← ceendesis.com

Privacy Policy

Last updated: 18 June 2026 (rev 4)

1. Who we are

Ceendesis Ltd(“Ceendesis”, “we”, “us”) is the data controller for the Ceendesis Accounting service available at accounting.ceendesis.com. You can contact us at privacy@ceendesis.com.

2. What data we process

  • Account data — name, email address, and organisation name collected when you create an account (via Clerk authentication).
  • Sales platform credentials — encrypted OAuth tokens for Amazon Seller Central, Shopify, eBay, Etsy, Walmart, TikTok Shop, Square, and WooCommerce, used solely to retrieve settlement reports on your behalf.
  • Accounting platform credentials — encrypted OAuth tokens for Xero and QuickBooks Online, used solely to post invoices and journals on your behalf.
  • Settlement data — financial line items from your marketplace payouts, including amounts, fees, and tax figures.
  • Order data — order-level financial fields retrieved from your connected sales platforms (order ID and number, status, currency, totals, line items, taxes, and payment-gateway names), used to categorise and post your sales. We request the minimum financial fields only and do notrequest or store your customers’ names, email addresses, postal addresses, or phone numbers. Where this data relates to your customers, you are the data controller and we act as your processor — see the data-processing terms in our Terms of Service.
  • Product cost data — cost-of-goods figures you enter manually or that are imported from your connected platforms.
  • Operational logs — server-side logs and error reports used to diagnose issues and maintain service reliability.

3. Legal basis for processing

  • Performance of a contract (Art. 6(1)(b) UK GDPR) — processing your account and financial data is necessary to deliver the accounting automation service you have subscribed to.
  • Legitimate interests (Art. 6(1)(f) UK GDPR) — maintaining operational logs and security monitoring to protect the service and your data.
  • Legal obligation (Art. 6(1)(c) UK GDPR) — retaining financial records where required by applicable law.

4. How we use your data

We use your data only to:

  • Authenticate you and secure your account.
  • Retrieve settlement reports from your connected sales platforms.
  • Post invoices and journals to your connected accounting software.
  • Send transactional notifications (posting failures, connection expiry).
  • Diagnose and fix service errors.

We do not sell your data, use it for advertising, or share it with third parties except as described in section 5.

5. Who we share data with

  • Clerk (authentication) — stores your email and name to manage login sessions. Clerk is GDPR-compliant.
  • Railway (database hosting) — hosts your account and settlement data in encrypted PostgreSQL databases. Data is stored in the EU (Europe West region). Railway is GDPR-compliant.
  • Cloudflare (CDN, security & file storage)— provides CDN, DDoS/WAF protection, and encrypted object storage (R2) for your settlement report files. Transfers are covered by Standard Contractual Clauses and Cloudflare's EU–US Data Privacy Framework certification.
  • Upstash (rate limiting) — provides Redis-based rate limiting to protect the service; receives only hashed request identifiers, no personal or financial data. Data is stored in the EU.
  • Resend (transactional email) — used to send alert and notification emails. Only your email address is shared.
  • Inngest (background jobs) — orchestrates settlement sync and posting jobs. Event payloads contain settlement IDs and org IDs.
  • PostHog (product analytics & session replay) — records page views and product-usage events, and (optionally) anonymised session replays to help us improve the service. PostHog is operated by PostHog Inc. and data is stored in the United States. This transfer is lawful under UK/EU GDPR on the basis of Standard Contractual Clauses (SCCs) and PostHog's certification under the EU–US Data Privacy Framework (DPF). Autocapture is disabled, and session recordings mask all text and inputs (maskAllText and maskAllInputs), with URL query strings stripped before send — so no amounts, account names, tokens, or form values are captured. You can opt out at any time by contacting privacy@ceendesis.com.
  • Sentry (error monitoring) — receives sanitised error and performance reports used to diagnose service issues. Sentry is operated by Functional Software, Inc. and data is stored in the United States. This transfer is lawful under UK/EU GDPR on the basis of Standard Contractual Clauses (SCCs) and Sentry's certification under the EU–US Data Privacy Framework (DPF). Before any error event is transmitted, our beforeSend scrubber automatically strips all tokens, OAuth credentials, and personal identifiers (email addresses, names) so that no financial line-item data or personal data is included in reports sent to Sentry.

All sub-processors are contractually bound via Data Processing Agreements (DPAs) to process data only on our instructions and to maintain appropriate security measures.

6. Data retention

We retain your data for as long as your account is active, plus 7 years after account closure to satisfy financial record-keeping obligations under UK law. Settlement line items and posted invoice records are kept for this full period. OAuth credentials are deleted immediately upon connection removal or account closure.

7. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data (subject to legal retention obligations).
  • Restrict or object to processing.
  • Data portability — receive your data in a machine-readable format.
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these rights, email privacy@ceendesis.com. We will respond within 30 days.

8. Security

All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted using AES-256. OAuth credentials are encrypted at the application layer before being stored. We apply the principle of least privilege to all internal systems.

9. Changes to this policy

We will notify you by email at least 14 days before any material change to this policy. Continued use of the service after that date constitutes acceptance of the updated policy.