Ledger

Ledger ยท Privacy

Privacy policy

Last updated: 9 September 2026

This policy describes how Hayo Telecom, Inc. (“Hayo”) handles information through Ledger, its private QuickBooks Online review workspace, and this information site. It applies to Ledger rather than every Hayo product or service.

Information we process

When an authorized user connects a QuickBooks company, Ledger receives company identity, account and vendor references, supported accounting transactions and requested reports. Records may include names, contact details, descriptions, dates, amounts, currencies and accounting identifiers. Ledger stores original provider records as well as the fields shown in its review interface, so an imported record may contain additional information supplied by QuickBooks.

Ledger also processes connection credentials and tokens, sign-in information, review assignments, grouping rules, approvals, reviewer identity and timestamps, audit history and export snapshots. Sign-in protection records client network identifiers and attempt counts.

Why we use it

We use this information to authenticate access, connect the companies a user authorizes, synchronize their records, support internal accounting review, and generate requested exports. Review history supports checking who approved an assignment and which source version they reviewed. Ledger does not write accounting changes back to QuickBooks.

Access and service providers

Ledger's workspace is restricted to authorized access through the Hayo VPN. Authorized administrators and infrastructure operators may access information as needed to operate and support the service. Downloaded exports are under the control of the person who downloads them and must be handled according to company requirements.

Ledger communicates with Intuit for authorization and accounting requests. Hosting and network providers process the information necessary to provide their services, including request metadata. Cloudflare provides domain services and, when this information site is hosted there, delivers its public pages. The workspace may load fonts from Google, which can receive browser request metadata.

Compatible browsers may make Ledger's review tools available to a browser-integrated assistant. These tools can expose merchant groups, source identifiers, counts, totals and categories, and can stage classification changes. If you use such an assistant, its provider's terms and privacy policy govern its handling of that information. Saving or approving a review remains a separate action.

Ledger has no advertising or tracking analytics integration. Information may also be disclosed where required by applicable law or to address unauthorized access or misuse.

Cookies

The workspace uses an essential sign-in cookie to maintain an authenticated session. It expires after eight hours; signing out removes the cookie from that browser. The interface may also set a sidebar preference cookie containing its open or closed setting, lasting up to seven days. These public information pages do not set application cookies.

Retention and disconnection

Imported records, review history and export snapshots remain stored for ongoing internal review and recordkeeping until an administrator removes them in accordance with applicable business and legal requirements. Ledger does not currently apply an automatic deletion deadline or provide a self-service data-erasure control.

Using Ledger's Disconnect control stops future synchronization after Intuit confirms revocation and removes that connection's stored access and refresh tokens. It does not delete previously imported accounting records, connection metadata, saved reviews, audit history, application credentials or export snapshots. Copies already downloaded must be managed separately.

Safeguards

The workspace uses HTTPS, VPN access restrictions, password verification, session controls and private filesystem permissions. Intuit application secrets and OAuth tokens are encrypted in Ledger's storage. These safeguards do not constitute a guarantee of security or a claim that every stored accounting record is encrypted at rest.

Requests and updates

Contact feraz@hayo.net about access, correction, deletion or other privacy requests. We may need to verify identity and authority for the affected company's records. Requests are assessed under applicable law and the company's retention obligations. Contact us before supplying additional financial records by email.

We may update this policy as Ledger's operation changes. The date above identifies the current version.