Last updated: June 26, 2026
This Privacy Policy explains what information My Book Pad ("we", "us", "our") collects when you use our service, how we use it, and the choices you have. We've tried to write it in plain language — if anything is unclear, email us at support@mybookpad.com.
We do not use third-party analytics scripts, tracking pixels, advertising cookies, or session-replay tools.
It matters who "owns" a given piece of personal information, because our responsibilities differ.
In practice: if one of your clients asks to access, correct, or delete information that lives in your workspace, that request is yours to handle as the controller — please direct it to your own organization, and we'll support you. If you need a formal data-processing agreement for your own compliance, a Data Processing Addendum is available on request at support@mybookpad.com.
We use the information above to:
We don't use Your Content to train AI/ML models, and we don't sell, rent, or trade your personal information.
We share information with a small number of vendors who help us run the Service. Each is bound by their own privacy commitments.
We keep a current list of these subprocessors, including what each one does and where it operates, on our Subprocessors page. When we plan to add or replace a subprocessor that handles workspace data, we'll update that page and give advance notice so you have an opportunity to review the change.
Our iOS and Android apps use three on-device capabilities, each tied to a specific user action.
The mobile app contains no third-party analytics SDKs, no advertising identifiers, and no session-replay tools. Data handling described in the other sections of this policy (workspace isolation, daily encrypted backups, deletion on request, vendor list) applies identically to mobile traffic.
When you collaborate with a partner workspace on a shared project, that workspace can view (and where applicable, contribute to) the project's data — expenses, notes, photos, and totals. You control which projects you share and with whom, and you can revoke a collaboration from the project settings at any time.
Your data is stored on servers in the United States and Canada. We protect it with HTTPS everywhere, salted password hashing, per-workspace database isolation, role-based access controls, and regular software updates. No system is perfectly secure, but we work hard to keep your data safe.
Despite our safeguards, no system is perfectly secure. If we become aware of a security breach affecting personal information, we'll act without undue delay to investigate and contain it.
We retain Your Content for as long as your workspace is active. If you delete your workspace, we keep the data for 30 days in case you change your mind, then permanently purge it from our production database. System logs are kept for up to 90 days for security and debugging.
Deleted projects. When you delete a project inside an active workspace, it isn't erased immediately — it moves to a Trash where you can restore it, with all of its expenses, payments, files and notes, for 90 days. After that window it's permanently removed from the live database. You can also delete a trashed project sooner ("Delete forever").
Backups. We keep encrypted backups for disaster recovery. When you delete content or a workspace, it's removed from the live Service within the window above, but residual copies may persist in encrypted backups for a short additional period before they're overwritten on our normal backup rotation. We don't restore deleted data from backups except to recover from a system failure. Billing and tax records are kept longer where Canadian tax and accounting law requires it, even after a workspace is closed.
Depending on where you live, you may have the right to:
To exercise any of these rights, email support@mybookpad.com. We'll respond within a reasonable time and may need to verify your identity first.
If your personal information is in a My Book Pad workspace because a contractor you dealt with entered it (for example, you're a homeowner on one of their projects), that contractor is the controller of your information — please direct your request to that business. If you contact us, we'll help identify the right workspace and support the contractor in responding, but we can't change or delete that data without their instruction.
This section supplements the rest of this Policy for residents of US states with comprehensive privacy laws (such as California). The categories of personal information we collect are described in Section 2; in statutory terms these may include identifiers (name, email), commercial information (subscription and billing data), internet or network activity (log data), professional or business information, and — where you upload them — images of receipts and cheques. We collect these for the business purposes described in Section 4.
We have not sold or "shared" (for cross-context behavioral advertising) personal information, and we don't do so now. Depending on your state you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of sale/sharing. Because we don't sell or share, there's nothing to opt out of; if that ever changes we'll provide a clear "Do Not Sell or Share My Personal Information" mechanism and will honor Global Privacy Control (GPC) browser signals. We will not discriminate against you for exercising any right. You may use an authorized agent to make a request, and we'll verify identity before acting.
Where EU or UK data-protection law applies to our processing as a controller, we rely on: performance of our contract with you to provide and bill for the Service; our legitimate interests in securing the Service, preventing abuse, and improving the product through aggregate (non-content) analysis; your consent where we ask for it (for example, optional communications); and compliance with legal obligations such as tax record-keeping. Where we process your clients' data inside your workspace, we do so as your processor under the Data Processing Addendum referenced in Section 3.
We host the Service on infrastructure in the United States and Canada, and our service providers (Section 5 and our Subprocessors page) may process limited data in the countries where they operate. This means personal information may be transferred to and stored in a country other than your own.
When personal information of Quebec residents is processed outside Quebec, we assess that it will receive protection appropriate to its sensitivity. Where we transfer personal information of individuals in the EU, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum). You can request more information using the contact details in Section 17.
My Book Pad is built for businesses and isn't intended for anyone under 18. We don't knowingly collect information from children. If you believe a child has given us personal data, contact us and we'll delete it.
We may update this Privacy Policy from time to time. If a change is material, we'll notify you by email or by an in-product notice before it takes effect. The "Last updated" date at the top of this page always shows when the policy last changed.
This Service is operated by My Book Pad Inc., a corporation based in Ontario, Canada. We are the organization responsible for the personal information described in this Policy, and we've designated a Privacy Officer who is accountable for our compliance with applicable privacy laws — including personal information we transfer to the service providers listed above.
To reach our Privacy Officer with any question, request, or complaint, email support@mybookpad.com with "Privacy" in the subject line. If you're not satisfied with our response, you have the right to contact your local data-protection authority (see Section 11).