TheGuyBooks Privacy Policy

Effective Date: June 10, 2026

This Privacy Policy describes how TheGuys App LLC, a Florida limited liability company operating the TheGuyBooks platform ("TheGuyBooks," "we," "us," or "our"), collects, uses, discloses, and protects information in connection with theguybooks.com and the hosted bookkeeping service we provide (together, the "Service").

TheGuyBooks is a business-to-business service. Our customers are businesses ("Hosts") that embed our bookkeeping product into their own websites and applications. A Host's customers and users ("End Users") reach the Service through the Host's property. Each set of financial books maintained in the Service is a "Tenant."


1. Our Three Roles

We handle information in three distinct capacities. Which rights and processes apply to you depends on which capacity is involved.

As a controller (our own business operations). For information about our Hosts, their representatives, our website visitors, and prospective customers — account registration details, billing records, support communications, and Service usage logs — we decide how and why the information is processed. This Privacy Policy governs that processing directly.

As a processor and service provider (Tenant books data). The financial books data inside each Tenant — journal entries, charts of accounts, transaction records, imported transaction data, reconciliation records, company configuration, branding assets, and any per-session display name a Host passes to us — is processed on behalf of and at the direction of the Host. The Host (or its End User) controls that data; we store and process it only to deliver the Service under our agreement with the Host. If you are an End User, the Host whose website or application you use is responsible for your books data and for responding to your privacy requests about it. Contact that Host directly. If you contact us about Tenant data, we will refer your request to the relevant Host and assist that Host in responding.

As a controller (End User authentication data). When an End User logs in to the Service through our Identity Service, we collect and control that End User's login credentials — email address, password stored in hashed form, and any second-factor secret and recovery codes — together with the related login and session records. We decide how and why that authentication data is processed, and this Privacy Policy governs it directly. If you are an End User, you may exercise your rights over your login and authentication data by contacting us directly, as described in Section 7.


2. Information We Collect

Information Hosts provide to us. When a business registers as a Host, we collect business name, contact name, email address, and billing information. Payments are processed by our payment processor; we receive transaction confirmations and limited payment metadata but do not collect or store full payment card numbers.

Information collected automatically. When Hosts, End Users, or visitors interact with the Service, our systems automatically record technical and usage information: IP address, browser and device characteristics, timestamps, pages and endpoints requested, API request metadata, seat and Tenant usage counts, and security and audit events. We maintain immutable, host-scoped audit logs of activity within the Service as a security control and as the authoritative record of usage for billing.

Cookies. We use only essential cookies and similar technologies strictly necessary to operate the Service — session management, security, and load balancing. We do not use advertising cookies, cross-site tracking technologies, or third-party analytics trackers on the Service.

Tenant books data (processed for Hosts). On behalf of Hosts, we store and process the complete double-entry financial books of each Tenant, as described in Section 1. This data may include personal information that a Host or its End Users choose to enter, such as payee names, customer names, transaction descriptions, and memo text.

End User authentication data. When End Users create a login and access the Service through our Identity Service, we collect and store their email address, password (stored in hashed form, never in plaintext), any second-factor (TOTP) secret and recovery codes, and login and session records. We control this data as described in Section 1.

What we do not collect. We do not store End User passwords in plaintext, and we do not collect or store full payment card numbers or bank account login credentials.


3. How We Use Information

We use the information described above to:

  1. Provide, operate, secure, and maintain the Service, including rendering each Tenant's books as configured by its Host;
  2. Meter seat and Tenant usage and bill Hosts;
  3. Authenticate API requests and End Users, mint and validate access tokens and login sessions, process password resets and second-factor verification, and enforce tenant and host isolation;
  4. Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents;
  5. Provide support and respond to inquiries from Hosts;
  6. Send transactional and administrative communications, such as billing notices, credential delivery, security alerts, and changes to our terms or this policy;
  7. Analyze aggregated, de-identified usage to operate and improve the Service; and
  8. Comply with legal obligations and enforce our agreements.

We do not sell personal information. We do not use Tenant books data for advertising, do not serve advertising on the Service, and do not use Tenant books data to train artificial-intelligence or machine-learning models.


4. How We Disclose Information

We disclose information only as follows:

Sub-processors and service providers. We use a small set of infrastructure providers to operate the Service, each bound by contractual obligations to protect the data they handle:

ProviderPurpose
Vercel Inc.Application hosting
Supabase Inc.Database hosting
ResendTransactional email delivery
GitHub, Inc.Code hosting and build infrastructure
Stripe, Inc.Payment processing

The current list is maintained at theguybooks.com/subprocessors. Hosts receive advance notice of changes to this list as provided in our Terms of Service.

