Privacy Policy
Last Updated: July 29, 2026
# Privacy Policy
Last Updated: July 29, 2026
This Privacy Policy explains how GOOD KEEPING SOLUTIONS LLC, a Florida limited liability company with a principal address at 1909 Thetford Cir, Orlando, Florida 32824, United States (“GoodKeeping,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects information in connection with the GoodKeeping website, platform, and related services.
GoodKeeping may be contacted at hello@goodkeeping.com.
The Service is currently offered for businesses established in the United States and is intended solely for business and professional use.
## 1. Scope of This Policy
This Privacy Policy applies to information processed through:
- the GoodKeeping website;
- GoodKeeping accounts and Organization workspaces;
- signup, invitations, and onboarding;
- bookkeeping and financial-document workflows;
- transaction review and categorization;
- reporting and collaboration features;
- billing and subscription management;
- customer support and feedback;
- marketing communications;
- Customer-authorized integrations; and
- related security, administration, and service operations.
This Policy does not govern the independent privacy practices of third-party websites or services that operate under their own privacy notices.
## 2. Organizations and GoodKeeping’s Role
GoodKeeping provides services through business workspaces referred to as “Organizations.”
GoodKeeping processes certain information for its own business purposes, including:
- account administration;
- authentication and security;
- billing;
- legal compliance;
- customer support;
- website operations;
- service monitoring; and
- GoodKeeping’s own communications.
GoodKeeping also processes financial documents, transactions, bookkeeping records, and related Customer Data on behalf of Organizations using the Service.
Organizations determine which owners, employees, accountants, advisers, contractors, and other authorized users may access their workspace.
An Organization is responsible for ensuring that it has the authority, notices, permissions, and consents required to submit information relating to its personnel, customers, vendors, contractors, or other persons.
## 3. Information We Collect
### 3.1 Account and identity information
We may collect:
- first and last name;
- email address;
- telephone number;
- account credentials;
- authentication and verification information;
- account status;
- Organization memberships;
- assigned roles and permissions;
- communication preferences;
- language preferences;
- marketing preferences; and
- records showing acceptance of legal documents.
Passwords are maintained using protective hashing methods rather than being stored as readable passwords.
### 3.2 Organization and business information
We may collect information used to establish and configure an Organization, including:
- business and Organization name;
- legal name;
- trade name or DBA;
- entity type;
- employer identification number or other tax identifier;
- formation date and jurisdiction;
- registered, operating, and billing addresses;
- business telephone number;
- website;
- industry;
- business description;
- company size;
- primary business contacts;
- accounting and bookkeeping contacts;
- fiscal-year information;
- accounting method;
- tax, payroll, software, and operational profile information;
- operating jurisdictions;
- accounting-firm relationships; and
- onboarding responses.
### 3.3 Financial-account information
We may collect financial-account information needed to identify accounts and perform bookkeeping services, including:
- financial institution;
- account type;
- account label;
- account currency;
- account holder or business name;
- masked account identifiers;
- the last digits of an account identifier;
- statement period;
- account balances;
- payment-processor information; and
- related account metadata.
Customer-submitted documents may contain fuller financial identifiers, including account numbers, routing information, balances, names, addresses, tax identifiers, and other sensitive financial information.
Customers should submit only the information reasonably necessary for the Service.
### 3.4 Financial documents and transaction information
Customers may submit:
- bank statements;
- credit-card statements;
- payment-processor reports;
- transaction exports;
- spreadsheets;
- financial reports;
- accounting records;
- invoices and supporting documents;
- documents requested by an assigned accounting team; and
- other materials related to bookkeeping and financial operations.
These documents and records may include:
- transaction descriptions;
- merchant and payee information;
- transaction dates;
- amounts;
- credits and debits;
- balances;
- financial-account identifiers;
- categories;
- invoices;
- payment details;
- names and addresses;
- tax-related information; and
- other information included by the Customer.
GoodKeeping may retain the original submitted materials together with extracted, normalized, classified, reviewed, corrected, or generated records.
### 3.5 Bookkeeping and workspace information
We may process information created or maintained through the Service, including:
- transactions;
- merchant information;
- categories and classifications;
- review decisions;
- corrections and overrides;
- reconciliation information;
- reports and summaries;
- assigned work;
- task status;
- comments and notes;
- document requests;
- approvals;
- user activity; and
- records showing actions taken within an Organization.
### 3.6 Communications and feedback
We may collect information provided through:
- contact forms;
- sales enquiries;
- support requests;
- email;
- feedback forms;
- surveys;
- uploaded support attachments;
- product-research participation; and
- other communications with GoodKeeping.
