accrova
Legal

Privacy Policy

Effective: June 23, 2026  ·  Accrova, Inc.  ·  Controller: Accrova, Inc.
What this means in plain language
We process your data only to operate and improve the Service — nothing else.
We do not sell your personal data or Customer Data to third parties, ever.
Your financial and contract data is encrypted in transit (TLS 1.3) and at rest (AES-256).
You can request deletion of all your data at any time — we act within 30 days.
We use a small number of vetted sub-processors, listed below.
We are subject to CCPA (California) and provide GDPR-equivalent rights to all users.

1. Who We Are

Accrova, Inc. ("Accrova," "we," "us," or "our") operates the Accrova platform at getaccrova.com. We are the data controller for personal data collected through the Service. Our Data Protection contact is privacy@getaccrova.com.

2. Data We Collect

Account data — name, work email address, company name, and role, provided when you register.

Customer Data — financial contracts, revenue schedules, journal entries, and other data you upload or generate within the Service. You own this data; we process it on your behalf.

Usage data — pages visited, features used, error logs, and device/browser metadata, collected automatically to operate and improve the Service.

Payment data — billing address and plan selection. Card numbers are handled exclusively by Square and never touch our servers.

Integration credentials — OAuth tokens for QuickBooks Online and Xero, stored encrypted per tenant and never exposed to other users.

We do not collect Social Security Numbers, government IDs, health data, or any data from minors under 18. The Service is not directed at children.

3. Legal Basis for Processing

We rely on the following legal bases (applicable under GDPR Art. 6 and equivalent frameworks):

4. How We Use Your Data

We do not use your Customer Data to train AI models without your explicit consent.

5. Sub-Processors

We use the following vetted sub-processors. Each is bound by a data processing agreement. We will notify you of any material changes to this list with at least 14 days' notice.

ProviderPurposeRegion
SupabaseDatabase & authentication storageUS East (AWS us-east-1)
ClerkUser identity & session managementUS / EU
VercelApplication hosting & edge deliveryGlobal CDN (US primary)
AnthropicAI analysis of contract dataUS
Intuit (QB)QuickBooks OAuth & journal entry syncUS
XeroXero OAuth & journal entry syncUS / NZ
SquarePayment processing (no card data stored)US
SvixWebhook delivery infrastructureUS

6. Data Retention

We retain your data for as long as your account is active plus the following periods:

7. Security

We implement the following controls:

If you discover a security vulnerability, please report it responsibly to security@getaccrova.com. We commit to responding within 48 hours.

8. Your Rights

Regardless of your location, we honor the following rights for all users. California residents have additional rights under CCPA; EU/UK residents under GDPR/UK GDPR.

To exercise any of these rights, email privacy@getaccrova.com. We will respond within 30 days (45 days for complex requests, with notice).

9. Cookies and Tracking

We use strictly necessary session cookies to maintain authenticated sessions. We use:

We do not use third-party advertising cookies, retargeting pixels, or behavioral tracking technologies.

10. International Data Transfers

Data is primarily stored and processed in the United States. If you are located in the European Economic Area, UK, or Switzerland, transfers to the US are made under the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) as appropriate for each sub-processor. A copy of our SCCs is available upon request.

11. California Privacy Rights (CCPA / CPRA)

California residents have the right to know, delete, and opt-out of the sale or sharing of personal information. As noted above, Accrova does not sell or share personal information for cross-context behavioral advertising. To submit a CCPA request, email privacy@getaccrova.com with "CCPA Request" in the subject. We will not discriminate against you for exercising your rights.

Personal information categories collected in the last 12 months: identifiers (name, email), commercial information (subscription tier, payment history), professional information (company, role), internet activity (usage logs). Categories of sources: directly from you. Business purpose: service delivery, security, billing.

12. Data Breach Notification

In the event of a data breach that is reasonably likely to result in risk to your rights or freedoms, we will notify affected users within 72 hours of becoming aware of the breach, consistent with applicable law (GDPR Art. 33/34, CCPA). Notification will include: nature of the breach, data affected, steps taken, and recommended actions for affected users.

13. Do Not Track

We respect browser-level Do Not Track (DNT) signals. When DNT is enabled, Vercel Analytics collection is suppressed for your session.

14. Changes to This Policy

We may update this Privacy Policy. For material changes, we will provide at least 14 days' notice via email and a notice on the Service. The effective date at the top of this page reflects the most recent version.

15. Contact & Complaints

For privacy questions or to exercise your rights: privacy@getaccrova.com

If you are in the EU/UK and we have not resolved your concern to your satisfaction, you have the right to lodge a complaint with your local data protection authority.

accrova.comTerms of ServiceCancellation & Refundsupport@getaccrova.com