Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how Bordaro ("Bordaro", "we", "us") collects, uses, shares, and protects information when you use the Bordaro financial dashboard at https://bordaro.app (the "Service"). Bordaro is a business tool: our customers connect their own commerce, accounting, and banking accounts so their team can see unified financial dashboards.
1. Information we collect
Information you provide
- Account information — name, email address, and password (stored as a secure hash; we never see your plaintext password) when you create an account or accept a team invitation.
- Feedback — anything you submit through the in-app feedback widget or by emailing us.
Information from connected services
When an administrator of your organization connects a third-party service, we sync business financial data on your organization's behalf:
- Shopify — orders, refunds, products, and payout data for your store.
- QuickBooks Online — expense and transaction records.
- Plaid — bank account balances and account names for accounts you link. Plaid's own privacy policy (plaid.com/legal) also applies to the connection process.
This data is business data about your organization. It may incidentally contain personal information (for example, customer names inside order records). Your organization controls that data; we process it only to provide the Service.
Information collected automatically
- Product analytics (PostHog) — pages viewed, features used (for example, which dashboard cards you open), browser and device type, and IP address. We do not enable analytics cookies until you accept them via the cookie banner (see Section 5).
- Error and performance data (Sentry) — when something breaks, we receive technical error reports (browser type, the page involved, and technical stack traces) so we can fix it. This is essential to operating the Service.
- Server logs — our hosting provider (Vercel) records standard request logs, including IP addresses, for security and operations.
2. How we use information
- Provide, maintain, and secure the Service;
- Sync and display your organization's financial data;
- Generate AI summaries of your dashboard data (see Section 4 — your data is not used to train AI models);
- Understand how the product is used so we can improve it;
- Send service emails such as team invitations and sync-failure alerts;
- Respond to support requests;
- Comply with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
3. Who we share information with
We share information only with service providers ("subprocessors") that help us run Bordaro, each bound to use it only for that purpose:
- Supabase — database, authentication, and hosting of application data;
- Vercel — application hosting and delivery;
- PostHog — product analytics (consent-gated);
- Sentry — error monitoring;
- Anthropic — AI summary generation (Section 4);
- Plaid, Shopify, and Intuit (QuickBooks) — the integrations you choose to connect;
- Resend — transactional email delivery.
We may also disclose information if required by law, to protect the rights and safety of Bordaro or others, or as part of a business transaction such as a merger or acquisition (in which case this policy continues to apply until updated).
4. AI features
Bordaro's drill-down summaries are generated by sending aggregated metrics from your dashboard (totals, percentage changes, and time periods) to the Anthropic Claude API. Summaries are cached so the same question is not sent twice. We use Anthropic's commercial API, which does not use customer data submitted via the API to train its models. AI summaries describe your data; they are not financial advice.
5. Cookies and consent
We use two categories of browser storage:
- Strictly necessary — authentication session cookies (Supabase) that keep you signed in, and a single value recording your cookie choice. These are required for the Service to function and don't need consent.
- Analytics — PostHog cookies and local storage that help us understand product usage. These are off by default. We set them only after you click "Accept" in the cookie banner. If you decline, analytics run without cookies or persistent identifiers for the current page view only, and no profile is built.
You can change your mind at any time by clearing your browser's site data for bordaro.app, which resets the choice and re-displays the banner.
6. Data retention
- Account data is kept while your account is active.
- Synced financial data is kept while your organization's subscription is active; after termination, it is retained for 30 days for export and then deleted.
- Analytics and error data are retained per our providers' standard windows.
7. Security
All traffic is encrypted in transit (TLS). Data is stored with row-level security so each organization can only access its own records. Integration tokens are stored server-side and never exposed to the browser. No method of storage is 100% secure, but we work to protect your information using industry-standard practices.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To exercise any of these rights, email support@bordaro.app. We will verify your request and respond within the timeframe required by applicable law. We will never discriminate against you for exercising your rights.
If you are an employee or team member of a Bordaro customer, note that your organization controls its workspace; we may route requests about organization data to your administrator.
9. Children
Bordaro is a business tool for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from children.
10. International users
Bordaro is operated from the United States and data is stored on U.S. servers. If you use the Service from outside the U.S., you consent to processing your information in the U.S.
11. Changes to this policy
We may update this policy as the Service evolves. We will post the updated version here and update the "Last updated" date; for material changes we will notify account holders by email or in-app notice.
12. Contact
Questions or requests: support@bordaro.app