This information may include:
- name;
- email;
- telephone number;
- company;
- role;
- message;
- attached materials;
- relevant page or feature;
- referral or campaign information; and
- communication preferences.
Information submitted through a public contact form may be maintained separately from a GoodKeeping account created later.
### 3.7 Billing and subscription information
For paid services, we may process:
- selected plan;
- billing frequency;
- subscription status;
- billing contact;
- payment-customer identifiers;
- subscription and invoice identifiers;
- payment status;
- renewal date;
- cancellation status;
- refunds or billing adjustments; and
- related billing records.
Payments are handled by a designated payment processor. GoodKeeping does not store full payment-card numbers in the GoodKeeping application.
### 3.8 Integration information
When an Organization connects another service, we may process:
- integration type;
- connection name;
- external account or connection identifiers;
- authorization status;
- synchronization information;
- connection credentials or tokens; and
- information received through the authorized connection.
The information available through an integration depends on the service selected and the permissions granted by the Organization.
### 3.9 Device, usage, security, and audit information
We may automatically collect:
- IP address;
- approximate location derived from IP address;
- browser and device information;
- operating system;
- session identifiers;
- authentication events;
- access events;
- page and feature activity;
- permission changes;
- security events;
- error and performance information;
- export and download activity;
- administrative activity; and
- records needed to operate, secure, and audit the Service.
Certain activities may be recorded to preserve bookkeeping history, investigate incidents, provide customer support, and demonstrate authorized access to Organization records.
### 3.10 Cookies and similar technologies
We may use cookies, local storage, session storage, and similar technologies for:
- authentication;
- session continuity;
- security;
- request validation;
- abuse prevention;
- language and interface preferences;
- remembering privacy choices;
- analytics; and
- marketing measurement.
Technologies necessary to operate and secure the Service may be used without optional marketing consent.
Optional analytics and marketing technologies are controlled through available cookie-preference settings and are intended to operate only after the required choice or consent has been provided.
Further information appears in the Cookie Policy.
## 4. How We Collect Information
We collect information:
- directly from users;
- from Organizations and Organization administrators;
- from accounting firms and assigned expert teams;
- from uploaded documents and files;
- through use of the Service;
- from Customer-authorized integrations;
- from payment and billing providers;
- from security and operational service providers;
- from contact, support, and feedback submissions; and
- from other persons authorized to provide information to an Organization.
## 5. How We Use Information
### 5.1 To provide the Service
We use information to:
- create and administer accounts and Organizations;
- complete onboarding;
- receive and process financial documents;
- extract and normalize transaction information;
- review and categorize transactions;
- maintain financial and bookkeeping records;
- assign work to accounting teams;
- prepare reports and summaries;
- support collaboration;
- maintain tasks, comments, and approvals;
- provide Organization-specific settings and workflows;
- respond to Customer instructions; and
- provide related bookkeeping and tax-preparation support workflows.
### 5.2 To provide expert review
GoodKeeping combines software-assisted processing with review by authorized personnel.
Assigned accounting, bookkeeping, expert, operations, and support personnel may access Customer Data where reasonably necessary to:
- review submitted statements and transactions;
- assign or correct categories;
- resolve incomplete or uncertain records;
- conduct quality review;
- complete bookkeeping workflows;
- respond to Customer questions;
- investigate processing errors;
- provide support; and
- administer and protect the Service.
Access is limited according to role, Organization assignment, authorization, and business need.
### 5.3 To provide automated and AI-assisted functionality
GoodKeeping may use automated systems, document-processing technologies, and artificial intelligence to support:
- document extraction;
- transaction normalization;
- merchant recognition;
- categorization;
- recommendations;
- summaries;
- report preparation;
- discrepancy review;
- assistance features; and
- quality-control workflows.
Automated systems may process relevant portions of Customer Data, including transaction information, document content, merchant information, sample data, Organization context, and prior corrections.
Automated outputs may be incomplete or inaccurate and may be reviewed or corrected by authorized personnel.
### 5.4 To personalize an Organization’s service
We may use an Organization’s:
- previous categorization decisions;
- merchant relationships;
- corrections;
- workflow history;
- business profile;
- preferences;
- approved rules; and
- related context
to improve consistency and reduce repeated work for that Organization.
