Privacy Policy
Last updated: September 2026
This Privacy Policy explains how Platybooks (“we”, “us”) collects, uses, stores, and shares information — including data obtained through Google when you sign in with your Google account — when you use our invoicing and sales CRM. We keep data collection to what is needed to run the service and never sell your data.
Information we collect
- Account data — your email address and the organization details you provide (name, address, currency, logo).
- Business records you create — clients, products, quotes, invoices, payments, and the documents you send.
- Usage and technical data — basic logs needed to operate, secure, and troubleshoot the service.
Google user data we access
When you choose to sign in with Google, we request access to the following Google user data through OAuth:
- Email address (
emailscope) — to identify your account and sign you in. Your email is stored as the login identifier for your Platybooks workspace and is used to send you service-related communications (e.g. account notifications, password resets, and important service changes). - Basic profile information (
profile/openidscope) — to retrieve your name so we can personalise your workspace. We do not access your Google contacts, Drive, Calendar, Gmail, or any other Google service or product data.
We do not request, access, or read your emails, files, photos, calendar events, contacts, or any other data stored in your Google account beyond the email address and basic profile name needed for authentication.
How we use Google user data
The Google user data we access is used solely to provide and improve the Platybooks service you signed in to use:
- Authentication — to identify you and maintain your signed-in session.
- Account personalisation — to display your name within your workspace.
- Service communications — to send you transactional emails related to your account and workspace.
We do not use Google user data for any of the following purposes:
- Advertising — targeted, personalised, retargeted, or interest-based.
- Selling or renting personal information to third parties or data brokers.
- Determining credit-worthiness or lending purposes.
- Building or training generalised (non-personalised) AI or machine-learning models.
- Creating databases of user profiles for any purpose outside the service.
- Any purpose other than providing or improving Platybooks.
How we share, transfer, or disclose Google user data
We do not sell, rent, or share Google user data with third parties for their own purposes. We transfer or disclose Google user data only in these limited circumstances:
- Service operators (sub-processors) — we share data only with the operators required to run Platybooks (listed below). Each acts on our behalf under a data-processing agreement and may not use your data for its own purposes.
- Legal requirements — we may disclose information if required by law, regulation, legal process, or enforceable governmental request.
- Safety — to protect the rights, property, or safety of our users or the public, when we have a good-faith belief that disclosure is required.
We do not transfer Google user data to third parties for advertising, data brokering, information reselling, credit determination, lending, or for training generalised AI/ML models.
How we protect your data
We use industry-standard security procedures to protect the confidentiality of your data:
- Encryption in transit — all data is transmitted over HTTPS/TLS.
- Encryption at rest — data stored in our database is encrypted at rest.
- Multi-tenant isolation — row-level security ensures each organization can only access its own records.
- Role-based access — within a workspace, access is limited by the user’s role (owner, admin, member).
- Append-only payment ledger — payment records cannot be altered after creation.
- Authentication — sessions are managed by our authentication provider with secure token handling.
No method of transmission or storage is completely secure, but we take reasonable measures to protect your information. To operate the service we must be able to read your workspace data — that is how invoices get emailed, reminders go out on schedule, and dashboards add up — so we do not offer customer-held-key encryption. The plain-language version of this section, written so you can forward it to an auditor, lives on our security & encryption page.
Data retention and deletion
We store your personal information for as long as your workspace is active and for the length of time needed to fulfil the purposes outlined in this privacy policy. When the data retention period expires for a given type of data, we will delete or destroy it.
- Account and business records — kept for as long as your workspace is active. After you close your account we delete or anonymise personal information within a reasonable period, except where we must retain certain records (for example invoices and accounting data) to meet legal obligations.
- Google authentication data — your email and profile name are retained as long as your account exists. If you delete your account or revoke access, we remove this data from our active systems.
- Server and error logs — kept only as long as needed for security and troubleshooting, then automatically purged.
You may request deletion of your data by closing your account or by contacting us. We will honour verified deletion requests within a reasonable timeframe, except where retention is required by law.
How to revoke access to your Google account
You can revoke Platybooks’s access to your Google account at any time through your Google Account settings (Google Account → Security → Third-party apps with account access). If you revoke access, you will no longer be able to sign in with Google. You can still access your workspace by setting a password on your account.
Lawful basis for processing
We process personal information under the grounds set out in South Africa’s Protection of Personal Information Act (POPIA), and — for visitors and customers in the EU/EEA — the corresponding bases under the GDPR:
- Performance of a contract — to create your workspace, store the business records you enter, send your documents, and operate the service (GDPR Art. 6(1)(b)).
- Legitimate interests — to keep the service secure, prevent abuse, and diagnose errors, balanced against your rights (GDPR Art. 6(1)(f)).
- Consent — where you give it, e.g. for optional analytics on our marketing site; you can withdraw consent at any time (GDPR Art. 6(1)(a)).
- Legal obligation — to meet retention and accounting duties that apply to us (GDPR Art. 6(1)(c)).
Cookies & tracking
Platybooks does not use advertising or cross-site tracking cookies. The only data stored in your browser is first-party and either strictly necessary to run the service or kept to honour your preferences:
- Authentication session — keeps you signed in. Strictly necessary; cleared on sign-out.
- lf.currentOrg — remembers which workspace you last used. Functional (localStorage); persists until cleared.
- lf.ui — remembers interface preferences such as your theme and sidebar state. Functional (localStorage); persists until cleared.
- lf.consent — remembers your choice about optional analytics so we don’t ask again. Strictly necessary to honour your preference (localStorage).
Marketing-site analytics. On our public marketing pages we use Plausible Analytics, a privacy-friendly, cookieless analytics tool. It measures page views and aggregate trends without cookies and without collecting personal information or building cross-site profiles. It is not loaded inside the signed-in app.
Error monitoring. Across the application we use Sentry to detect and diagnose technical errors. We configure it to scrub IP addresses and personal data so that error reports do not identify you. This runs on the basis of our legitimate interest in a reliable, secure service.
Operators & sub-processors
We share data only with the operators required to run Platybooks. Each acts on our behalf under a data-processing agreement and may not use your data for its own purposes. We do not sell personal information.
- Supabase — application hosting, database, authentication, and file storage (the core of the service).
- Resend — delivery of transactional email (document and account notifications).
- Plausible Analytics — cookieless, aggregate analytics on our marketing site (no personal information).
- Sentry — application error monitoring (IP and personal data scrubbed).
- Your payment processor — when you enable online payments, the processor you connect handles payment data under its own terms.
Cross-border transfers
Some of these operators may process data outside South Africa, including in the EU and the United States. Where that happens we rely on appropriate safeguards — consistent with POPIA section 72 and, for EU data, the EU Standard Contractual Clauses — so your information stays protected to a comparable standard.
Your rights
Subject to applicable law, you may have the right to access your personal information, to have it corrected or deleted, to object to or restrict certain processing, to data portability, and — where processing is based on consent — to withdraw that consent at any time. To make a request, contact us using the details below.
You also have the right to lodge a complaint with a supervisory authority. In South Africa this is the Information Regulator; in the EU/EEA it is the data protection authority in your country of residence.
Children’s privacy
Platybooks is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the service before the changes take effect. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact
Our Information Officer handles privacy questions and data requests. Email us at privacy@platybooks.app.