Privacy Policy
This describes what personal data Ledgerlot actually collects, why, who it's shared with, and what rights you have over it. It's separate from our Legal & Disclaimer page, which covers the documents Ledgerlot generates, not your account data.
What we collect
- Account information — email address (required), and optionally your name, phone number, license number, and a signature image, if you provide them.
- Document content — the information you enter into a document (e.g. buyer/seller/tenant names, addresses, financial terms) and any files you upload.
- Signing records — for e-signature requests, we record IP address, approximate location, device/browser, and timestamp for each signer, as a tamper-evident record of who signed and when. This detail is kept for that legal record but is not shown in the everyday admin-facing audit view — only the signing outcome and timestamps are.
- Billing information — handled entirely by Stripe's hosted Checkout. Ledgerlot never receives or stores your card number.
- Usage data — which search results you click on (used only to improve search relevance), and, if you use the AI assistant, your questions to it (used to generate a response; not used to train any model).
- Cookies — a session cookie (keeps you signed in) and a workspace cookie (remembers which organization you last had active). Both are functional, first-party, and required for the app to work — we don't use advertising or third-party tracking cookies.
Why we collect it
To provide the service you're asking for: generating and storing your documents, running e-signature workflows, billing your subscription, and answering support/assistant questions. We don't sell personal data, and we don't use your document content for advertising.
Who it's shared with
We use a small number of subprocessors to run Ledgerlot, each handling only what their role requires:
- Vercel — application hosting
- Neon — database hosting (Postgres)
- Vercel Blob — file storage (uploaded documents, signature images)
- Stripe — payment processing (card details go directly to Stripe, never through our servers)
- Resend — transactional email delivery (signature requests, notifications)
The AI assistant's models run on our own server infrastructure — your questions and document context are not sent to a third-party AI API. The model files themselves are downloaded once from HuggingFace, a public open-source model repository; that's a one-time software download, not an ongoing data-sharing relationship, and no user or document data is ever sent to HuggingFace.
We don't share personal data with anyone else except where required by law.
How long we keep it
Documents are retained for a period set by your plan (7 years by default on every current plan) and automatically purged after that window via a scheduled job — not indefinitely. Signing records are kept for the same period, for their function as a legal audit trail. If a subscription lapses, we don't shorten the retention already promised for documents created under it.
Your rights
You can request an export of your own account data — profile, folders, documents, and signature history — at any time from Settings. If you'd like your account and its data deleted, contact us via the Support page — this isn't yet a self-serve action in the product, but we will action a deletion request directly.
Security
See our Security & Data Handling page for how we protect data in transit and at rest, and how access is controlled.
Changes to this policy
If this policy changes in a way that affects how your data is handled, we'll update this page and, for material changes, notify account holders directly.
Contact
Questions about this policy or your data — reach out via the Support page.