MatchLedger, Inc., a corporation organized under the laws of the State of Delaware, United States (“Company,” “we,” “us,” or “our”), operates the MatchLedger web application at app.matchledger.ai (the “Service”) and the marketing website at matchledger.ai (the “Website”). This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Service and the Website.
By using the Service or the Website, you agree to the practices described in this Privacy Policy. This Privacy Policy is incorporated into our Terms of Service by reference.
If you do not agree with this Privacy Policy, do not use the Service or the Website.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- First and last name
- Email address
- Password (stored as a salted hash — we never store your password in plain text)
- Company or organization name
- Country and default currency preference
If you sign up using Google OAuth, we receive your name and email address from Google. We do not receive or store your Google password.
1.2 Financial Documents You Upload
When you use the Service, you may upload:
- Bank statements (PDF, CSV)
- Credit card statements (PDF, CSV)
- Ledger reports from accounting software (PDF, CSV)
These documents contain sensitive financial information including account numbers, transaction details, balances, and merchant names. We treat all uploaded documents as confidential.
1.3 Data Extracted from Your Documents
The Service uses artificial intelligence to extract structured data from your uploaded documents, including:
- Transaction dates, descriptions, and amounts
- Account numbers and card numbers (last 4 digits)
- Merchant and payee names
- Balance information
This extracted data is stored in our database to provide reconciliation and export features.
1.4 Reconciliation and Export Data
When you run reconciliation jobs, we generate and store:
- Match results between transactions and ledger entries
- Confidence scores and match reasons
- Export files (CSV, Excel) generated from your reconciliation results
1.5 Usage Information
We automatically collect:
- Features used and actions taken within the Service (e.g., reconciliation jobs created, exports generated)
- Subscription plan, usage counts (reconciliation jobs and line items extracted per month)
- IP address, browser type, and device information when you access the Service
- Timestamps of account activity
- If the application or our servers encounter an error, a report describing it — the error message, the page you were on, your browser type, and a technical trace — sent to Sentry, our error-monitoring provider, without your IP address or account identifiers
1.6 Website Analytics and Advertising Measurement
Our marketing website (matchledger.ai) uses Google Analytics to collect aggregated, anonymous usage data including pages visited, time on site, referral source, and general geographic region. See Section 7 (Cookies) for details.
The marketing website also uses Google Ads conversion tracking to measure which advertisements lead people to start using MatchLedger. When you follow a link from this website to create an account, we send Google Ads a signal that the click happened, so it can be credited to the advertisement that brought you here. That signal identifies the advertisement click, not you — the website does not ask for your email address, so none is collected, hashed, or transmitted.
The MatchLedger application (app.matchledger.ai) also loads Google Analytics and Google Ads code. It uses the same Google tag as the marketing website, which lets us measure two things: how the application is used in aggregate, and whether an advertisement led to a completed signup.
Because the marketing website and the application are separate web addresses, the Google tag is configured to recognise them as one visit rather than two. This means the identifier for an advertisement click you arrived from is carried across when you move from matchledger.ai to app.matchledger.ai. If you create an account, we store that advertisement click identifier alongside your account record so the signup can be credited to the advertisement that produced it, and we report a conversion to Google Ads at that moment.
The conversion is reported only when a new account is actually created— not when you sign in again, link a Google account to an existing login, or return after closing an account. What is reported is the advertisement click and the fact that a signup followed. It carries no account details, no name, and no email address. No data from your financial documents, reconciliations, or account activity is ever used for advertising. The application also uses one third-party product-analytics tool, described in Section 1.7 below.
1.7 Product Analytics in the Application
The MatchLedger application uses PostHog to understand how the Service is used — which features people rely on and where they get stuck — so we can improve it. This is product analytics only; it is never used for advertising, and the data is not sold or shared with advertisers.
