PipeLedger AI

Privacy Notice

Last updated: August 11, 2026 · Version 2026-08-11 · Effective: August 11, 2026

This Privacy Notice explains how PipeLedger Inc. ("PipeLedger," "we," "us," or "our") collects, uses, discloses, and protects Personal Information when individuals visit our websites, communicate with us, create or administer an account, or use the PipeLedger service on behalf of a business or other organization.

PipeLedger is a business-to-business service. It is not offered for personal, family, or household use and is not directed to children.

1. Scope and our roles

"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household, together with analogous terms under applicable privacy law. Personal Information does not include information excluded from the applicable statutory definition.

"Customer Data" means financial records, ERP data, configurations, and other information that a customer submits to, connects to, or processes through the PipeLedger service. Customer Data may or may not contain Personal Information.

PipeLedger handles Personal Information in two different roles:

  • For account, website, billing, sales, security, and service-administration information, PipeLedger determines why and how the information is processed and generally acts as a business or controller.
  • For Customer Data processed on behalf of a customer, the customer determines why the data is processed and PipeLedger generally acts as a service provider, contractor, or processor under the customer's instructions and the applicable agreement.

If you seek to exercise rights regarding Personal Information contained in Customer Data, you should ordinarily contact the PipeLedger customer that controls that data. Where required, we assist the customer in responding to your request.

2. Personal Information we collect

Depending on your relationship with PipeLedger, we may collect the following categories:

Category Examples
Business identity and contact information Name, business email, employer, and organization
Account and authentication information User ID, organization membership, roles, permissions, login events, authentication factors, session information, and credential metadata
Commercial and subscription information Selected plan, add-ons, usage allowances, usage totals, invoices, payment status, tax information, renewal information, and billing contacts
Transaction and payment information Payment method tokens, billing address, transaction identifiers, and limited payment details supplied by our payment processor; PipeLedger does not intentionally store full payment-card numbers in its application systems
Device, network, and activity information IP address, browser and device type, operating system, user agent, timestamps, referring pages, pages or features used, request outcomes, and diagnostic information
Communications and support information Messages, support tickets, meeting notes, feedback, attachments, and information you choose to provide during support or sales interactions
Security, governance, and audit information Administrative actions, access grants, approvals, publication events, credential activity, security alerts, masking state, request identifiers, and cryptographic fingerprints
Usage and metering information Tool or feature used, request status and timing, row counts, warehouse measurements, FCU and FIQ consumption, organization-scoped credential references, and opaque request or host-session references
Customer Data ERP general-ledger and sub-ledger records, chart-of-accounts data, dimensions, budgets, user and employee information, customer and vendor information, projects, account classifications, and other data selected by the customer
Inferences and derived operational information Fraud or security signals, service-health indicators, account classifications, data-quality status, and technical or governance states produced to provide and protect the service

Some Customer Data may contain information treated as sensitive under applicable law, such as account credentials, financial-account information, employee compensation, or precise business transaction information. Customers control what they connect and must use appropriate PipeLedger governance settings and access permissions.

3. Sources of Personal Information

We collect Personal Information from:

  • you or your organization;
  • administrators and other authorized users of your organization;
  • connected ERP, identity, cloud, payment, AI-host, Business Intelligence, and other services authorized by you or your organization;
  • service providers supporting hosting, security, analytics, communications, billing, and customer support;
  • business partners and referral sources;
  • public business sources; and
  • the operation of our websites, applications, APIs, connectors, and security systems.

4. How we use Personal Information

We use Personal Information for the following purposes:

  • provide, operate, maintain, support, and improve the service;
  • create and administer accounts, organizations, roles, permissions, credentials, subscriptions, and integrations;
  • connect to authorized ERP systems and process Customer Data under customer instructions;
  • perform deterministic transformations, governance workflows, publication, delivery, reconciliation support, and related product functions;
  • meter FCU and FIQ consumption, bill subscriptions and usage, process payments, and maintain transaction evidence;
  • authenticate users, secure accounts and systems, prevent fraud or abuse, investigate incidents, and enforce our agreements;
  • respond to inquiries, support requests, feedback, and administrative requests;
  • communicate about service changes, security, billing, renewals, support, and legal terms;
  • analyze service performance and develop or improve features using information we are permitted to use;
  • comply with law, respond to lawful process, establish or defend legal claims, and protect rights and safety; and
  • carry out another purpose disclosed at collection or authorized by you or your organization.

Customer Data and AI model training

PipeLedger does not use Customer Data to train a general-purpose AI model or permit a third-party model provider to train a general-purpose model on Customer Data unless the customer expressly authorizes that use in a written agreement identifying the purpose and applicable controls.

Customer-authorized AI hosts may process data that a customer sends to them through PipeLedger. Their handling of that data is governed by the customer's agreement and settings with the host, not by this Privacy Notice.

