Privacy Policy

Simplance was designed for freelancers who demand ownership and clarity. We never sell data, and we only collect what powers the experience you asked for. Every integration connects only with your explicit permission.

Last updated March 20, 2026

Privacy at a Glance

Privacy-First Design

Secure authentication and database. No hidden scrapers, no data selling. Optional integrations only connect with your explicit authorization.

Transparent Analytics

We only track in-app events to improve features. Respect DNT, no ad retargeting, opt-out anytime.

Your Control

Delete or update every business, client, or profile record from Settings. Export your data anytime from Settings.

Data You Choose to Give Us

Account & Profile

  • Email + password or Google OAuth for sign-in. Passwords are hashed by our auth provider — Simplance staff never see plain-text passwords.
  • • Profile fields you opt in to share (bio, website, social links, avatar).
  • Subscription tier and billing preferences (if you upgrade to Pro tier). Stripe customer reference for billing management only.
  • • Notification preferences, feature toggles, and saved layout states (stored securely in your browser and our database).

Workspaces & Financial Data

  • • Business records, invoices, proposals, and expense entries you manually create.
  • • Assets you upload (receipts, business logos, client images) and CSV imports you submit.
  • • Community business shares: business name, type, industry, cover image, and optional details captured at the moment you post.

Invoicing & Client Data

  • • Invoice details you create: line items, amounts, dates, payment terms, and notes.
  • • Client records: name, email, company, phone, and mailing address.
  • Payment link URLs (via Stripe, Square, or PayPal) generated for invoice collection (the provider processes the payment; we store the link reference).

Platform Integrations

  • Stripe Connect: charges, refunds, transaction metadata, customer emails, and payment descriptions synced from your connected Stripe account.
  • Square: payment and order data synced from your connected Square account for payment link generation.
  • PayPal: invoice and payment data from your connected PayPal account for payment link generation.
  • Bank connections via Plaid: bank transaction data (amounts, dates, merchant names, balances) from accounts you link.
  • • OAuth tokens stored encrypted (never logged, server-side only).
  • • You authorize each connection explicitly and can revoke access anytime from Settings.

Expenses, Taxes & Business Info

  • • Expense entries: amount, category (IRS Schedule C), vendor, date, deductibility, and optional receipt images.
  • • Tax settings: filing status, state, deduction method, retirement contributions, and health insurance amounts. Used to estimate (not file) taxes.
  • • Business profile: name, email, and business structure (sole proprietor or single-member LLC).
Simplance never auto-connects to accounts without your permission. All income data is either entered by you manually or synced from platforms you explicitly authorize (like Stripe Connect). You can disconnect integrations and stop syncing at any time from Settings. When you generate a payment link for an invoice (via Stripe, Square, or PayPal), the payment provider processes the payment — we store only the link reference and payment status.

How & Why We Use Data

Deliver the product

Render your dashboards, analytics, invoices, and notifications. Legal basis: contract.

Sync & back up

Store entries securely in our database, with daily encrypted backups. Legal basis: contract.

Improve Simplance

Analyze aggregated product usage to prioritize features. Legal basis: legitimate interest. No behavioral ads.

Support & safety

Respond to support tickets, fight spam, and moderate public posts. Legal basis: legitimate interest.

Sync platform data

Sync income and transactions from platforms you connect (Stripe Connect, Plaid bank connections). Data used to populate your income dashboard and expense tracking. Legal basis: consent (you authorize each connection).

Process payments

Generate payment links for invoices (via Stripe, Square, or PayPal) and process Pro subscription charges via Stripe. Legal basis: contract.

Community & Public Sharing

Community sharing is optional. When you publish a business share you pick a visibility setting:

  • Unlisted: Accessible to anyone with the link (requires sign-in).
  • Public: Shows up in the community feed.

Public shares display your profile (display name, avatar, bio, website) and your business details (name, type, industry, logo, cover image). Email addresses stay private. You can delete a share at any time; deleted shares disappear immediately from public feeds.

Security, Retention & Location

In Plain English:

We protect your financial data using the same security methods that banks use. Your information is encrypted (scrambled), and only you can access your own records.

Technical safeguards

  • • Secure architecture ensures only you can access your own records.
  • • Bank-level encryption protects your data at all times.
  • • Passwords are hashed by our auth provider; Simplance staff never see plain-text credentials.
  • • Restricted access for maintenance operations.

Retention & deletion

  • • Active data lives in North America-based servers.
  • • Daily encrypted backups retained up to 30 days for disaster recovery.
  • • Account deletion removes active data immediately; backups purge within 30 days.
  • • Support logs are stored until the ticket is resolved plus 12 months for auditing.

Payment & Subscription Data

In Plain English:

When you subscribe to the Pro tier, we store basic billing information (which plan you have, when it started/ends). Your credit card details are stored by Stripe, not Simplance. We never see or touch your payment card information.