### 5.5 To operate billing and subscriptions
We use billing information to:
- create and manage subscriptions;
- provide access to billing controls;
- process renewals;
- manage cancellations;
- handle failed payments;
- issue invoices and receipts;
- review billing disputes;
- administer plan access; and
- process approved refunds or adjustments.
### 5.6 To communicate
We may send:
- account verification messages;
- security notifications;
- invitations;
- task and review reminders;
- comment notifications;
- billing messages;
- service announcements;
- support responses;
- legal and policy notices; and
- marketing communications where permitted.
Operational communications necessary to provide the Service are separate from optional marketing communications.
### 5.7 To protect the Service
We may use information to:
- authenticate users;
- administer access and permissions;
- detect unauthorized activity;
- prevent abuse and fraud;
- investigate security incidents;
- maintain audit history;
- diagnose errors;
- protect Customer Data;
- enforce agreements;
- comply with law; and
- establish or defend legal rights.
### 5.8 To develop and improve GoodKeeping
We may use:
- service activity;
- user corrections;
- feedback;
- categorization results;
- generalized merchant relationships;
- quality measurements;
- operational outcomes;
- aggregated information;
- de-identified information; and
- derived information
to evaluate and improve the Service, GoodKeeping’s internal systems, categorization methods, merchant recognition, quality-control processes, and future features.
GoodKeeping may retain generalized merchant and categorization knowledge after it has been separated from Customer identity and Customer-specific source records.
We do not sell Customer financial records or uploaded financial documents.
## 6. Use of Service Providers
GoodKeeping may engage service providers supporting:
- infrastructure and hosting;
- network and security services;
- data and document storage;
- communications and email;
- payment processing;
- document extraction;
- automated and AI-assisted processing;
- security monitoring;
- analytics;
- marketing measurement;
- customer support;
- professional services; and
- other functions necessary to operate the Service.
Service providers may process information only as reasonably necessary to perform their assigned services, subject to applicable contractual, confidentiality, security, and legal requirements.
The providers used by GoodKeeping may change as the Service evolves.
GoodKeeping does not authorize service providers to use raw Customer financial submissions for:
- their independent advertising;
- sale to data brokers;
- unrelated commercial profiling; or
- training general-purpose artificial intelligence models for their own purposes.
## 7. How We Disclose Information
### 7.1 Within an Organization
Information may be available to:
- Organization owners;
- administrators;
- authorized employees;
- assigned accountants;
- bookkeeping and expert teams;
- professional advisers;
- invited collaborators; and
- other authorized users
according to their roles and assignments.
### 7.2 To service providers
We may disclose information to service providers described in Section 6 where reasonably necessary to operate the Service.
### 7.3 Through Customer-authorized integrations
When an Organization authorizes an integration, we may exchange information with that integration according to the Organization’s instructions and permissions.
### 7.4 For legal and safety purposes
We may disclose information when reasonably necessary to:
- comply with applicable law;
- respond to a subpoena, court order, or lawful government request;
- prevent or investigate fraud or abuse;
- protect the rights, property, or safety of GoodKeeping or others;
- investigate a security incident;
- enforce our agreements; or
- establish, exercise, or defend legal claims.
### 7.5 Corporate transactions
Information may be transferred in connection with:
- a merger;
- acquisition;
- financing;
- corporate reorganization;
- bankruptcy;
- asset sale; or
- similar business transaction.
Any recipient remains subject to applicable obligations concerning the information transferred.
### 7.6 Professional advisers
We may disclose information to attorneys, auditors, insurers, accountants, and other professional advisers where reasonably necessary for legitimate business, legal, compliance, or risk-management purposes.
## 8. Sale, Advertising, and Independent Use
GoodKeeping does not sell Customer financial documents, transaction records, or Organization workspace data.
GoodKeeping does not disclose Customer Data to third parties for those third parties’ independent direct-marketing purposes.
Optional website analytics and advertising technologies may process website or campaign information according to the selections made through the cookie-preference system.
Where applicable law treats particular advertising technology as a sale, sharing, or targeted-advertising activity, GoodKeeping will provide any notice or choice required by that law.
## 9. Marketing Communications
Marketing communications are optional and separate from:
- accepting the Terms of Service;
- accepting this Privacy Policy;
- creating a Free account;
- participating in a product trial;
- purchasing a subscription; and
- selecting cookie preferences.
A recipient may withdraw marketing consent through:
- an unsubscribe link;
- available account settings; or
- a request sent to hello@goodkeeping.com.
Withdrawal applies to future marketing communications.
GoodKeeping may retain a limited suppression record where necessary to ensure that an opt-out continues to be honored.