We collect:
- Pages viewed within the application, and clicks on buttons, links, and controls
- A defined set of product events: sign-up, trial start, document extraction completed or failed, reconciliation completed, export generated, subscription started, upgraded, downgraded or cancelled, and warnings that you are approaching or have reached a plan limit
- Attributes of your account used to group this activity: your plan tier, whether the account is sponsored, trial status, and sign-up date
- How you first arrived at sign-up — campaign parameters in the link you followed (commonly called UTM parameters) and the domain of the referring website
We do not send the contents of your financial documents. The files you upload, the transactions and entries extracted from them, and the values you type into forms are not transmitted to PostHog. One limitation is worth stating plainly: because we record which control you clicked, the visible text label of that control is captured, and on some screens a label can incidentally include text drawn from your statements — for example a merchant name shown on a button. We do not use this text, and we are working to remove it.
Session recording is switched off. We do not record video or replays of your screen. The administrative portal used by our staff is excluded from analytics entirely. Analytics profiles are created only for signed-in users.
PostHog Inc. processes this data on our behalf as a service provider, on servers in the United States. See Section 3 (How We Share Your Information) and Section 7 (Cookies and Browser Storage). You can limit this collection using your browser's privacy settings or an ad-blocking extension, and visitors from the EEA, the United Kingdom, and Switzerland can decline it in the consent banner (Section 7.3); the Service works normally either way.
1.8 Payment Information
When you subscribe to a paid Plan, your payment is processed by Stripe, Inc. Your full payment-card number and related card details are collected and processed directly by Stripe; we do not receive or store your full card number. We receive from Stripe limited billing information such as your subscription status, the last four digits and card brand, billing country, and payment outcomes, which we use to manage your subscription.
1.9 Free Conversion Tool (No Account)
The free statement converter at app.matchledger.ai/convert can be used without creating an account. Because there is no account, there is no Organization, no contract with a business customer, and no one instructing us on your behalf: for the free tool, we are the controller of the information described in this Section. When you use it, we collect:
- The file you drop in (a bank or credit card statement in PDF or CSV form), its name, type, size, and page count, and the transactions extracted from it
- The email address you give us if you ask for the full converted file — used to deliver that file and for nothing else
- A hashed (one-way, non-reversible) form of your IP address, a random session identifier, and the result of an automated bot check performed by Cloudflare Turnstile, all used to prevent abuse of the tool
- The type of statement you chose and the export format you selected
Exactly one page of your statement is sent to our AI sub-processor (Section 8) to produce the on-screen preview. The whole document is processed only after you ask for the full file by giving us your email address. Product-analytics events for the tool carry no file name, no email address, no IP address, and no content from your statement.
Files are processed once and then deleted. A conversion that is never delivered is deleted within 48 hours of upload. A delivered file is available through its download link for 24 hours and is deleted within 24 hours after that link expires — so nothing you upload to the free tool survives longer than 48 hours. See Section 5.
2. How We Use Your Information
We use your information for the following purposes:
- Providing the Service — processing your uploaded documents, running AI extraction, performing reconciliation, and generating exports
- Account management — authenticating your identity, managing your subscription, and communicating with you about your account
- Payments — processing subscription payments through Stripe
- Service improvement — analyzing usage patterns to improve features, fix bugs, and optimize performance
- Format template creation — creating and improving format templates: configuration artifacts that describe how a financial institution or accounting package structures its documents (for example, column order, date formats, and standard header text), so that extraction is more accurate for you and all other customers. We may create or improve a format template by reference to the structure, layout, and formatting of documents you upload or format requests you submit. Format templates are designed, validated, and reviewed so that they contain no transactions, balances, account numbers, or personal information (whether yours or anyone else's); if any such value is ever found in a format template, we will promptly remove it or delete the template, and that value will be handled as personal data under this Policy. Format templates are retained after your documents are deleted
- Support and calibration access — our authorized personnel may access your account and documents as needed for support, troubleshooting, and format-template calibration; administrative access requires separate credentials and is audit-logged (see Section 4.3)
- Security — detecting and preventing fraud, unauthorized access, and abuse
- Legal compliance — responding to legal requests and fulfilling our obligations under applicable law
- Communications — sending transactional emails (extraction complete, export ready, password reset) and, with your consent, product updates
2.1 Legal Bases for Processing
Where required by applicable data-protection law (including the Philippine Data Privacy Act of 2012 and, where applicable, the EU/UK GDPR), we rely on the following legal bases to process your personal information:
- Performance of a contract — to provide the Service you have signed up for or, for the free conversion tool, the conversion you have asked for: account management, document processing — including transmitting your uploaded documents to our AI sub-processor for extraction, which is how the Service works and cannot be provided without it — reconciliation, exports, and payments.
