Privacy Policy — Ledgerline
Vantrel Consulting · Last updated: 10 September 2026
This policy describes what Ledgerline accesses, why, who else sees it, and what we do with it. Every claim in it was written against the code that implements it and can be checked against that code.
Who we are
Ledgerline is operated by Vantrel Consulting, a sole proprietorship of Bennett Fountain, located in the State of Florida, United States. We install and run software agents inside a business's existing systems — accounting, email — so the business gets the benefit without doing the integration work.
We are the data processor for the business records our clients connect. The client remains the controller of their own accounting and mailbox data. Where a client's own customers or vendors appear in that data, we process it only to provide the service the client asked for, on that client's instructions. The terms governing that relationship are in our Data Processing Addendum.
Questions, requests, or complaints: support@vantrelco.com
What we access, and why
We only ever connect systems a client explicitly authorises, through that provider's own consent screen.
A client can end either connection at any time, in two ways that both work without our involvement. From Disconnect inside the service: we ask the provider to cancel our access, then delete the stored credentials — and if the provider cannot be reached to confirm the cancellation we say so plainly rather than reporting it as done. Or from the provider's own settings, which stops our access at their end immediately. Reconnecting afterwards means granting permission again, which we set up.
Accounting system (QuickBooks Online) — read only. Bills, vendors, purchase orders, payments and accounts. Used to check an invoice against the client's own records: whether a bill is a duplicate, whether the vendor has been paid before, whether it matches a purchase order.
We do not write to a client's accounting system. Not "writes require approval" — there is no code capable of it.
Accounts payable mailbox (Microsoft 365) — read only. Messages and attachments in the mailbox a client nominates for supplier invoices. Used to find invoices that arrive by email and read what they say.
We hold the Mail.Read permission and nothing else. We cannot send, reply to,
move or delete mail. Where a client scopes the permission to a single mailbox —
which we recommend and help configure — we cannot read any other.
Accounts. For people who sign in: email address, display name, and a password stored only as a scrypt hash. We never store a password. Sessions are stored as a SHA-256 hash of the session token, so a copy of our database does not let anyone sign in.
What the service produces. Invoices read out of email, the questions the agent raised, the decisions a client made in response, and a plain-language history of what the agent did.
What we do not collect
- Payment card numbers, bank account numbers or payment credentials. We hold no means of moving money and never ask for one.
- Anything from systems a client has not connected.
- Personal data about anyone for advertising, profiling or resale. We do not sell or share personal data, and we do not use it for targeted advertising.
We also do not use client data to train models, and we do not use one client's data to improve the service for another.
Who else processes it
Providing this service means data reaching a small number of others. We use no others without updating this list and telling our clients first.
| Who | What reaches them | Why | Where |
|---|---|---|---|
| Anthropic, PBC | Bill details, invoice text, email content and attachments from the connected mailbox | The agent that reads and checks invoices runs on their platform | United States |
| Intuit Inc. | Read requests against the client's own company | Retrieving the client's accounting records | United States |
| Microsoft Corporation | Read requests against the client's nominated mailbox | Retrieving invoices that arrive by email | United States |
| DigitalOcean, LLC | Everything stored, as data at rest on the server | Running the service | United States (New York) |
| Backblaze, Inc. | Nightly database backups, encrypted before they leave our server | Holding a copy of the backups somewhere other than the machine they came from | United States |
Content a client's supplier writes — an invoice, an email body — is sent to Anthropic as part of processing it. Clients should know that before nominating a mailbox.
Each of these is bound by its own agreement with us to process data only to provide its service. Where a client needs the specifics of one of those agreements, we will provide what we are permitted to share.
Where it is held, and how it is protected
Our servers are in New York, in the United States. Nightly backups are kept on that server and copied to storage held by Backblaze, also in the United States. We do not transfer client data outside the United States, and the processors above are engaged on their United States infrastructure.
Backups that leave our server are encrypted first, with a key whose secret half is not held on that server. Neither the storage provider nor anyone who obtained a copy of the stored files could read them, and neither could our own server: it can add to the archive and cannot read it back.
- Credentials for connected systems are encrypted at rest using AES-128 in CBC mode with HMAC-SHA256 authentication, with the key held separately from the database and supporting rotation. Losing that key makes stored connections unreadable rather than exposed. The system refuses to store a credential at all if no key is configured, rather than falling back to storing it in the clear.
- Each client's credentials are stored separately. One client's connection cannot be used to reach another's data.
- Access is scoped by account. A client's users see their own organisation and nothing else — enforced by the server on every request, not by the interface hiding things. This is verified by an automated test that was confirmed to fail when the scoping is removed.
- Passwords are hashed with scrypt and sessions are stored only as a SHA-256 hash of the session token. Sign-in attempts are rate-limited.
- Traffic is served over TLS. Session cookies are HttpOnly, SameSite=Lax and marked Secure, and are not readable by scripts.
- Credentials are never written to logs. Anything credential-shaped is replaced with its length before any diagnostic output.
- Documents from outside are parsed in an isolated process with a time limit, because a supplier's PDF is a file written by a stranger.
We are a small operation and say so plainly: there is no 24-hour security team. What there is, is a narrow attack surface by design — read-only access to everything we touch, and no capability to move money.
How long we keep it
Decisions and history are kept for the life of the account, and are not deleted on request while the account is open. They record who approved what, when, and what they were shown at the time. A record of decisions about money that can be edited afterwards is not a record. If this conflicts with a client's own retention obligations, we will discuss it before they sign up.
Invoices read from email, and the connected-system data we cache to answer a question, are kept while the account is open.
On account closure, we delete client data within 30 days, except where we are required by law to keep it. Credentials are deleted immediately. Backups containing deleted data age out on the ordinary backup cycle and are not restored to reinstate deleted records.
Rights
Depending on where a client or the people in their records are, they may have rights to access, correct, export or delete personal data, to opt out of sale or sharing — which we do not do — and to object to processing. Requests to support@vantrelco.com; we respond within 30 days. We do not charge for this and we will not treat anyone differently for asking.
Because we are a processor for our clients, a request from their customer or vendor should normally go to the client, and we will support them in answering it. Where a request reaches us directly, we will pass it to the client and tell the person that we have done so.
Florida residents. The Florida Digital Bill of Rights applies to controllers with more than $1 billion in global gross annual revenue. We are far below that threshold, so it does not apply to us. We describe our practices here anyway, because the size of a company is not a reason for the people it serves to be told less.
Security incidents
If personal data is exposed in a way that puts anyone at risk, we will tell affected clients without undue delay and in any case within 72 hours of becoming aware, with what happened, what was affected, and what we are doing about it. We will not wait until we understand it completely before saying something has happened.
That 72-hour commitment is deliberately shorter than what the law requires of us. As a third-party agent holding personal information on behalf of our clients, Florida law requires us to notify the client within 10 days of determining that a breach has occurred. Our clients then have their own statutory obligations, which for Florida residents include notifying affected individuals within 30 days and, for breaches affecting 500 or more Florida residents, notifying the Florida Department of Legal Affairs. We will give clients the information they need to meet those deadlines, and in time to be useful.
Children
Ledgerline is a business service. It is not directed at children and we do not knowingly collect personal data from anyone under 18.
Changes
Material changes are announced to clients before they take effect. The date at the top of this page is the last time it changed, and the version history lives in our source repository alongside the software it describes.
Contact
support@vantrelco.com Vantrel Consulting · State of Florida, United States