5. How we disclose Personal Information

We may disclose Personal Information to:

  • Service providers and subprocessors that support cloud hosting and data warehousing, authentication, payment processing, abuse prevention, transactional email, error monitoring, and pipeline orchestration, as listed on our Trust & Security page;
  • Customer-authorized third parties. PipeLedger delivers governed data to AI hosts, Business Intelligence tools, and other applications only in response to requests made by the customer's authorized users or credentials, and only as permitted by the customer's configured governance and access policies;
  • Your organization and its administrators for account management, security, governance, support, billing, and compliance purposes;
  • Professional advisers such as auditors, accountants, insurers, and legal advisers who advise PipeLedger on its own business, subject to confidentiality duties; they are not given access to Customer Data;
  • Corporate transaction participants in connection with a financing, merger, acquisition, restructuring, sale of assets, or similar transaction, subject to appropriate protections; and
  • Government authorities or other parties where reasonably necessary to comply with law, legal process, enforce agreements, protect rights and safety, or investigate fraud or security incidents.

ERP connections are read-only. PipeLedger retrieves data from customer-authorized ERP providers and does not share Customer Data or Personal Information with them.

We require service providers and subprocessors handling Personal Information on our behalf to process it under contractual restrictions appropriate to their role.

6. Sale, sharing, advertising, and cookies

PipeLedger does not sell Customer Data for monetary consideration.

PipeLedger does not sell Personal Information or share Personal Information for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act.

Authentication and service-security technologies are used to provide login, session management, fraud prevention, and related functionality. PipeLedger does not use advertising cookies or cross-context behavioral advertising technologies on its websites.

7. Retention

We retain Personal Information only for as long as reasonably necessary for the purposes described in this Notice, including to provide the service, maintain security and audit evidence, comply with legal and accounting requirements, resolve disputes, and enforce agreements.

Retention is determined using the following criteria:

Information Retention criteria
Customer Data The subscription term, the post-termination period stated in the applicable agreement, backup cycles, customer deletion instructions, and legal-hold requirements
Account and organization records The account or subscription lifecycle plus the period reasonably necessary for security, support, dispute, and legal purposes
Billing, tax, and transaction records The period required by applicable tax, accounting, anti-fraud, and contract laws
Contract-acceptance and legal-version evidence The agreement term plus the period during which a claim, audit, or enforcement matter may reasonably arise
Security, governance, and audit records The period established by the applicable security and audit schedule, taking account of incident investigation, fraud prevention, contractual, and legal requirements
Support and communications The period needed to resolve the matter and support business, security, training, and legal needs
Website analytics and cookie-derived information The duration configured for the applicable tool and permitted by consent or law

When retention is no longer reasonably necessary, we delete, de-identify, or aggregate information, subject to technical limitations and legal requirements. Deletion from active systems may occur before deletion from encrypted backups. Information retained for legal, security, fraud-prevention, billing, or dispute purposes is restricted from unrelated use.

8. Security

PipeLedger uses administrative, technical, and organizational safeguards designed to protect Personal Information based on its nature and the risks of processing. These safeguards may include access controls, encryption in transit and at rest, credential protection, logging, monitoring, tenant-scoped authorization, and governance controls described in our AI Governance & Security Overview.

No internet-connected system is completely secure, error-free, or immune from unauthorized access. Customers are responsible for their users, credentials, connected services, and governance configuration.

9. Privacy rights

Depending on your location and applicable law, you may have rights regarding Personal Information, such as the right to request access, correction, deletion, or a copy, to opt out of certain processing, to withdraw consent where processing relies on consent, and to non-discriminatory treatment for exercising a privacy right.

PipeLedger account holders should submit privacy requests and appeals through the Help & Support section of the product, which records each request under a permanent reference. Individuals without a PipeLedger account may email support@pipeledger.ai with the subject line "Privacy Request" or "Privacy Appeal."

We may need to verify your identity and authority before completing a request. If your request concerns Customer Data controlled by a PipeLedger customer, identify that organization; we may direct the request to the customer or assist the customer under its instructions. You may also have the right to contact your privacy regulator.

10. International processing

PipeLedger and its service providers process information in the United States, in the data locations described on our Trust & Security page, and in other countries where our service providers operate. Where required, we use contractual or other approved safeguards for cross-border transfers.

11. Children

The service is not directed to individuals under 18, and we do not knowingly collect Personal Information directly from children through a consumer service. Customer Data may include information selected by a business customer; the customer is responsible for ensuring that its collection and instructions are lawful. Contact us if you believe a child has provided Personal Information directly to PipeLedger without appropriate authorization.

12. Changes to this Notice

We may update this Notice to reflect changes in law, technology, or our practices. We will post the updated version with a new "Last updated" date. Where required, we will provide additional notice before a material change takes effect. Historical versions are listed at /legal/versions.

13. Contact us

PipeLedger Inc. Email: support@pipeledger.ai (use the subject line "Privacy Request" for privacy matters)

Account holders may also use the Help & Support section of the product for any request.