Privacy Policy
Last updated: May 2026
1. Information We Collect
When you use the Solo Ledger platform, we collect:
- Account information — name, email address, and password (stored as an Argon2id hash, never in plain text)
- Business data — product inventory, transactions, staff records, and reports you create
- Device information — browser fingerprint, IP address, and device metadata for security purposes
- Usage data — login times, pages visited, and feature usage to improve the Service
2. How We Use Your Data
We use your information to:
- Provide and operate the Service
- Authenticate users and secure your account
- Generate reports and analytics for your business
- Send transactional emails (OTP codes, security alerts, end-of-day reports)
- Detect and prevent fraud, abuse, and security threats
- Improve the Service based on usage patterns
3. Data Isolation
Solo Ledger uses a multi-tenant architecture with strict data isolation. Each tenant's data is separated at the database level using PostgreSQL Row-Level Security (RLS). No tenant can access another tenant's data under any circumstances. Every database query is scoped to the authenticated tenant's context.
4. Security Measures
We implement industry-standard security practices including:
- Argon2id password hashing (the strongest available algorithm)
- Two-factor authentication via one-time codes
- Device fingerprinting and approval workflows
- IP-based access controls and blocklists
- Brute-force protection with account lockouts
- Comprehensive audit logging of all sensitive actions
5. Data Sharing
We do not sell, rent, or share your personal or business data with third parties for marketing purposes. We may share data only when:
- Required by law or legal process
- Necessary to protect our rights or prevent fraud
- You have given explicit consent
6. Data Retention
We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days. Anonymised usage data and aggregate analytics may be retained indefinitely. Audit logs are retained for a minimum of 12 months for security and compliance purposes.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format (CSV/PDF)
- Withdraw consent for optional data processing
8. Cookies
Solo Ledger uses strictly-necessary cookies only. Because they are essential to providing the service you have asked for, they do not require consent under UK PECR — but for transparency, they are:
- Authentication — a secure, http-only session cookie that keeps you signed in, plus a CSRF-protection cookie. Cleared when you sign out or after 8 hours.
- Point of sale — a short-lived, signed cookie used to authorise a manager-approved discount on a till. It carries no personal data and expires within minutes.
We do not use tracking cookies, advertising cookies, or third-party analytics services, and no third-party scripts can run on the site. Point-of-sale terminals also hold their working session in your browser's session storage (not a cookie), which is cleared automatically when the tab is closed.
To protect accounts from fraud and abuse we collect a limited device fingerprint (for example browser, operating system and screen characteristics). This is a security measure, is not used for advertising or cross-site tracking, and does not rely on cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the platform. Your continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy-related enquiries, contact our data protection team at [email protected] or call 07823 332 691.