My Book Pad
Docs Pricing Start free trial

Privacy Policy

Last updated: June 26, 2026

This Privacy Policy explains what information My Book Pad ("we", "us", "our") collects when you use our service, how we use it, and the choices you have. We've tried to write it in plain language — if anything is unclear, email us at support@mybookpad.com.

1. The short version

  • We collect only what's necessary to run the Service and bill you.
  • We never sell your data, and we don't run ads inside the app.
  • Your project data, expenses, notes, and photos belong to you.
  • We use a small number of trusted vendors (mainly Stripe and Google) and we list them below.
  • You can export or delete your workspace at any time.

2. Information we collect

Information you give us

  • Account details — your name, email address, business name, and password (stored as a salted hash, never in plain text).
  • Workspace content — projects, expenses, notes, photos, customer details, and any other content you add. We treat this as confidential business data.
  • Billing details — when you subscribe, Stripe collects your payment method on our behalf. We don't see or store your full card number; we only receive a token and a few non-sensitive fields (card brand, last 4, country, expiry) so we can show them in your billing settings.
  • E-signature records — when a document is sent for signing and someone signs it (you, a teammate signing on behalf of your company, or your client), we store the document, the typed or drawn signature, the signer's name and email, and an audit trail — IP address, timestamps, and the consent statement they agreed to. This is confidential workspace content held under your control so you have a complete record of who agreed to what.
  • Support correspondence — any emails you send us so we can reply and improve the product.

Information we collect automatically

  • Log data — IP address, browser type, pages visited, and timestamps, kept in short-lived server logs for security and debugging.
  • Session cookies — a single first-party cookie that keeps you signed in. See our Cookie Policy for details.
  • Audit log — important actions inside your workspace (logins, destructive operations, billing events) are written to an internal audit log so you and our support team can investigate issues.

We do not use third-party analytics scripts, tracking pixels, advertising cookies, or session-replay tools.

3. Our two roles: your data vs. your customers' data

It matters who "owns" a given piece of personal information, because our responsibilities differ.

  • When we are the controller. For information about you and your business — your account details, login and audit records, billing data, and support correspondence — we decide how and why it is processed, and this Policy governs that processing.
  • When we are the processor. Your workspace also contains personal information about your own clients and projects — for example homeowner or property-owner names, site addresses, insurance claim numbers, and project financials. You decide what to enter and why; we simply store and process it on your behalf and under your instructions so you can run your business. For that information you are the controller and we act only as your processor.

In practice: if one of your clients asks to access, correct, or delete information that lives in your workspace, that request is yours to handle as the controller — please direct it to your own organization, and we'll support you. If you need a formal data-processing agreement for your own compliance, a Data Processing Addendum is available on request at support@mybookpad.com.

4. How we use information

We use the information above to:

  • Run the Service — host your workspace, render your data, send invitations, and run features like cross-org collaboration.
  • Send transactional email — confirmations, password resets, trial-expiry warnings, payment receipts, and security notices.
  • Bill you and prevent payment fraud (in partnership with Stripe).
  • Provide customer support when you ask for it.
  • Detect, investigate, and prevent abuse, security incidents, and Terms violations.
  • Improve the product — we look at aggregate usage patterns, not individual content.
  • Comply with legal obligations.

We don't use Your Content to train AI/ML models, and we don't sell, rent, or trade your personal information.

5. Service providers & subprocessors

We share information with a small number of vendors who help us run the Service. Each is bound by their own privacy commitments.

  • Stripe — handles payment processing, subscription billing, and the customer portal. See stripe.com/privacy.
  • Google Workspace — hosts our support inbox and sends our transactional email through Gmail SMTP.
  • Google Cloud (Gemini API) — used only when you explicitly run receipt OCR. We send the receipt image to Gemini and discard the response after extracting fields into your workspace. No human reviews the image, and it is not used to train Google's models.
  • Apple Push Notification service & Google Firebase Cloud Messaging — deliver the push notifications you opt into, using an opaque per-device token.
  • DigitalOcean — provides the virtual server that hosts the Service.

We keep a current list of these subprocessors, including what each one does and where it operates, on our Subprocessors page. When we plan to add or replace a subprocessor that handles workspace data, we'll update that page and give advance notice so you have an opportunity to review the change.

6. Mobile app permissions

Our iOS and Android apps use three on-device capabilities, each tied to a specific user action.

  • Camera — accessed only when you tap a "Scan" or "Take a photo" button to capture a receipt or cheque image. Captured images are uploaded over HTTPS to your workspace and, in the case of receipts, sent to Google Cloud Gemini Vision for OCR (vendor, total, date, HST) as already described in section 5. Images are never used for any other purpose, and the camera is never accessed in the background.
  • Push notifications — used only to deliver project-related alerts you opt into (new comments, milestone changes, payment reminders). Delivery is handled by Firebase Cloud Messaging on Android and Apple Push Notification Service on iOS, both of which receive an opaque per-device token associated with your user ID. The token is not linked to your contacts, location, or any other on-device data. You can revoke push at any time via your phone's OS notification settings or in-app preferences.
  • Biometric authentication (Face ID, Touch ID, or Android fingerprint) — used only to unlock an already-issued session token after the operating system confirms your biometric. Biometric templates never leave your device and are never transmitted to our servers; we only see a yes/no answer from the OS.

The mobile app contains no third-party analytics SDKs, no advertising identifiers, and no session-replay tools. Data handling described in the other sections of this policy (workspace isolation, daily encrypted backups, deletion on request, vendor list) applies identically to mobile traffic.

