Privacy Policy
Last updated: September 9, 2026
This Privacy Policy explains how Ethan McIntyre (“Parline”, “we”, “us”) collects, uses, shares, and protects personal information when you use the Parline bookkeeping application and the website at parline.app (the “Service”).
For personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland, the data controller is Ethan McIntyre, 829 Tappan Ave Unit 101, Ann Arbor, MI 48104, United States. Contact: support@parline.app.
1. Information we collect
1.1 Information you give us
- Account and profile. When you sign in with Google, we receive your name, email address, and Google profile-picture URL from Google. You can edit the name and picture in your account settings.
- Your books (financial data). The content you enter: companies/“books” you create, chart of accounts, journal entries and their line items (amounts, debits/credits, descriptions, dates), tags, budgets, closing dates, and any notes. If you upload a logo or banner image, we store that image.
- Team information. If you invite someone to your books, we store the email address you enter and the role you assign. If you are invited, the inviter’s name and the company name are shown to you.
- Support messages. If you contact us through the in-app help form or by email, we keep your message and our correspondence, along with your email address and (from the form) the page you were on and your browser’s user-agent string.
- Billing information. If you subscribe to Pro, our payment processor Stripe collects and processes your payment details. We do not receive or store your full card number. We store a Stripe customer ID, subscription status, plan, and billing-period dates.
- Marketing preference. Whether you have opted in to product-update emails.
1.2 Information we collect automatically
- Log and usage data. Our hosting provider (Vercel) and database provider (Supabase) generate server logs that include IP address, request time, pages or endpoints accessed, referring URL, and browser/device information. We use these for security, debugging, and reliability.
- Cookies and local storage. The Service uses: a session cookie set by our authentication provider to keep you signed in; an HTTP-only
les_<company id>cookie that coordinates edit locking so two browser sessions don’t overwrite each other’s changes; aparline.companycookie that remembers which set of books to open (about one year); and browser local storage keys prefixedparline:that hold unsent import or budget drafts and view preferences on your device only. We do not use advertising cookies, third-party analytics that track you across other sites, or cross-context behavioral tracking.
We do not knowingly collect special categories of data (such as health or biometric data). Please do not enter such data into free-text fields.
2. How we use information
We use personal information to:
- provide the Service — authenticate you, create and run your books, generate statements and exports, and coordinate access for the members you invite;
- process payments and manage your subscription through Stripe;
- communicate with you — send transactional email (a welcome message, invite notifications, support replies, billing notices); and, only if you opt in, send product-update (“marketing”) email, which always includes a one-click unsubscribe;
- provide support and respond to your requests;
- secure the Service — detect, prevent, and respond to fraud, abuse, security incidents, and technical problems, including rate limiting;
- improve the Service — understand which features are used and fix bugs, using aggregated or de-identified information where practical; and
- comply with law and enforce our Terms.
Legal bases (EEA/UK)
We rely on: performance of a contract (to provide the Service you signed up for and to bill you); legitimate interests (to secure and improve the Service, prevent abuse, and send transactional messages, balanced against your rights); consent (for marketing email; you can withdraw it at any time); and legal obligation (to keep certain records and respond to lawful requests).
3. AI-assisted import — what we do not do
Parline’s AI import feature does not transmit your financial data to any artificial-intelligence or large-language-model provider. The prompt is generated in your browser. If you choose to paste it into a third-party AI tool, your data goes to that tool under its own privacy policy, not ours, and that is your choice.
4. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information with:
- Service providers (“subprocessors”) that host and run the Service on our behalf, under contracts that require them to protect it:
| Provider | Purpose | Primary location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States (AWS us-west-2, Oregon) |
| Vercel | Application hosting and content delivery | United States |
| Sign-in (OAuth) | Global | |
| Stripe | Payment processing and the billing portal | United States / global |
| Resend | Sending transactional and opt-in marketing email | United States |
| Squarespace Domains (email forwarding, powered by Mailgun) | Receiving and forwarding email sent to support@parline.app | United States |
- Other members of your books. Anyone you invite to a set of books can see that book’s contents and your name and email address as a member. Their access is governed by the role you give them.
- Legal and safety. We may disclose information if we believe in good faith that it is required by law, legal process, or a governmental request, or is necessary to protect the rights, property, or safety of Parline, our users, or the public, or to investigate fraud or a security incident.
- Business transfer. If Parline is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honor this Policy or notify you of any material change.
5. International data transfers
Parline is operated from the United States and our providers are primarily in the United States. If you are outside the United States, your information will be transferred to and processed in the United States and other countries whose data laws may differ from yours. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) for such transfers.
6. Data retention
- We keep your account and books data for as long as your account is active.
- If you close your account or ask us to delete your data, we will delete or de-identify it within 30 days, except: copies in routine backups (purged within 90 days), and records we must keep to comply with legal, accounting, tax, or fraud-prevention obligations, or to resolve disputes and enforce agreements.
- Support messages are retained for 24 months.
- Server logs are retained by our providers for a limited period per their policies.
7. Your rights and choices
Depending on where you live, you may have some or all of these rights:
- Access / portability — get a copy of your personal data. You can export your books from within the app; for other data, email us.
- Correction — fix inaccurate data (name and picture are editable in settings).
- Deletion — ask us to delete your account and personal data (subject to the retention exceptions above).
- Objection / restriction — object to or ask us to restrict certain processing based on legitimate interests.
- Withdraw consent — turn off marketing email at any time via the unsubscribe link or your account settings; this does not affect processing already carried out.
- Complain — lodge a complaint with your local data-protection authority (EEA/UK) or attorney general (US).
California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to not be discriminated against for exercising these rights. We do not “sell” or “share” personal information as those terms are defined under California law.
To make a request, email support@parline.app from the address on your account. We may need to verify your identity before acting, and we will respond within the time the applicable law requires.
8. Security
We use technical and organizational measures to protect personal information, including encryption in transit (HTTPS), database row-level security that scopes each company’s data to its members, access controls, and reliance on Google sign-in rather than passwords we store. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
9. Children
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
10. Marketing email
We send product-update email only to people who opt in (from account settings). Every marketing email has a working one-click unsubscribe link, and unsubscribing takes effect promptly. You cannot opt out of essential transactional email (such as billing notices or security alerts) while you have an account, because we need it to run the Service.
11. Changes to this Policy
We may update this Policy. If a change is material, we will notify you by email or in the app before it takes effect. The “Last updated” date at the top shows the current version. Your continued use of the Service after a change takes effect means you accept the updated Policy.
12. Contact
Ethan McIntyre
829 Tappan Ave Unit 101, Ann Arbor, MI 48104, United States
Privacy, data requests, and general support: support@parline.app