Privacy Policy
Last updated: July 26, 2026 · Effective: July 26, 2026
The short version: your books are yours. We don't sell your data, we don't advertise, and there is no analytics or tracking software of any kind in the Investimates app — not ours, not anyone else's. The app sets exactly one cookie, and it exists only to keep you logged in.
The long version follows, including the specific companies that touch your data and why.
1. Who we are
CoreLedgery, Inc., doing business as Investimates, is the controller of the personal information described here.
CoreLedgery, Inc.201 Mikel Ln
Yellville, AR 72687
info@investimates.io
2. Information we collect
Information you give us to have an account
- Your email address.
- A password, which we store only as a salted scrypt hash. We never store your password itself and cannot recover it — we can only help you set a new one.
- Your business profile if you fill it in: business name, address, phone, email, website, and a logo image you upload.
Business records you enter into the app
This is the bulk of what we hold, and you decide all of it:
- Bank account records — account nicknames, types, balances, and, if you use check printing, bank routing numbers and account numbers, bank name and address, and bank contact details.
- Transactions — dates, amounts, vendors, categories, projects, check numbers, payee mailing addresses, and notes.
- Clients — names, addresses, phone numbers, and email addresses of the people and businesses you bill.
- Documents — estimates, invoices, line items, bills, and your item catalog.
About routing and account numbers. If you use check printing, you're storing real bank credentials with us. We hold them so the app can print a correct check. We do not use them to move money — we can't, and we don't try to. Only your account can see them, and if you never set up check printing, we never have them at all.
Information we collect automatically
- Server logs — IP address, request time, and errors, kept to keep the Service running and secure.
- One cookie.
cl_sessionkeeps you logged in. It is HttpOnly, SameSite=Lax, sent only over HTTPS, and expires after 30 days or when you log out. It is strictly necessary to operate the Service. We set no advertising, analytics, or tracking cookies, and the app loads no third-party scripts — so there is nothing to consent to and no consent banner.
Payment information
Paid features are billed through Stripe. Your full card number never reaches our servers. Stripe handles it and gives us back an identifier, the subscription's status, and its renewal dates.
3. How we use information
We use it to:
- provide the Service — store your records, show them back to you, print your checks, build your documents;
- authenticate you and keep your account secure;
- send transactional email you asked for (login links, password resets, and — if you turn on the Email or SMS plugin — the estimates and invoices you send to your clients);
- bill you and handle subscriptions;
- respond when you contact support;
- diagnose problems, prevent abuse, and meet legal obligations.
We do not sell or rent your information, share it for cross-context behavioral advertising, use it to train machine-learning models, or read your books for any purpose other than operating the Service or responding to a support request you made.
4. Service providers
These companies process data on our behalf, only as needed to do their job:
| Provider | What it does | What it can see |
|---|---|---|
| Stripe | Subscription billing; Stripe Connect for Online Payments | Your name, email, and payment details you give it directly |
| Resend | Sends transactional and document email | Recipient address and message contents |
| Telnyx | Sends text messages | Recipient phone number and message contents |
| Cloudflare (R2) | Stores encrypted backups | Encrypted files only — contents are not readable by Cloudflare |
| Bluehost | Hosts the servers the Service runs on | Data at rest on the server, as any hosting provider would |
We may also disclose information if required by law, valid legal process, or to protect the rights, safety, or property of CoreLedgery, our customers, or the public. If we are ever part of a merger, acquisition, or sale of assets, information may transfer as part of that transaction, and this Policy will continue to apply until it is replaced with notice to you.
5. Mobile information and text messaging
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors performing supporting services, such as our messaging provider, is permitted solely to deliver messages you have requested. All other use is excluded. Text messaging originator opt-in data and consent are never shared with any third parties.
See our Messaging Policy for how opt-in, STOP, and HELP work.
6. How your data is separated and secured
- One database per account. Every customer's records live in their own separate database file, never in a shared table with other customers' rows. This is architectural, not a filter applied at query time.
- Encryption in transit. All traffic to the Service uses HTTPS.
- Encrypted backups. If you use Cloud Backup, snapshots are encrypted with AES-256-GCM before they leave our server. The key is held by us, not by Cloudflare — which is what allows us to restore your account for you. It also means we are technically able to decrypt a backup; we do that only to operate the Service.
- Passwords are stored as salted scrypt hashes, never in readable form.
- Sessions are random per-login tokens, invalidated when you log out.
No system is perfectly secure, and we don't claim otherwise. We do not currently hold SOC 2, ISO 27001, or PCI certification, and we would rather say so plainly than imply protection we haven't independently verified. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
7. How long we keep it
- Account and business data — for as long as your account is open.
- After you close your account — we keep your data for up to 30 days so you can request an export, then delete it. Deletion covers backups as well, and once deleted it cannot be recovered.
- Cloud Backup snapshots — we keep only the most recent snapshot, overwritten each time a new one is taken, plus a pre-restore copy retained for 24 hours after any restore.
- Billing records — retained as long as required for tax and accounting purposes.
- Server logs — retained for a limited period for security and troubleshooting.
8. Your choices and rights
You can, at any time:
- See and change essentially all of your data directly in the app;
- Export it — ask us and we'll provide a copy in a machine-readable format;
- Delete it — ask us to close your account and delete your data;
- Turn off Cloud Backup, Email, or SMS whenever you like.
Depending on where you live, you may have additional rights — to access, correct, delete, or port your personal information, to opt out of sale or sharing (we do neither), or to limit use of sensitive information. To exercise any of these, email info@investimates.io from your account address. We will not discriminate against you for making a request. We may need to verify your identity first.
Investimates is offered to businesses in the United States. If you access it from elsewhere, your information will be processed in the United States, where privacy laws may differ from those where you live.
9. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, email us and we will delete it.
10. Changes to this Policy
If we make a material change we will give notice by email or in-app before it takes effect. The "Last updated" date above always reflects the current version.
11. Contact
Questions, requests, or concerns about privacy:
CoreLedgery, Inc.201 Mikel Ln
Yellville, AR 72687
info@investimates.io