7. Cross-organization sharing

When you collaborate with a partner workspace on a shared project, that workspace can view (and where applicable, contribute to) the project's data — expenses, notes, photos, and totals. You control which projects you share and with whom, and you can revoke a collaboration from the project settings at any time.

8. Data location & security

Your data is stored on servers in the United States and Canada. We protect it with HTTPS everywhere, salted password hashing, per-workspace database isolation, role-based access controls, and regular software updates. No system is perfectly secure, but we work hard to keep your data safe.

9. If a data breach happens

Despite our safeguards, no system is perfectly secure. If we become aware of a security breach affecting personal information, we'll act without undue delay to investigate and contain it.

  • For information where we are the controller (your account, billing, and log data): where a breach creates a real risk of significant or serious harm, we'll notify the affected individuals and the relevant authorities — which may include the Office of the Privacy Commissioner of Canada and, for Quebec residents, the Commission d'accès à l'information — as and when the law requires, and we'll keep records of breaches as required.
  • For information where we are your processor (your clients' and projects' data): we'll notify you, the controller, without undue delay after becoming aware of a breach, and give you the information you reasonably need to meet your own notification obligations.

10. Retention

We retain Your Content for as long as your workspace is active. If you delete your workspace, we keep the data for 30 days in case you change your mind, then permanently purge it from our production database. System logs are kept for up to 90 days for security and debugging.

Deleted projects. When you delete a project inside an active workspace, it isn't erased immediately — it moves to a Trash where you can restore it, with all of its expenses, payments, files and notes, for 90 days. After that window it's permanently removed from the live database. You can also delete a trashed project sooner ("Delete forever").

Backups. We keep encrypted backups for disaster recovery. When you delete content or a workspace, it's removed from the live Service within the window above, but residual copies may persist in encrypted backups for a short additional period before they're overwritten on our normal backup rotation. We don't restore deleted data from backups except to recover from a system failure. Billing and tax records are kept longer where Canadian tax and accounting law requires it, even after a workspace is closed.

11. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct or update it.
  • Delete your account yourself, right inside the app: go to Account → Delete my account. If you're the only person in your workspace this removes the whole workspace and its data (recoverable for 30 days, then permanently erased); if you're a team member it removes just your own account. You can also delete an entire workspace from Settings → Danger zone, or follow our account-deletion page.
  • Export it in a portable format.
  • Object to certain processing, or withdraw consent where consent is the basis.
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email support@mybookpad.com. We'll respond within a reasonable time and may need to verify your identity first.

If your personal information is in a My Book Pad workspace because a contractor you dealt with entered it (for example, you're a homeowner on one of their projects), that contractor is the controller of your information — please direct your request to that business. If you contact us, we'll help identify the right workspace and support the contractor in responding, but we can't change or delete that data without their instruction.

12. Information for US residents

This section supplements the rest of this Policy for residents of US states with comprehensive privacy laws (such as California). The categories of personal information we collect are described in Section 2; in statutory terms these may include identifiers (name, email), commercial information (subscription and billing data), internet or network activity (log data), professional or business information, and — where you upload them — images of receipts and cheques. We collect these for the business purposes described in Section 4.

We have not sold or "shared" (for cross-context behavioral advertising) personal information, and we don't do so now. Depending on your state you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of sale/sharing. Because we don't sell or share, there's nothing to opt out of; if that ever changes we'll provide a clear "Do Not Sell or Share My Personal Information" mechanism and will honor Global Privacy Control (GPC) browser signals. We will not discriminate against you for exercising any right. You may use an authorized agent to make a request, and we'll verify identity before acting.

13. Legal bases (EEA & UK users)

Where EU or UK data-protection law applies to our processing as a controller, we rely on: performance of our contract with you to provide and bill for the Service; our legitimate interests in securing the Service, preventing abuse, and improving the product through aggregate (non-content) analysis; your consent where we ask for it (for example, optional communications); and compliance with legal obligations such as tax record-keeping. Where we process your clients' data inside your workspace, we do so as your processor under the Data Processing Addendum referenced in Section 3.

14. International data transfers

We host the Service on infrastructure in the United States and Canada, and our service providers (Section 5 and our Subprocessors page) may process limited data in the countries where they operate. This means personal information may be transferred to and stored in a country other than your own.

When personal information of Quebec residents is processed outside Quebec, we assess that it will receive protection appropriate to its sensitivity. Where we transfer personal information of individuals in the EU, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum). You can request more information using the contact details in Section 17.

15. Children

My Book Pad is built for businesses and isn't intended for anyone under 18. We don't knowingly collect information from children. If you believe a child has given us personal data, contact us and we'll delete it.

16. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we'll notify you by email or by an in-product notice before it takes effect. The "Last updated" date at the top of this page always shows when the policy last changed.

17. Who we are & how to reach us

This Service is operated by My Book Pad Inc., a corporation based in Ontario, Canada. We are the organization responsible for the personal information described in this Policy, and we've designated a Privacy Officer who is accountable for our compliance with applicable privacy laws — including personal information we transfer to the service providers listed above.

To reach our Privacy Officer with any question, request, or complaint, email support@mybookpad.com with "Privacy" in the subject line. If you're not satisfied with our response, you have the right to contact your local data-protection authority (see Section 11).

Terms Privacy Cookies Subprocessors Delete account Docs Support
© 2026 My Book Pad Inc.