Privacy policy
Ledro helps a business code its card and bank transactions and send them to its accounting system. To do that we handle financial data on behalf of the business that signs up. This page says what we collect, why, who else touches it, how long we keep it, and how to get it removed.
This policy is issued by Ledro. Contact: privacy@ledro.io.
Who this covers
Our customer is a business. The people whose data we hold are that business's team members: the people who use cards, code transactions and manage the account. We process this data on the business's instructions. If you are a team member, the business you work for decides what Ledro connects and who can see it.
What we collect
- Sign-in details. Your name, email address and profile picture from Google when you sign in. We do not store passwords.
- Bank and card transactions. Date, amount, currency, merchant text, the last four digits of the card, and running balances, from statement files the business uploads or from a live bank connection the business authorises.
- Receipts. Images and PDFs of receipts that team members upload or email in, and the details we read from them.
- Accounting data. Chart of accounts, suppliers, tracking categories and bank transactions from the business's Xero organisation, and the coded lines we send back.
- What you do in Ledro. The coding choices, notes and actions you take, so the business has a record of who did what.
Live bank connections and Plaid
When a business connects a US bank account, the connection is made through Plaid Inc. Plaid collects the business's bank login on its own screens, and Ledro never sees it. Plaid then passes account and transaction data to Ledro. Plaid's handling of that data is described in the Plaid End User Privacy Policy. A business can disconnect a bank in Ledro at any time, and can manage its Plaid connections at my.plaid.com.
Why we use it
- To show each person the transactions on their card so they can code them.
- To suggest a supplier, account and job for a transaction, using AI.
- To match receipts to transactions.
- To send coded transactions to the business's accounting system.
- To keep an audit trail for the business.
- To run, secure and improve the service.
We do not sell personal or financial data, and we do not use it for advertising.
AI processing
Ledro uses large language models to read statements and receipts and to propose how a transaction should be coded. Transaction text and receipt content are sent to the model provider for that purpose only. Our providers are contracted not to train their models on this data. A person always confirms or changes a proposal before it is sent to the accounting system.
Who else sees it
We share data only with the services needed to run Ledro:
- Google Cloud hosts the service and stores the data, in the United States.
- Google for sign-in and, where the business enables it, Google Chat notifications.
- Plaid for live bank connections, as above.
- Xero, the business's accounting system, which receives the coded transactions.
- AI model providers (Google Vertex AI, Anthropic and Cerebras) for the processing described above.
- SendGrid to receive emailed receipts.
We will also disclose data if the law requires it. Otherwise nobody else gets it.
How we protect it
Data is encrypted in transit and at rest. Access is limited to the people who need it to run the service, protected by multi-factor authentication. Bank connection credentials are held by Plaid, not by Ledro. Access tokens and secrets are stored in a managed secret store, never in code.
How long we keep it
We keep data for as long as the business has an account, because it is the business's financial record. When a business closes its account, we delete its data within 30 days, except where we must keep it longer by law. When a business disconnects a bank, we stop receiving new data from it at once; the transactions already in Ledro stay with the business's records.
Your rights
You can ask to see the personal data we hold about you, to correct it, or to have it deleted. Email privacy@ledro.io and we will respond within 30 days. Where the data belongs to the business's records, we may need the business's agreement to delete it. We handle personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles. If you are in the United States, you have the rights your state law gives you, and the same email address is the way to use them.
Changes
If this policy changes in a way that matters, we will update the date at the top and tell account administrators by email.