Privacy Policy

Last updated 30 August 2026. This policy explains how SoloLedger handles personal data under the EU General Data Protection Regulation (GDPR), as applied across the EEA, and the UK GDPR.

1. Who we are

SoloLedger (“we”, “us”) provides a child-expense record-keeping service for separated parents. We are the data controller for the personal data described in this policy.

Contact for privacy matters: hello@solo-ledger.co. All privacy enquiries are handled by email.

2. What data we collect

  • Account data: email address, password (stored only as a salted hash by our authentication provider), account creation and sign-in timestamps.
  • Child records you enter: the child’s first name or reference and date of birth. Do not enter more identifying detail than you need.
  • Expense records: description, category, amount, currency, date, payment status, split share, notes and any receipt images or documents you upload.
  • Payment data: purchase status, access expiry and the payment reference returned by Stripe. Card details are entered on Stripe’s systems and are never received or stored by us.
  • Communication preferences: whether you opted in to expense reminder emails and delivery records for those emails.
  • Technical data: essential session storage, security logs and error diagnostics generated when you use the service.

We do not run advertising trackers, we do not sell personal data, and we do not profile you or make automated decisions with legal effects.

3. Why we use it and our legal basis

  • Contract (Art. 6(1)(b)): creating your account, storing your ledger, generating PDF reimbursement reports and providing paid access for the purchased term.
  • Legal obligation (Art. 6(1)(c)): keeping transaction and tax records for payments.
  • Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing fraud and abuse, responding to support requests, and maintaining audit records of administrative support actions.
  • Consent (Art. 6(1)(a)): optional expense reminder emails. Reminders are off by default and you can withdraw consent at any time from your Account page.

Data about children is entered by you, the parent, in your capacity as their guardian. Keep entries to the minimum needed to evidence an expense.

4. Who we share it with

We use a small number of processors who act only on our instructions under data processing agreements:

  • Our cloud database, authentication, storage and hosting provider.
  • Stripe, for payment processing and receipts.
  • Our transactional email provider, for account and reminder emails.

We may also disclose data where legally required, or to establish, exercise or defend legal claims.

5. International transfers

Some providers may process data outside the EEA/UK. Where that happens, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), supplemented by encryption in transit and at rest.

6. How long we keep it

  • Ledger, child and receipt data: for as long as your account exists, including read-only periods after access lapses, so your records are not lost.
  • After you delete your account: erased within 30 days, apart from data we must retain by law.
  • Payment and invoice records: retained for up to 7 years to meet accounting and tax obligations.
  • Email delivery and security logs: typically up to 12 months.

7. Your rights

If you are in the EU, EEA or UK, you have the right under the GDPR to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent to reminder emails at any time;
  • lodge a complaint with your local supervisory authority — the data protection authority in your EU/EEA country of residence, or the Information Commissioner’s Office in the UK.

You can export your ledger as a PDF at any time from the app. For any other request, email hello@solo-ledger.co and we will respond within one month.

8. Security

Access to your records is restricted at database level so that only your authenticated account can read or write them. Receipts are held in private storage and served through short-lived signed links. Traffic is encrypted in transit. Support staff cannot see your password; assisted sign-in actions are logged in an internal audit trail.

9. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in and to protect the service. We also use optional advertising and measurement cookies from Meta (the Meta pixel) to measure the performance of our ads. These load only if you choose “Accept” on our cookie banner, and never if you choose “Reject”. You can change your choice by clearing this site’s browser storage, which makes the banner appear again.

10. Children

The service is intended for adults. We do not knowingly allow anyone under 18 to create an account. Information about children appears only as records entered by a parent or guardian.

11. Changes to this policy

We will update this page if our processing changes, and we will notify you by email where the change is significant.

Back to home