Security, billing, task, account, and service communications may continue where required to administer an active account or Organization.
## 10. Data Retention
GoodKeeping retains information for as long as reasonably necessary to:
- provide the Service;
- maintain bookkeeping and financial-record continuity;
- administer accounts and subscriptions;
- comply with legal, tax, accounting, and contractual obligations;
- maintain security and audit records;
- resolve disputes;
- prevent fraud; and
- enforce agreements.
Retention periods vary according to the type of information and its purpose.
### 10.1 Active accounts and Organizations
Information needed to provide the Service is generally retained while the relevant account or Organization remains active.
### 10.2 Financial and workspace records
Financial documents, transactions, reports, tasks, comments, categorizations, and related workspace records may be retained while the Organization maintains its workspace.
### 10.3 Billing and legal records
Billing records, subscription records, invoices, legal-acceptance evidence, and related information may be retained as reasonably necessary for:
- tax and accounting obligations;
- contract evidence;
- dispute resolution;
- fraud prevention; and
- legal compliance.
### 10.4 Security and audit records
Security, access, and audit records may be retained for periods reasonably necessary to:
- protect the Service;
- investigate incidents;
- preserve financial-record integrity;
- demonstrate authorized activity; and
- establish or defend legal claims.
### 10.5 Contact and support records
Contact enquiries, support communications, feedback, and related records may be retained for:
- follow-up;
- customer support;
- service improvement;
- dispute handling;
- business records; and
- legal compliance.
### 10.6 De-identified and generalized information
GoodKeeping may retain aggregated, generalized, de-identified, or derived information that is no longer reasonably linked to a Customer or capable of reproducing Customer Content.
This may include generalized:
- merchant knowledge;
- category relationships;
- performance statistics;
- quality measurements;
- operational patterns; and
- product-improvement information.
### 10.7 Backups
Information removed from active systems may remain temporarily in protected backups until those backups expire or are overwritten through the ordinary backup lifecycle.
Backups are maintained for continuity, security, and disaster recovery and are not intended to operate as ordinary active records.
### 10.8 Legal holds
GoodKeeping may suspend deletion of particular records where reasonably necessary to:
- comply with law;
- preserve evidence;
- respond to a dispute;
- investigate fraud or security events; or
- establish or defend legal claims.
## 11. Account Deletion
A verified user may request deletion of the user’s account.
When an account-deletion request is completed, GoodKeeping may:
- deactivate the account;
- remove or replace identifying profile information;
- invalidate credentials;
- revoke sessions;
- remove authentication and recovery information;
- clear personal preferences; and
- de-identify retained records where appropriate.
Deleting an individual user account does not automatically delete the financial and bookkeeping records belonging to an active Organization.
Records of actions previously taken for an Organization may remain where needed to preserve bookkeeping and audit integrity, but the deleted user’s identity may be removed or replaced where appropriate.
## 12. Organization Deletion
Only an authorized Organization owner may request deletion of an Organization.
GoodKeeping may require:
- identity verification;
- authority verification;
- confirmation of the request;
- expiration of a revocation or grace period;
- resolution of a legal hold; and
- completion or scheduled cancellation of an active subscription.
When Organization deletion is completed, GoodKeeping may:
- deactivate and de-identify the Organization profile;
- revoke user access;
- terminate integrations;
- remove integration credentials;
- remove or de-identify business contacts;
- remove Organization-specific settings and preferences;
- delete financial documents and stored files;
- delete transactions and related bookkeeping records;
- delete Organization-specific automated-processing context;
- remove Customer-specific rules and overrides; and
- retain only records permitted under this Policy or required by law.
Generalized merchant, category, quality, and product knowledge may remain where it is no longer reasonably linked to the deleted Organization or its source records.
GoodKeeping does not promise immediate deletion of records subject to:
- an active subscription period;
- a grace period;
- legal retention requirements;
- billing or tax obligations;
- security or audit requirements;
- legal holds;
- dispute preservation; or
- normal backup expiration.
## 13. Subscription Cancellation Is Separate from Deletion
Cancelling a paid subscription does not delete:
- the user account;
- the Organization;
- Customer Data; or
- bookkeeping records.
Subscription cancellation prevents future renewal after the current paid period, subject to the Subscription, Cancellation and Refund Policy.
Account or Organization deletion requires a separate request.
## 14. Privacy Rights and Choices
Subject to identity and authority verification, GoodKeeping provides a process through which users may request:
- access to personal information associated with their account;
- correction of inaccurate personal information;
- export of available account or Organization information;
- deletion of a user account;
- deletion of an Organization by an authorized owner;
- withdrawal of marketing consent;
- information about categories of personal information processed; and
- review of a privacy-request decision where required by applicable law.
