Privacy Policy

Effective and last updated: July 31, 2026.

FinArctic LLC operates GlacialBooks under license from Fluent Terrain LLC. We process financial data to provide the bookkeeping service, do not sell it or use it for targeted advertising, and do not train a general-purpose AI model on customer ledgers or documents.

1. Scope, entity, and roles

This Policy covers glacialbooks.com, the signed-in GlacialBooks application, support, and related communications. FinArctic LLC is the controller or business for account, direct billing, security, support, legal-compliance, and product-operation data. A customer organization controls the bookkeeping data its authorized users submit, and FinArctic acts as that customer's processor or service provider under the Data Processing Addendum. This Policy does not replace a customer's notice to its own employees, contractors, customers, or vendors.

2. Information categories

Category

Examples

Identifiers and account data

Name, email, user and organization identifiers, role, session, device and IP information

Commercial and billing data

Plan, trial, subscription, invoice, payment status, organization details and support history

Financial and bookkeeping data

Accounts, balances, transactions, contacts, invoices, bills, receipts, journals, payroll summaries, tax-related records, jobs, reports and uploaded documents

Application and security activity

Authentication, page path, request, workflow, audit, provider, error, support-access and security events

Automation output and inferences

Categories, matches, confidence, extraction, anomaly, profitability, close, lineage, recommendation and correction results

Preferences

Marketing choice, analytics consent, theme, saved views and notification settings

The Notice at Collection and Data and Processing Inventory provide purpose, source, recipient, and retention detail.

3. Sources

We receive information from you, other authorized members of your organization, your accountant or adviser, files and documents you upload, Clerk for identity, Stripe for billing, financial institutions connected through Plaid, services you direct us to connect, and normal operation of browsers, APIs, providers, and the application. We do not receive bank credentials entered in Plaid Link or full payment-card details entered in Stripe Checkout.

4. Purposes

We use information to authenticate users; enforce organization roles; provide bookkeeping, document extraction, reconciliation, reporting, billing, support, transaction lineage, autonomous actions, and month-end close; prevent and investigate fraud or security incidents; maintain audit evidence; communicate about the Service; comply with law; and measure and improve reliability. Optional analytics and marketing use the choices described below.

5. GDPR and UK legal bases

Where GDPR or UK GDPR applies to processing for which we are controller, we rely on the following bases:

Basis

Uses

Contract

Provide accounts, bookkeeping, integrations, reports, support, billing and requested autonomous actions.

Legitimate interests

Secure the Service, prevent fraud, maintain audit evidence, troubleshoot, measure reliability, improve workflow quality, and operate our business where those interests are not overridden by a person's rights.

Consent

Optional product analytics and optional marketing communications. Consent can be withdrawn at any time.

Legal obligation

Tax and accounting records, sanctions and fraud response, valid legal process, incident duties, and privacy-right requests.

Vital interests or public task

Used only in the unusual circumstance where applicable law permits and the facts require that basis.

When we rely on legitimate interests, you may request information about the balancing assessment and may object to the processing. Contractual account information is required to provide the Service; without it, we cannot create or operate an account. Optional analytics and marketing information is not required.

6. Automated bookkeeping and AI

GlacialBooks uses deterministic accounting logic, organization rules, statistical scoring, Microsoft Azure OpenAI, and Microsoft Azure Document Intelligence to explain records, plan requested actions, extract documents, recommend or apply bookkeeping treatment, reconcile activity, identify anomalies, prepare reports, and run close workflows. Model reasoning receives a compact context limited to the signed-in user's current organization and role. The model has no direct database access and cannot apply a change. We do not use customer financial content to train a public, general-purpose, or foundation model. We do not use these systems for consumer credit, employment, housing, insurance, health, or other legal-eligibility decisions. See the AI Transparency and Risk Management Notice.

7. Disclosures and subprocessors

We disclose only the information needed to Microsoft Azure for hosting, storage, database, model reasoning, document processing, telemetry, and email; Clerk for identity; Plaid for customer-authorized financial connections; Stripe for subscription billing; PostHog for consented analytics; and Cloudflare for edge delivery, protection, and aggregate performance data. We may also disclose data to a service the customer directs us to connect, professional advisers under confidentiality, a successor in a corporate transaction with appropriate protections, or a government or other party when legally required. Authorized organization administrators and members can access information according to role. Current details are in the Subprocessor List.

