Privacy Policy
LedgerDo LLC, an Iowa limited liability company
Effective Date: September 18, 2026
LedgerDo LLC (“LedgerDo”, “we”, “our”, or “us”) provides cloud-based business management software for automotive repair, construction, landscaping, and similar service businesses.
This Privacy Policy explains how we collect, use, disclose, and protect information when you visit ledgerdo.com, use the LedgerDo web application, use the LedgerDo mobile app for technicians, or use MyDVI, our digital vehicle inspection product. Together these are the “Services”.
LedgerDo is a business-to-business service. Most personal information we hold belongs to the customers of the shops that use LedgerDo. We process that information on the shop’s behalf and under its instructions, as described in our Data Processing Addendum.
1. Information We Collect
A. Information Provided by Account Holders (Shops)
When a business creates an account, we collect:
- Business name and address
- Account owner and staff names
- Email addresses and phone numbers
- Billing details
- Payment method (collected and stored by Stripe, not by LedgerDo)
- Acceptance records for our Terms of Service and Data Processing Addendum, including the date, the DPA version accepted, and the IP address and browser used to accept
B. Information Processed on Behalf of Shops
LedgerDo processes data entered by shops and their customers, including:
- Customer names, email addresses, phone numbers, and mailing addresses
- Vehicle information, including VIN, year, make, model, mileage, and license plate
- Property and job-site addresses, project and equipment details, and seasonal or recurring service contracts
- Estimates, work orders, invoices, payments, and service history
- Digital inspection results, photos, technician notes, and customer approval decisions
- Customer signatures captured on completed work
- Messages exchanged between a shop and its customers through LedgerDo
- Warranty, fleet, and recurring-service records
- Internal employee accounts, time clock entries, and job assignments
This information is processed strictly on behalf of our customers under our Data Processing Addendum. The shop, not LedgerDo, decides what to collect and how long to keep it while its account is open; the retention limits in Section 8 apply when an account closes.
C. Messaging Information
When SMS/MMS or related messaging features are used, LedgerDo may process:
- Phone numbers
- SMS consent status, timestamp, source, and related notes
- Opt-out and help-request status
- Message content and message metadata
- Sender, recipient, routing, and delivery information
- Provider message identifiers, delivery status, errors, and timestamps
Customer messaging data may be visible to the business account associated with that customer.
D. Information From Connected Services
When a shop connects a third-party service, we receive only what that integration needs:
- Google Calendar: the connected Google account’s email address and identity, the list of calendars on that account, and free/busy and event details for the calendars the shop selects. See Section 5 for how we use Google data.
- Square and QuickBooks: payment and accounting records needed to sync transactions the shop chooses to sync.
- Parts and labor data providers: when a shop looks up parts, labor times, or recalls, the vehicle identifiers and job description needed for the lookup.
- Your own email provider: a shop may configure its own SMTP service for the email LedgerDo sends to its customers. Recipient addresses and message content then pass through that provider under the shop’s own agreement with it.
E. Information From the Mobile App
The LedgerDo mobile app for technicians collects, with your permission where the device requires it:
- Camera and photos: photos you take or choose to attach to inspections and work orders. Photos are uploaded to LedgerDo and stored with the related record.
- Signatures: customer signatures drawn on the device and attached to the work order.
- Push notification token: a device token issued through Expo’s push notification service so we can deliver job and message notifications. We do not receive your device’s advertising ID.
- Biometric unlock: if you enable fingerprint or face unlock, verification happens entirely on your device. LedgerDo never receives biometric data.
- Offline data: work orders and edits you make while offline are stored on the device until they sync.
The mobile app does not access your contacts, location, microphone, or files outside of the photos you choose.
F. Automatically Collected Information
When you use the Services we automatically record:
- IP address, browser type, and device type
- Pages and features used, and actions taken inside the product (first-party usage records used to improve the product and support customers)
- Security and audit logs, including sign-in attempts, session activity, and administrative actions
- When a customer approves an estimate, work order, or inspection through a link a shop sent them, the time, the decision, the name and email they provide, and the IP address and browser used
We do not use third-party analytics, advertising, or tracking SDKs on our website, web application, or mobile app. Usage records are collected by LedgerDo directly and are not shared with advertisers.