- Consent — for optional product-update communications, and for non-essential cookies and analytics where the law of your country requires it (see Section 7.3). You may withdraw consent at any time, and withdrawing it does not affect your use of the Service.
- Legitimate interests — to secure the Service, prevent fraud and abuse, and improve and maintain the Service, including by analyzing the structure, layout, and formatting of documents you upload and of data extracted from them (which may involve processing a document through the same AI extraction pipeline used to provide the Service) in order to create and improve format templates that are designed and validated to contain no personal information — provided these interests are not overridden by your rights. Format-template creation and calibration rest on this legitimate-interests basis, not on consent. We have weighed each of these interests against your rights and freedoms, and you may object to processing on this basis at any time (see Section 6).
- Legal obligation — to comply with applicable laws, regulations, and lawful requests.
Because uploaded financial documents may contain sensitive information, we process them only as necessary to provide the Service and protect them with the safeguards described in Section 4.
2.2 Our Role: Controller or Processor
Data-protection law distinguishes between a controller, who decides why and how personal data is processed, and a processor, who processes it on the controller's instructions. We act in both roles:
- For your own account information (Sections 1.1, 1.5, 1.6, 1.7, and 1.8) and for the free conversion tool (Section 1.9), we are the controller.
- For personal data contained in the documents you upload (Sections 1.2 to 1.4) — account-holder names, counterparties, transaction descriptions — you, or the business or client on whose behalf you upload, are the controller, and we are your processor. We process that data only to provide the Service to you, as described in this Policy and our Terms of Service, and you are responsible for having a lawful basis to upload it.
Business customers who need a written data-processing agreement, including the Standard Contractual Clauses described in Section 10, can obtain our Data Processing Addendum by writing to dpo@matchledger.ai. No automated decision that produces legal or similarly significant effects for you is made by the Service: matches suggested by the Service are proposals that a person reviews and confirms.
3. How We Share Your Information
We share your information only with the following third-party service providers (our “sub-processors”), solely for the purpose of operating the Service:
| Provider | What is shared | Purpose |
|---|---|---|
| Anthropic (Claude API) | Contents of uploaded financial documents | AI-powered data extraction, and testing and calibration of format templates using documents you upload |
| Linode (Akamai Cloud) | Uploaded source files, generated export files | Cloud storage (US region) |
| Stripe, Inc. | Name, email, billing country, and payment-card details you enter at checkout | Payment processing and subscription billing |
| Resend | User email addresses, notification content | Transactional email delivery |
| Google (Analytics) | Aggregated browsing data from the marketing website and the application (pages viewed, time on page, referral source) | Website and application traffic analysis (US) |
| Google (Ads) | An advertisement click identifier, and the fact that a signup followed it. No name, email address, or account details | Measuring which advertisements result in new signups |
| PostHog, Inc. | Product-usage events in the application as described in Section 1.7 — pages viewed, controls clicked, a defined set of product events, and plan attributes. No document contents | Product analytics (US) |
| Sentry (Functional Software, Inc.) | Error reports from the application and our servers: the error message, page, browser type, and technical trace. No IP address and no account identifiers | Error monitoring (US) |
| Cloudflare, Inc. (Turnstile) | IP address and browser signals, on the free conversion tool only | Automated bot check, to prevent abuse of the free tool |
We do not share, sell, rent, or trade your personal information or financial documents with any other third parties. We do not allow our service providers to use your data for their own purposes. Each sub-processor is bound by contractual obligations to process your data only on our instructions and to protect it.
On advertising: the single exception to the above is the Google Ads row in the table — an advertisement click identifier and the fact that a signup followed it, used only to measure which advertisements produced a signup. We do not share your financial documents, extracted transaction data, reconciliation results, or any application activity with advertisers, and we do not sell personal information to anyone. Google acts as our data processor for this measurement under the Google Ads Data Processing Terms.
3.1 Legal Disclosures
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud.
3.2 Business Transfers
If we are involved in a merger, acquisition, reorganization, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will require the recipient to honor the commitments in this Privacy Policy, and we will notify you of any change in the entity controlling your personal information.
