1. Who is responsible for personal data?
Customer project data
The Customer company generally decides why and how project data is used. It is the data controller or equivalent responsible organisation. FinishLedger processes that data for the Customer as a processor or service provider under the Customer’s instructions.
FinishLedger account and service data
FinishLedger is the controller or responsible organisation for account administration, authentication, service security, support, billing, legal acceptance records, website enquiries and platform-level service improvement.
If you are a worker, contractor, consultant or external recipient and your data appears in a project, contact the relevant Customer first. FinishLedger will assist the Customer with valid requests.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email, password authentication record, company, role, phone number if added, legal-document acceptance | You, an inviter or authorised workspace manager |
| Project access | Company, project memberships, invitation email, permissions, revocation and acceptance history | Customer administrators and system events |
| Project operations | Locations, quantities, progress, dates, workforce deployment, materials, issues, comments, approvals, reports and site logs | Project users, imports and connected workflows |
| Evidence and files | Photos, captions, original filenames, documents, report files and file metadata | Users and imported files |
| Accountability history | Author, timestamps, views, acknowledgements, reminders, status changes, completion submissions and audit events | Application activity |
| Device and reliability | Session identifiers, local preferences, offline drafts, sync queue, route, scrubbed error code and technical diagnostics | Your browser/device and application |
| Communications | Support enquiries, pilot requests, invitation delivery status and transactional email events | You and email providers |
FinishLedger is not designed to store payroll, biometric templates, medical records, passports, payment-card information or private messaging archives. Do not upload those categories unless a written agreement and lawful process specifically permit it.
3. Purposes and legal bases
Depending on the relationship and applicable law, we process personal data to:
- provide accounts, projects, invitations, records, files, notifications, reports and support under a contract;
- protect the service, prevent unauthorised access, diagnose failures and preserve record integrity based on legitimate interests and legal obligations;
- send service, security, invitation and workflow communications necessary to operate FinishLedger;
- comply with law, respond to valid legal requests and establish or defend legal claims;
- improve product reliability using privacy-scrubbed operational diagnostics;
- process optional data where a valid consent or another lawful basis is required.
We do not use project content for advertising, sell personal data, or train general-purpose AI models on Customer project content. FinishLedger does not make solely automated decisions producing legal or similarly significant effects.
4. Project data, contacts and accountability
Authorised project members may see names, roles, contact information and project actions needed to coordinate work. Where a phone number is added, authorised project users may be able to tap a name to call through their device carrier.
Page-presence records may show that a project member viewed a page, the first and latest view time, and a view count. Issues, photos, changes, external acknowledgements and completion submissions carry authorship and timestamps. These records support operational accountability but do not automatically prove legal identity, fault or liability.
External issue links reveal only the shared ticket and any snapshot photo attached to that ticket. They do not grant project access. A recipient’s typed name, company, reply and server timestamp are stored in the Customer’s audit history.
5. Photos, documents and metadata
Project photos and documents are stored privately and served through controlled or time-limited access. Original files may contain device metadata such as capture time, camera information or GPS coordinates. FinishLedger currently keeps the original file, so Customers should disable location capture or remove metadata where it is unnecessary.
Only photograph what is relevant to the project record. Avoid faces where unnecessary and do not capture identity documents, medical information, private chats, home areas or unrelated people. Customers are responsible for site notices and any legally required consent or other lawful basis.
7. International transfers
FinishLedger’s providers may process data in more than one country. The selected Supabase project region stores primary database and file content, while hosting, email delivery, support or security systems may involve other locations. Where required, we use contractual safeguards or another lawful transfer mechanism and assess provider protections.
Commercial Customers should confirm their required hosting region, transfer restrictions and contractual safeguards in the order form and Data Processing Addendum.
8. How long data is kept
We keep data only as long as needed for the service, Customer instructions, security, dispute handling and legal obligations. Current early-access rules are:
- project records and evidence remain available while the Customer keeps the project or requires an archive;
- project invitations normally expire after 14 days, while limited invitation history may remain for security and audit purposes;
- external issue links expire or become unavailable when revoked, closed or voided; the internal ticket and response audit remain with the project;
- offline drafts and queues remain on the user’s device until synced, cleared or removed by browser/device controls;
- privacy-scrubbed error and security records are kept for a limited operational period;
- deleted data may remain temporarily in encrypted backups until those backups rotate.
A precise retention and archive schedule must be agreed before commercial launch. Customers can request project export, deletion or archival review through an authorised workspace owner and hello@finishledger.com.
9. Your choices and rights
Depending on applicable law and your location, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, withdraw consent, or complain to a competent data-protection authority.
Send requests to hello@finishledger.com with “Privacy” in the subject. State your name, account email, Customer/project and request. We may need to verify identity and route project-data requests to the Customer controller.
You can control necessary browser storage through your device, but clearing it may sign you out and delete unsynced offline drafts. See Cookies & local storage.
10. Security and incidents
Measures include encrypted transport, managed authentication, private file storage, database row-level security, scoped project roles, access revocation, server timestamps, audit events, backups and restricted infrastructure access. Security is risk-based and no system can guarantee absolute protection.
If a personal-data incident affects Customer project data, FinishLedger will investigate, mitigate and notify the Customer without undue delay as required by the applicable agreement and law. Users should report suspected incidents immediately.
11. Changes and contact
We may update this notice to reflect legal, provider or product changes. Material changes will be highlighted through the website, app or account email, and the version date will change.
Privacy and data requests: hello@finishledger.com. General service questions: hello@finishledger.com.