Accrova, Inc. ("Accrova," "we," "us," or "our") operates the Accrova platform at getaccrova.com. We are the data controller for personal data collected through the Service. Our Data Protection contact is privacy@getaccrova.com.
Account data — name, work email address, company name, and role, provided when you register.
Customer Data — financial contracts, revenue schedules, journal entries, and other data you upload or generate within the Service. You own this data; we process it on your behalf.
Usage data — pages visited, features used, error logs, and device/browser metadata, collected automatically to operate and improve the Service.
Payment data — billing address and plan selection. Card numbers are handled exclusively by Square and never touch our servers.
Integration credentials — OAuth tokens for QuickBooks Online and Xero, stored encrypted per tenant and never exposed to other users.
We do not collect Social Security Numbers, government IDs, health data, or any data from minors under 18. The Service is not directed at children.
We rely on the following legal bases (applicable under GDPR Art. 6 and equivalent frameworks):
We do not use your Customer Data to train AI models without your explicit consent.
We use the following vetted sub-processors. Each is bound by a data processing agreement. We will notify you of any material changes to this list with at least 14 days' notice.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database & authentication storage | US East (AWS us-east-1) |
| Clerk | User identity & session management | US / EU |
| Vercel | Application hosting & edge delivery | Global CDN (US primary) |
| Anthropic | AI analysis of contract data | US |
| Intuit (QB) | QuickBooks OAuth & journal entry sync | US |
| Xero | Xero OAuth & journal entry sync | US / NZ |
| Square | Payment processing (no card data stored) | US |
| Svix | Webhook delivery infrastructure | US |
We retain your data for as long as your account is active plus the following periods:
We implement the following controls:
If you discover a security vulnerability, please report it responsibly to security@getaccrova.com. We commit to responding within 48 hours.
Regardless of your location, we honor the following rights for all users. California residents have additional rights under CCPA; EU/UK residents under GDPR/UK GDPR.
To exercise any of these rights, email privacy@getaccrova.com. We will respond within 30 days (45 days for complex requests, with notice).
We use strictly necessary session cookies to maintain authenticated sessions. We use:
We do not use third-party advertising cookies, retargeting pixels, or behavioral tracking technologies.
Data is primarily stored and processed in the United States. If you are located in the European Economic Area, UK, or Switzerland, transfers to the US are made under the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) as appropriate for each sub-processor. A copy of our SCCs is available upon request.
California residents have the right to know, delete, and opt-out of the sale or sharing of personal information. As noted above, Accrova does not sell or share personal information for cross-context behavioral advertising. To submit a CCPA request, email privacy@getaccrova.com with "CCPA Request" in the subject. We will not discriminate against you for exercising your rights.
Personal information categories collected in the last 12 months: identifiers (name, email), commercial information (subscription tier, payment history), professional information (company, role), internet activity (usage logs). Categories of sources: directly from you. Business purpose: service delivery, security, billing.
In the event of a data breach that is reasonably likely to result in risk to your rights or freedoms, we will notify affected users within 72 hours of becoming aware of the breach, consistent with applicable law (GDPR Art. 33/34, CCPA). Notification will include: nature of the breach, data affected, steps taken, and recommended actions for affected users.
We respect browser-level Do Not Track (DNT) signals. When DNT is enabled, Vercel Analytics collection is suppressed for your session.
We may update this Privacy Policy. For material changes, we will provide at least 14 days' notice via email and a notice on the Service. The effective date at the top of this page reflects the most recent version.
For privacy questions or to exercise your rights: privacy@getaccrova.com
If you are in the EU/UK and we have not resolved your concern to your satisfaction, you have the right to lodge a complaint with your local data protection authority.