service
Vercel (Vercel Inc.)Application hostingRequest metadata and aggregated usage and performance statistics (such as page views, referrer, device and browser type, general location, and site speed). Cookieless; not used for advertising or cross-site tracking. Sensitive URL paths (for example guest-invoice links) are excluded from page-view recording.
Google (Google LLC)Sign-InProfile data during sign-in (Google's terms also apply to your Google Account)
Resend (Plus Five Five, Inc.)Transactional emailRecipient email and the minimum content needed to send the message

Each publishes customer terms and, in most cases, a data-processing addendum that takes effect when we use their product (we do not countersign a separate paper DPA for each). Vercel's DPA is written for Pro and Enterprise plans — if our hosting plan does not include it, we will not claim a Vercel DPA is in force. Confirm current documents: Supabase DPA, Vercel DPA, Resend DPA. Google Sign-In is governed by Google's API terms and API Services User Data Policy; the Cloud Data Processing Addendum applies to Google Cloud products we subscribe to, not automatically to Sign-In profile sharing.

Invoice emails through Resend carry invoice number, amount due, due date, and a link to a time-limited guest page (90-day token). They do not embed the PDF, line items, or FPS/bank details.

We may add or change sub-processors; we will update this section and, for material changes, notify you.

We may disclose information if required by law or to protect the Service, users, or the public from serious harm.

6. Data Retention

7. Export and deletion

Closing does not delete your Google Account.

8. Data Security

Practices we apply (not a guarantee that a breach cannot occur):

See the Terms §12 on residual risk and backups.

9. Storage outside Hong Kong

Supabase, Vercel, Google, and Resend may process or store data outside Hong Kong (including the United States and other regions they operate in). We rely on our providers' published terms, security documentation, and (where they apply to our plan) data-processing addenda.

10. Your rights under the PDPO

Subject to the Ordinance and to IRO retention:

Contact privacy@aliceledger.com. You may also complain to the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD).

11. Cookies and site metrics

Strictly necessary cookies and similar storage keep the Service running: sign-in session (Google Sign-In), your UI language, language on a guest invoice page, and your signed-in Look preference. Light and dark appearance follows the device (and a session toggle) and is not stored as a cookie.

We may also collect aggregated, cookieless site-usage and performance statistics through our hosting provider (see §5). We do not use advertising or cross-site tracking cookies.

12. Children

The Service is for adults acting for a business. It is not directed at children, and we do not knowingly collect personal data from children.

13. Changes

We may update this Policy. Material changes: email and/or in-app notice, then a fresh clickwrap. Operational banners (for example maintenance) are not a change to this Policy.

14. Contact

Syntax Code Lab, Hong Kong.