G. Cookies
We use only cookies that are necessary to operate the Services: a session cookie that keeps you signed in, a security (CSRF) cookie that protects forms from forgery, and, if you choose “remember me,” a longer-lived sign-in cookie. We do not set advertising or third-party tracking cookies. Because these cookies are essential, there is no cookie banner; you can clear or block them in your browser, but the Services will not work without the session and security cookies.
2. How We Use Information
We use information to:
- Provide, maintain, and secure the Services
- Process payments and manage subscriptions
- Provide customer support
- Send, receive, route, deliver, and log service-related messages
- Maintain consent and opt-out records
- Troubleshoot delivery issues and prevent messaging abuse
- Generate labor estimates and answer help questions using AI features (see Section 4)
- Improve system performance and product features
- Detect and prevent fraud or abuse
- Comply with legal obligations
We do not sell personal information, including customer phone numbers or SMS consent data. SMS consent is not shared with third parties for their independent marketing.
3. Legal Basis for Processing (If Applicable)
If subject to GDPR or similar laws, we process personal data based on:
- Contractual necessity
- Legitimate interests
- Legal obligations
- Consent (where required)
4. AI Features
Shop AI features run on the shop’s own AI account, not ours. Features such as AI labor estimates are turned off until a shop connects its own provider (Anthropic, an OpenAI-compatible service, or Ollama) and API key under Settings → AI & Automation. When a shop does so, requests go directly from LedgerDo to that provider under the shop’s own agreement with it. For labor estimates we send the vehicle year, make, and model, the description of the job, and, where available, summaries of that shop’s own completed jobs. We do not send customer names, contact details, or VINs. LedgerDo does not operate a platform-wide AI provider for shop or customer data.
Help assistant. The in-app help assistant is the one AI feature that runs on a LedgerDo-owned key, with Anthropic. It receives only the question a staff member types and excerpts from our published help articles. It never receives shop, customer, vehicle, or financial records. We use Anthropic’s commercial API, which does not use API inputs to train Anthropic’s models.
AI output is a suggestion for shop staff to review and is never sent to a shop’s customers automatically.
5. Google User Data
If a shop connects Google Calendar, LedgerDo requests only the Google scopes needed for the calendar features the shop enables: basic account identity and email, the list of calendars on the account, and, where the shop chooses calendars to sync, free/busy information and the ability to create and update appointment events on those calendars.
We use Google user data solely to display availability, avoid double-booking, and keep the shop’s selected calendars in sync with its LedgerDo schedule. We store the connected account email, calendar list, encrypted OAuth tokens, and synced event references. We do not use Google user data for advertising, and we do not sell it or transfer it to third parties except as needed to operate the feature, with the user’s consent, for security purposes, or to comply with law. Human access to Google user data is limited to what is needed for support, security, and legal compliance, or with the user’s explicit consent.
LedgerDo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A shop can disconnect Google Calendar at any time from its LedgerDo settings, which deletes the stored tokens, or revoke access from its Google account permissions page.
6. Sharing of Information
We share information only with service providers that help us run the Services, and only what each one needs:
- Stripe (payment processing, subscriptions, and payouts)
- Twilio and other communications providers, as needed to send, receive, route, deliver, log, support, or secure messages
- Anthropic (in-app help assistant only, as described in Section 4)
- The AI provider a shop chooses to connect for its own AI features (under the shop’s own account, see Section 4)
- Google (Calendar sync, where a shop connects it)
- Square and QuickBooks (payments and accounting, where a shop connects them)
- PartsTech, MOTOR, and the U.S. National Highway Traffic Safety Administration (parts, labor time, VIN decoding, and recall lookups)
- Cloudflare (DNS, security, CDN, and storage of uploaded photos and files)
- Expo (mobile push notification delivery)
- Hostinger (server hosting, database, and transactional email delivery)
- The email (SMTP) provider a shop chooses to connect for its own customer email, where enabled (under the shop’s own account)
A current list of these providers is published on our Subprocessors page. We require service providers that store or process data for us to maintain appropriate safeguards and to process data only on our instructions. Lookup services (PartsTech, MOTOR, and NHTSA) receive only the vehicle identifiers and job details needed to answer a query and handle them under their own terms. Search indexing runs on software we host on our own servers and is not shared with any third party.