8. No sale, advertising share, or financial-data marketing

We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use GlacialBooks data for targeted advertising. We do not use sensitive financial information to infer unrelated characteristics about a person. We do not knowingly sell or share personal information of a person under 18.

9. Analytics, cookies, and marketing

PostHog product analytics starts only after browser consent. It records pseudonymous identifiers, device context, and page paths without query strings. It does not receive form contents, session recordings, or automatic element capture. Global Privacy Control and Do Not Track signals disable analytics. Cloudflare may process request metadata for security, delivery, and aggregate performance without using it for targeted advertising. Marketing email requires opt-in, and an unsubscribe is honored through our suppression list. See the Cookie Policy.

10. Security and incident response

Safeguards include TLS, encryption at rest, protected provider credentials, private data services, organization-scoped authorization, database row-level security, rate limiting, signed webhooks, immutable financial audit records, secrets management, logging, monitoring, backups, and controlled production access. No system can guarantee absolute security. We assess legal notification duties after a confirmed incident and notify affected customers or people as required by applicable law, including Georgia breach requirements where applicable. Report a concern to [email protected].

11. Retention and deletion

We retain each category only for its stated purpose, legal duties, disputes, and security. Personal account deletion has a 30-day grace period and normally completes within 31 days unless a legal hold applies. Accounting records and source evidence may be retained for seven years after organization closure or termination. Production database backups are retained for 35 days, document soft-delete recovery for 30 days, production telemetry for 90 days, and application security events for 365 days. A restricted acceptance record containing legal-document versions, acceptance time, account-email snapshot, request fingerprint hash, user agent, source, and request identifier is retained for seven years after the later of acceptance or contract termination to establish the agreement and resolve disputes. Exact schedules and exceptions are in the Data Retention and Deletion Policy.

12. Privacy rights

Depending on your location and our role, you may have a right to know or access personal data, correct it, delete it, receive a portable copy, restrict processing, object to processing, withdraw consent, appeal a decision, and complain to a regulator. EEA and UK residents may complain to the supervisory authority where they live or work. Withdrawing consent does not affect processing already performed. You also have a right not to be subject to a solely automated decision that produces legal or similarly significant effects where that right applies; GlacialBooks is not designed to make such decisions.

13. How to exercise a right

Email [email protected] from the account email and describe the request. You may also use account settings for profile, consent, export, and deletion controls. We verify identity and authority in proportion to the sensitivity of financial data and normally respond within 30 days, with an extension when law permits. If Customer controls the data, we may direct you to Customer. An authorized agent may submit a request where law permits, subject to proof of authority and identity. Appeal a denial by replying with the word Appeal. We do not discriminate for exercising a privacy right.

14. California disclosures

The categories collected during the preceding 12 months are listed in Section 2 and the Notice at Collection. We used and disclosed them for the business purposes in Sections 4, 7, 9, and 10 to the recipient categories in Section 7. We did not sell personal information or share it for cross-context behavioral advertising. We do not offer a financial incentive for personal information. California residents may request access to categories and specific pieces, correction, deletion, or portability. Because we do not sell or share personal information, no sale or sharing opt-out is necessary. We honor applicable browser opt-out preference signals for optional analytics.

15. Georgia disclosures

FinArctic LLC applies this Policy to Georgia residents and operates processes for reasonable security, secure disposal, incident assessment, and notification where Georgia law applies. We do not make deceptive claims about the Service, AI accuracy, data use, or privacy controls. Georgia residents may submit the same access, correction, deletion, and appeal requests described above even when a specific statutory right does not apply.

16. International transfers

GlacialBooks is operated in the United States, and information may be processed in the locations on the Subprocessor List. Where a restricted transfer from the EEA, United Kingdom, or Switzerland requires a transfer mechanism, we use the Standard Contractual Clauses and applicable UK or Swiss terms described in the DPA, together with technical and organizational safeguards. You may request a copy of applicable transfer terms, with confidential information removed.

17. Children

GlacialBooks is a business service for adults and is not directed to children under 18. We do not knowingly create an account for a child or collect a child's personal information through the Service. Contact us if you believe a child has provided personal information without proper authorization.

18. Changes and contact

We will provide conspicuous notice of a material change and may require renewed acknowledgement. We will not silently change this Policy to permit general-purpose AI training on existing Customer Data. Privacy questions, rights requests, and requests for transfer terms may be sent to [email protected]. Legal notices may be sent to [email protected]. FinArctic LLC is established in the United States. If appointment of a local representative becomes legally required for a targeted market, representative details will be published here before that offering begins.