What Subscription Data We Collect

  • Subscription tier (free or pro) and billing period (monthly or annual)
  • • Subscription status (active, canceled, past_due, etc.)
  • • Start date, end date, and whether you've scheduled cancellation
  • • Stripe customer ID and subscription ID for billing management only
  • Add-on subscription IDs for extra business add-ons, linked to your account for billing management
  • • Invoice payment link IDs and payment status (paid/unpaid) for invoices with payment links (Stripe, Square, or PayPal)

Credit Card Security

  • • Stripe is PCI-DSS Level 1 compliant (the highest security standard for payment processors)
  • • Simplance never receives, never sees, and never stores your credit card details
  • • All payment data lives in Stripe's secure vault
  • • You manage payment methods through the Stripe Customer Portal (accessible from Settings)
  • • When your clients pay an invoice via a payment link, their payment data is handled entirely by the provider (Stripe, Square, or PayPal) — Simplance never receives or stores client payment details

Connected Platform Data

  • What we access: charges, refunds, amounts, dates, descriptions, and customer info from Stripe Connect; payment and order data from Square; invoice and payment data from PayPal; transaction amounts, dates, merchant names, and balances from Plaid bank connections.
  • Token storage: access tokens stored encrypted server-side only (never logged or exposed to the browser).
  • On disconnect: tokens deleted immediately; historical synced data retained until you delete it.
  • On account deletion: all integration data deleted (tokens + synced income records).

Retention Policy

  • • Subscription data is kept for the duration of your subscription plus 7 years for tax and accounting compliance
  • • When you cancel, we retain your subscription history for billing reconciliation and tax reporting
  • • Stripe retains payment method details according to their privacy policy

How to Access Your Subscription Data

  • • View your current plan, billing period, and renewal date in Settings
  • • Export your subscription history via Settings
  • • Download invoices and receipts through the Stripe Customer Portal

Trusted Processors

Secure Database & Authentication

Stores your data with enterprise-grade security and privacy controls. Also handles transactional emails (verification, password reset).

View policy →

Stripe Payment Processing

Secure payment processing for Pro subscriptions and optional income syncing via Stripe Connect. PCI-DSS compliant; Simplance never stores credit card details. Stripe Connect tokens stored encrypted and revocable anytime.

View policy →

Square Payment Processing

Payment link generation for invoices via Square. Square handles checkout and payment processing securely.

View policy →

PayPal Payment Processing

Invoice creation and payment collection via PayPal. PayPal handles payment processing and buyer protection.

View policy →

Plaid Bank Connections

Securely links your bank accounts to sync transactions and balances. Simplance never receives your bank login credentials — Plaid handles authentication directly.

View policy →

Google Sign-In

Single-sign-on. Simplance never sees your password.

View policy →

Privacy-First Analytics

Product analytics to improve features (respects DNT, no ads).

View policy →

Spam Protection

Keeps support forms free from bots and spam.

View policy →

AI Financial Advisor

Powers the AI Advisor feature using Anthropic's Claude. Your financial summary is sent to generate personalized advice. No data is stored by Anthropic beyond the request.

View policy →

Hosting & Performance

Fast, reliable hosting for the Simplance web app.

View policy →

Cookies, Local Storage & Opt-Outs

We rely on three categories of browser storage:

  • Essential: Authentication tokens keep you signed in.
  • Preferences: Browser storage remembers layout, theme, and onboarding dismissals.
  • Analytics: Anonymous tracking for feature improvement. Disabled automatically when DNT is enabled or you opt out.

You can clear or block any of these via your browser. Disabling essential storage prevents login; disabling analytics has no product impact. Read the full Cookie Policy for detailed lifetimes.

Your Rights & Controls

Access & Portability

Download your complete data export (CSV format) from Settings, or contact support for JSON format.

Rectification

Update any business, profile field, or notification preference immediately in-app.

Erasure

Delete businesses, community posts, or your full account. Deleted data leaves backups within 30 days.

Restriction

Disable analytics via your browser's Do Not Track setting or by blocking analytics cookies. Simplance respects DNT automatically.

Objection

Contact us to opt out of legitimate-interest processing (analytics/support retention).

Complaints

Email support@simplance.org and we'll respond promptly.

UK Visitors

UK GDPR (the UK's post-Brexit data protection regime) applies to UK residents. It parallels the EU GDPR with substantively the same rights, which are already enumerated in "Your Rights & Controls" above (access, rectification, erasure, restriction, objection, portability, complaint).

Data residency: Simplance stores user data in the United States (Supabase, AWS us-east-1). Transfers from the UK to the US rely on the UK Extension to the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable. We do not transfer your data outside of these safeguards.

Supervisory authority: If you believe we're processing your personal data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. We'd appreciate the chance to address your concern first via support@simplance.org.

Lawful basis for processing: we process your account and financial data under "contract" (we need it to provide the service you signed up for) and process analytics under "legitimate interest" (improving the product), which you can object to at any time. Marketing emails are sent only with your explicit consent and you can unsubscribe at any time.

Need to Talk to a Human?

Email support@simplance.org or open the in-app support form. We use spam protection to verify legitimate requests; this only receives your IP and browser metadata to prove you're human.

Support messages are stored securely until resolved, then retained for auditing purposes before deletion.

Policy Updates

When we materially change this policy, we'll email all registered users and display an in-app banner. We timestamp changes, keep an archive of prior versions, and require re-consent for anything that expands how we process personal data.