Additional rights may apply under the law governing a particular request.
GoodKeeping may limit or deny a request where permitted by law, including where:
- identity or authority cannot be verified;
- the information belongs to or is controlled by another Organization;
- retention is required by law;
- the information is needed for billing, tax, security, fraud prevention, audit integrity, or legal claims;
- fulfilling the request would adversely affect another person’s rights; or
- another legal exception applies.
GoodKeeping will not discriminate against a person for making a valid privacy request.
## 15. Submitting a Privacy Request
Privacy requests may be submitted:
- through privacy controls made available in the Service; or
- by emailing hello@goodkeeping.com.
The request should describe:
- the requested action;
- the relevant account;
- the relevant Organization, where applicable; and
- information reasonably necessary to locate the records.
GoodKeeping may request additional information to verify:
- identity;
- account ownership;
- Organization authority;
- the scope of the request; or
- authorization of an agent.
A request concerning Organization financial records may require confirmation from an authorized Organization owner.
Public contact, lead, or support submissions may be processed separately from account deletion.
GoodKeeping will respond within the period required by applicable law.
## 16. Information Security
GoodKeeping maintains administrative, technical, and organizational safeguards intended to protect information from unauthorized access, use, alteration, disclosure, loss, and destruction.
Safeguards may include:
- role-based and assignment-based access;
- authentication controls;
- session management;
- protected credentials;
- multi-factor authentication for sensitive access;
- encryption of network traffic;
- protected data and document storage;
- audit and access logging;
- monitoring;
- backup and recovery processes;
- restricted personnel access; and
- incident-investigation procedures.
No service or storage system can guarantee absolute security.
Customers are responsible for:
- protecting credentials and devices;
- selecting appropriate Organization administrators;
- maintaining accurate permissions;
- removing users who should no longer have access;
- protecting information exported from GoodKeeping; and
- reporting suspected unauthorized access.
Suspected security issues should be reported to hello@goodkeeping.com.
## 17. Security Incidents
GoodKeeping investigates suspected security incidents and takes action appropriate to the nature and scope of the incident.
GoodKeeping provides notices to affected persons, Organizations, regulators, or authorities when and as required by applicable law.
## 18. United States Service and International Processing
The Service is currently offered for businesses established in the United States.
Users, authorized accounting personnel, and service providers may access or process information from other locations.
Information may be processed in the United States and in other countries where GoodKeeping’s service providers operate.
Those countries may apply privacy and data-protection rules that differ from the rules in the location from which a user accesses the Service.
GoodKeeping does not claim certification under a specific international privacy framework unless that certification is expressly stated separately.
## 19. Sensitive and Specially Regulated Information
Financial and business information is central to the Service.
Customers should not submit information that is unrelated or unnecessary for bookkeeping and financial operations.
GoodKeeping does not ordinarily request the following during account registration:
- biometric information;
- protected health information;
- government identity documents; or
- information requiring specialized regulatory arrangements unrelated to the Service.
Customer-submitted documents may incidentally contain such information.
The Service is not designed for protected health information or other specially regulated data unless GoodKeeping has expressly agreed in writing and any required contractual safeguards are in place.
## 20. Children
The Service is intended solely for business users who are at least 18 years old.
It is not directed to children, and individuals under 18 may not create or use a GoodKeeping account.
A concern involving information submitted by a child may be reported to hello@goodkeeping.com.
## 21. Third-Party Services
The Service may contain links to or integrations with third-party services.
GoodKeeping does not control the independent privacy practices of those services.
Customers should review the applicable third-party privacy notices and permissions before connecting or using an external service.
## 22. Changes to This Policy
GoodKeeping may update this Privacy Policy to reflect changes in:
- the Service;
- data practices;
- technologies;
- legal or regulatory requirements;
- service providers;
- security practices; or
- business operations.
The “Last Updated” date identifies the current version.
Where reasonably practicable, GoodKeeping will provide notice of a material change by email, within the Service, or through another appropriate method.
Where applicable law requires consent for a new use, GoodKeeping will request that consent before applying the new use in the manner requiring consent.
## 23. Contact
Questions, complaints, security concerns, and privacy requests may be sent to:
GOOD KEEPING SOLUTIONS LLC
1909 Thetford Cir
Orlando, Florida 32824
United States
Email: hello@goodkeeping.com
