Skip to content
← TERM

Privacy Policy

What TERM collects, why, who it goes to, and how to get it removed. Financial data gets its own section.

Last updated: September 2, 2026

Contents

  1. 1. Scope
  2. 2. What we collect
  3. 3. Your accounting data specifically
  4. 4. How we use information
  5. 5. Legal bases
  6. 6. Who we share with
  7. 7. Retention and deletion
  8. 8. Security
  9. 9. Your rights
  10. 10. Cookies
  11. 11. International transfers
  12. 12. Children
  13. 13. Changes to this policy
  14. 14. Contact

1. Scope

This policy explains how Liam Kittok ("TERM", "we") handles information when you use https://www.term.business and the TERM application.

For accounting data you connect, you are the controller of that data and we process it on your instructions. For your own account and billing details, we are the controller.

2. What we collect

CategoryExamplesSource
AccountName, email address, authentication eventsYou, via our authentication provider
BillingBilling contact, plan, subscription status, payment method type and last four digitsYou, via our payment processor
Connected accounting dataTransactions, amounts, dates, vendor names, categories, company profileThe accounting system you connect
Access tokensOAuth access and refresh tokens for systems you connectThe provider, at the moment you consent
Usage and technicalPages viewed, actions taken, IP address, browser and device type, timestampsAutomatically, as you use the Service
SupportMessages you send us and their contentsYou

We do not receive or store full payment card numbers. Card details are submitted directly to our payment processor.

We do not intentionally collect special category data such as health or biometric information. Do not send it to us.

3. Your accounting data specifically

This is the most sensitive information the Service handles, so it is worth stating precisely.

  • We read accounting data only from the company you explicitly connect, and only within the permissions granted during that provider's consent screen.
  • Access is read-only in normal operation. Write access is exercised only to apply a change you have approved.
  • We use this data to operate the Service for you: organizing spend, detecting recurring commitments, surfacing renewals, and preparing suggestions.
  • We do not sell it, rent it, or share it for advertising.
  • We do not use your accounting data to train machine learning models for other customers.
  • You can disconnect at any time. Disconnection stops further access immediately.

4. How we use information

  • To provide, maintain, and secure the Service.
  • To authenticate you and keep your session active.
  • To take payment and manage your subscription.
  • To respond to support requests.
  • To detect, investigate, and prevent abuse, fraud, and security incidents.
  • To understand aggregate product usage so we can improve it.
  • To send service messages about your account, billing, or material changes. These are not marketing and you cannot opt out of them while you hold an account.
  • To comply with legal obligations.

5. Legal bases

Where data protection law such as the UK GDPR or EU GDPR applies, we rely on the following bases:

  • Performance of a contract — to deliver the Service you subscribed to.
  • Legitimate interests — to secure the Service, prevent abuse, and improve the product, balanced against your rights.
  • Consent — where you connect a third-party account, and for any optional communications. You may withdraw consent at any time.
  • Legal obligation — for tax, accounting, and lawful requests.

6. Who we share with

We do not sell personal information. We share it only with service providers who process it on our behalf under contract, and only as needed:

ProviderPurposeData involved
Intuit (QuickBooks Online)Source of the accounting activity TERM reads, once you connect a company.Transactions, vendors, and company profile from the company you authorize.
ClerkAccount creation, sign-in, and session management.Email address, name, authentication events, session identifiers.
StripeSubscription billing and payment processing.Billing contact and payment method. Card details go to Stripe directly.
VercelApplication hosting and delivery.Request metadata such as IP address and user agent, plus server logs.
NeonThe database TERM stores your workspace in.Imported transactions and commitments, workspace and membership records, billing identifiers, audit history, and encrypted accounting-provider tokens.
ComposioManages the connections to QuickBooks, Gmail, Outlook, and Slack, and carries the data TERM reads through them.The authorization granted for each connected account, and the provider records TERM reads through it — accounting activity, and mailbox or channel content for the integrations you choose to connect.

We may also disclose information where required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.

7. Retention and deletion

  • Account and connected data is retained while your account is active.
  • Access and refresh tokens are deleted when you disconnect a provider or close your account.
  • After account closure we delete or anonymize your data, except where we must keep records for legal, tax, or dispute-resolution purposes.
  • Backups and logs may persist for a limited period after deletion before they are overwritten on their normal cycle.

To request deletion, contact support@term.business.

8. Security

  • Data is encrypted in transit using TLS.
  • Access tokens for connected accounting systems are encrypted at rest using authenticated encryption.
  • Access to production systems is limited to personnel who need it.
  • Payment card data never reaches our servers.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by law.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Delete your information, subject to our legal retention obligations.
  • Receive a copy in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent where processing relies on it.
  • Complain to your local data protection authority.

Exercise any of these by contacting support@term.business. We will not discriminate against you for making a request. We do not sell or share personal information for cross-context behavioural advertising.

10. Cookies

We use cookies that are necessary for the Service to function. We do not use advertising cookies.

CookiePurposeLifetime
Session cookiesKeep you signed in and secure your session. Set by our authentication provider.Session or as set by the provider
OAuth state cookieProtects the accounting-system connection flow against cross-site request forgery.10 minutes, single use

11. International transfers

Our providers may process information in countries other than yours, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses.

12. Children

The Service is for business use and is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.

13. Changes to this policy

We may update this policy. Material changes will be notified by email or in the Service before they take effect. The date at the top of this page shows when it last changed.

14. Contact

Privacy questions and rights requests: support@term.business.

Terms of ServicePrivacy PolicyBack to TERM