Privacy Policy
Last updated August 3, 2026PactTailor

Privacy details for a high-trust bookkeeping workspace.

This Privacy Policy explains what PactTailor collects, how it is used, who helps process it, how long it is kept, and how to request access, correction, export, or deletion.

Who controls the data

PactTailor controls the personal data described in this notice for the PactTailor website, product, and related support operations. Privacy questions and requests can be sent to hello@pacttailor.com.

What PactTailor collects

  • Account data: full name, workspace name, work email address, password hash or authentication credentials, account status, and related security logs.
  • Single sign-on data: Google account identifiers and profile details needed to authenticate and associate a user with a PactTailor workspace.
  • Product data: proposals, tasks, client records, workspace records, notes, approvals, billing configuration, imported spreadsheets, and similar operational data entered by users.
  • Payments metadata: Stripe customer, subscription, invoice, checkout, and payment-link metadata. Raw payment card details are processed by Stripe, not by PactTailor.
  • Analytics and attribution data: utm parameters, gclid, fbclid, li_fat_id, landing path, landing variant, referrer information, cookies or local-storage identifiers, and first-party analytics events. Analytics starts enabled by default and can be turned off from cookie settings; attribution remains preference-controlled.
  • Support and contact data: emails, attachments, and operational context shared with PactTailor support.

How PactTailor uses data

  • To create accounts, authenticate users, secure sessions, and prevent abuse or fraud.
  • To deliver the core service, including proposals, tasks, billing, payments, onboarding, and workspace collaboration.
  • To process subscriptions, reconcile billing activity, and support refunds, credits, disputes, or chargeback review.
  • To measure product performance and improve workflows through default-on first-party analytics, unless a visitor turns analytics off.
  • To measure campaigns, referrals, and landing-page performance when attribution consent is enabled.
  • To respond to support requests and comply with legal, security, or accounting obligations.

Who PactTailor shares data with

  • Supabase for authentication, database storage, and related backend operations.
  • Stripe for checkout, subscriptions, invoices, payment links, and payments metadata.
  • Google when a user chooses Google Sign-In.
  • First-party analytics processors for product and website analytics when analytics consent is enabled.
  • Vercel and infrastructure providers for hosting, delivery, logging, and application operations.

PactTailor may also disclose data when reasonably necessary to enforce terms, protect users, detect security incidents, respond to lawful requests, or complete a corporate transaction.

Retention

  • Account and workspace records are generally kept while the account is active and for a limited period afterward to support security, bookkeeping, legal, and audit needs.
  • Billing and payment metadata may be kept for longer where required for financial records, dispute handling, fraud prevention, or tax compliance.
  • Analytics identifiers are retained according to tool settings and the consent choices a visitor makes.
  • Referral and attribution data is retained according to campaign settings, including partner attribution windows where applicable.

User rights and requests

Depending on location and applicable law, users may have rights to request access, correction, deletion, export, portability, objection, or restriction for certain personal data.

To submit a request, email hello@pacttailor.com with enough detail for PactTailor to verify the request and find the relevant workspace or account. PactTailor may need to verify identity before completing a request.

Cookies and tracking

PactTailor uses essential cookies for authentication, security, and session continuity. First-party analytics is enabled by default unless a visitor turns it off. Referral or attribution measurement remains controlled through the cookie banner and settings center.

See the dedicated cookie policy for more detail or open to change preferences at any time.

International transfers

PactTailor may process or store data in countries other than the user’s home country. When that happens, PactTailor uses contractual, technical, and organizational safeguards appropriate to the transfer.

Security

PactTailor uses a mix of access controls, transport security, provider security features, logging, and operational review intended to protect personal data. No system can promise absolute security, so users should also use strong credentials and protect workspace access carefully.

Children

PactTailor is not directed to children under 13 and is intended for business use. PactTailor does not knowingly collect personal data from children under 13.