Between LedgerDo products. LedgerDo and MyDVI are both operated by LedgerDo LLC. When a shop links a MyDVI account to its LedgerDo account, customer, vehicle, and work order records are synchronized between the two products so the shop sees one record in both places.
We may also disclose information to comply with law, enforce our agreements, or protect the rights, property, or safety of LedgerDo, our customers, or others.
Phone numbers and messaging information are shared only as needed to provide, operate, support, or secure the relevant service. They are not provided to third parties for those third parties’ independent marketing.
7. Data Security
We implement reasonable safeguards including:
- HTTPS encryption for all traffic, including the mobile app
- Encrypted storage of integration credentials and API keys
- Role-based access controls and tenant data isolation
- Firewall protections and rate limiting
- Regular software updates
- Secure, tested backup procedures
No system can guarantee absolute security. See our Security page for how to report a vulnerability.
8. Data Retention
We retain information as follows:
- Account and shop data: for as long as the account is active. When an account is closed, its records and uploaded files (photos, inspection media, receipts, attachments) are deleted or anonymized within 90 days, except for the categories below that we must keep longer. Shops should export any invoices or records they need for their own tax purposes before closing.
- Our billing records for your subscription: invoices, payments, refunds, and dispute records for what you pay LedgerDo are kept for 7 years after the transaction to meet tax and accounting obligations, including after the account is closed.
- Messaging consent and opt-out records: phone number, consent or opt-out status, how consent was collected, keyword, and timestamps are kept for at least 4 years after the last message, including after the account is closed, to demonstrate consent and comply with carrier and regulatory requirements. This includes consent recorded on a customer’s profile, which is copied to a minimal archive before the profile is deleted. Message content and provider payloads are deleted with the account.
- Security, sign-in, and audit logs: up to 12 months. A scheduled job removes older records.
- Product usage records: up to 24 months. A scheduled job removes older records.
- Backups: encrypted backups are kept on a rolling schedule (daily for 14 days, weekly for 8 weeks, monthly for 12 months, and yearly for 3 years). Data deleted from live systems ages out of backups on that schedule and is restored only for disaster recovery.
Before an account is closed, the shop may export its records as a JSON file from the settings area, download photos and attachments from each record, or request a bulk copy of stored files from support.
Inactive accounts. If an account has no active or past-due subscription and shows no activity for 90 days, we may email the account owner a warning. If the account is still inactive 30 days later, its data may be deleted or anonymized on the same schedule as a closed account. Signing in during that period keeps the account open.
9. SMS Choices and Communications
Recipients may reply STOP to opt out of SMS/MMS messages and HELP for help. Message frequency varies, and message and data rates may apply.
Opting out of SMS does not necessarily stop non-SMS communications. Customers may still receive email, portal messages, invoices, or legally or operationally necessary communications where appropriate.
More information is available on our SMS Consent and Messaging page and in our Terms of Service.
10. Your Rights and Choices
Depending on jurisdiction, individuals may have rights to:
- Access personal data
- Request correction
- Request deletion
- Restrict processing
- Data portability
If you are a customer of a shop that uses LedgerDo, please direct requests to that shop, which controls your data. If you submit a request directly to LedgerDo, we will forward it to the appropriate shop and assist them in responding.
Shop account holders and staff, including mobile app users, may request deletion of their account data through our data deletion request form or by emailing [email protected]. We respond within 30 days.
Mobile app users can stop push notifications at any time in the app’s notification settings or the device’s app settings, and can remove all locally stored data by signing out or uninstalling the app.
11. International Transfers
LedgerDo operates in the United States. Data is stored and processed primarily on U.S.-based infrastructure; our hosting and email provider is headquartered in the European Union and may perform support operations from there. If you use the Services from outside the United States, your information will be transferred to and processed in the United States.
12. Children’s Privacy
LedgerDo is not intended for individuals under 18. We do not knowingly collect data from children.
13. Changes to This Policy
We may update this Privacy Policy periodically. The effective date at the top of this page shows when it last changed. Material changes will be posted on our website and, for account holders, announced by email or in-product notice at least 30 days before they take effect.
14. Contact Information
LedgerDo LLC
6701 CORPORATE DR
STE N
JOHNSTON, IA, 50131, USA
Email: [email protected]