The relevant Host. Information within a Tenant is available to the Host under whose account that Tenant exists, and to the End Users that Host authorizes through its own systems.

Professional advisors. Lawyers, accountants, auditors, and insurers, under confidentiality obligations, where needed for our legitimate business operations.

Legal and safety. We may disclose information where we believe in good faith it is required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, property, security, or safety of TheGuyBooks, our Hosts, End Users, or the public, or to enforce our agreements.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our business or assets, information may be transferred as part of that transaction, subject to the commitments of this policy or successor commitments that are no less protective.

We do not disclose Tenant books data to any other party for that party's own purposes.


5. Data Retention

Host account and billing data. Retained for the duration of the Host relationship and thereafter as needed for legitimate business purposes and legal compliance, including tax, accounting, and audit requirements.

Tenant books data. Retained for the duration of the Host's subscription. Following termination of a Host's subscription, the Host may request an export of its Tenant data within 90 days; we then delete Tenant data within 30 days after that window closes, with encrypted backups aging out within an additional 35 days. Hosts and End Users are responsible for exporting and retaining any financial records they are required by law to keep.

End User authentication data. Retained while an End User's login is active under a Host. When an End User's login is deactivated, or when the Host's subscription ends, we delete the associated login credentials within 30 days, with encrypted backups aging out within an additional 35 days.

Logs, audit records, and usage records. Security logs, audit trails, and seat-usage and billing records are retained as long as needed for security, billing-integrity, dispute-resolution, and legal purposes.

We may retain information longer where required by law, legal hold, or active investigation, and we may retain aggregated or de-identified information indefinitely.


6. Security

We maintain technical and organizational measures designed to protect the information we handle, including: tenant-level and host-level data isolation enforced at the database layer through row-level security and a non-privileged runtime role; isolation of the Identity Service's credential store from books data; API keys stored in hashed form only; End User passwords stored using a modern password-hashing algorithm and second-factor secrets stored in encrypted form; short-lived, cryptographically signed session tokens issued only after End User authentication; immutable, host-scoped audit logging; encryption of data in transit and at rest; logical access controls on production systems; and tested backup and restore procedures.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Hosts are responsible for safeguarding their own API keys and for conveying and promptly revoking End User entitlements; access to books data that results from a Host's failure to do so is outside our control.


7. Your Choices and Rights

Hosts. Hosts may review and update their account information through their account, and may contact Admin@theguys.app to access, correct, or delete account data, subject to our retention obligations. Hosts may opt out of non-essential communications at any time; transactional and security communications cannot be opted out of while the account is active.

End Users. If you use a bookkeeping feature on a Host's website or application, the Host is responsible for your books data and for honoring your privacy rights over it. Direct access, correction, deletion, and other requests about your books data to that Host; where we receive such a request directly, we will forward it to the relevant Host and provide the Host reasonable assistance in responding. For your login and authentication data, which we control, direct your requests to us at Admin@theguys.app.

U.S. state privacy rights. Depending on your state of residence, you may have rights to know, access, correct, delete, or obtain a portable copy of personal information, and to non-discrimination for exercising those rights. For information we control, submit requests to Admin@theguys.app; we will verify your identity before acting and respond within the time required by applicable law. You may use an authorized agent where the law permits. We do not sell or share personal information as those terms are defined under applicable U.S. state privacy laws, and we therefore do not offer an opt-out of sale or sharing; we treat universal opt-out signals such as Global Privacy Control consistently with that position. For information we process on behalf of a Host, your state-law requests should be directed to the Host, which is the "business" or "controller" with respect to that data.

International visitors. The Service is operated from the United States and is directed to United States businesses. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction. For any personal data subject to the EU or UK General Data Protection Regulation contained in Tenant data, the Host is the controller and TheGuyBooks processes that data as a processor under the data processing terms in our Terms of Service.


8. Children

The Service is business software and is not directed to children. We do not knowingly collect personal information from anyone under 18, and access to the Service, including creating a login through our Identity Service, is restricted to individuals who are at least 18 years of age. No part of the Service is directed to children under 13 within the meaning of the Children's Online Privacy Protection Act. If you believe a child has provided personal information to us, contact Admin@theguys.app and we will delete it.


9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy at theguybooks.com with a revised effective date, and for material changes we will provide notice to Hosts by email or within the Service before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.


10. Contact Us

TheGuys App LLC, operating TheGuyBooks Privacy inquiries: Admin@theguys.app Legal: legal@theguys.app Support: support@theguys.app