4. Data Storage and Security
4.1 Where Your Data is Stored
All Customer Data is stored on servers located in the United States.
- Uploaded files are stored on Linode Object Storage (US region)
- Extracted data and account information are stored in a PostgreSQL database hosted in the US
- Temporary processing data is stored in Redis (in-memory, US region)
If you access the Service from outside the United States, please see Section 10 (International Users) regarding cross-border transfer.
4.2 Data Isolation
Each organization's data is isolated using PostgreSQL Row-Level Security. Users in one organization cannot access data belonging to another organization. This isolation is enforced at the database level.
4.3 Security Measures
We implement the following security measures to protect your data:
- All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
- Passwords are stored using bcrypt hashing with salt
- Authentication uses stateless JWT tokens with configurable expiration
- Database access is restricted by Row-Level Security policies per organization
- File storage uses per-organization path isolation with time-limited access URLs
- Administrative access requires separate credentials and is audit-logged
4.4 Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users by email within 72 hours of becoming aware of the breach, consistent with applicable law. Where the Philippine Data Privacy Act of 2012 applies, we will also notify the National Privacy Commission (NPC) and affected data subjects within the timeframes required by the NPC's breach-notification rules. Where the EU or UK GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware of a breach that is likely to result in a risk to your rights, and will inform you without undue delay where that risk is high.
5. Data Retention
We retain your data only as long as necessary to provide the Service:
| Data Type | Retention Period |
|---|---|
| Uploaded source files and the transaction data extracted from them (bank statements, CC statements, ledger reports) | Deleted together 30 days after the last reconciliation job that used the document finishes — or 30 days after that job's most recent export, whichever is later. Each new reconciliation or export restarts that 30-day window. If never used in a reconciliation, 30 days after upload |
| Reconciliation results and export files (CSV, Excel) | 30 days after the reconciliation job completes or the last export is generated, whichever is later; export files are downloadable for 30 days after generation |
| Account information (name, email, org settings) | Until account closure, plus 30 days for data export |
| ToS acceptance records and audit logs | 3 years after account closure |
| Format and export-format request records (institution name, document type, notes) | Retained as template library records; deleted or de-identified on request or account closure |
| Files uploaded to the free conversion tool (no account), the data extracted from them, and the delivery email address | Never delivered: deleted within 48 hours of upload. Delivered: the download link is valid for 24 hours and everything is deleted within 24 hours after the link expires. Nothing survives longer than 48 hours |
After the retention period, data is permanently deleted from our active systems. Copies in backup archives are removed as those archives rotate, no more than 30 days after deletion from our active systems.
Format templates — configuration artifacts that describe financial-institution and accounting-software document formats and are designed and validated to contain no personal information — are not personal information about you or your business and are retained independently of your account and documents (see our Terms of Service, Section 7.1). Any personal information ever found in a format template will be promptly removed and handled as personal data under this Policy.
You may request earlier deletion of your data at any time by contacting us at support@matchledger.ai.
6. Your Rights
6.1 All Users
You have the right to:
- Access your data through the Service's built-in features (view uploaded documents, extracted data, reconciliation results)
- Export your data at any time using the Service's export features — as a CSV file or an Excel spreadsheet, depending on your plan
- Delete your data by requesting deletion at support@matchledger.ai — we will process deletion requests within 30 days
- Close your account from your account settings — you will have 30 days to export your data before automatic deletion
- Correct your account information from your account settings
6.2 California Residents (CCPA Rights)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following additional rights:
- Right to Know — You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete — You may request that we delete your personal information, subject to certain exceptions (e.g., legal compliance, completing a transaction you requested).
- Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA rights.
- Right to Opt-Out of Sale — We do not sell your personal information. No opt-out is necessary.
To exercise your CCPA rights, contact us at support@matchledger.ai with “CCPA Request” in the subject line. We will verify your identity before processing your request and respond within 45 days.
6.3 Philippine Residents (Data Privacy Act of 2012 Rights)
If you are a resident of the Philippines, the Data Privacy Act of 2012 (Republic Act No. 10173) provides you with the following rights as a data subject:
- Right to be Informed — to be informed whether your personal data is being processed, and of the purposes and extent of processing.
- Right to Access — to obtain a copy of the personal data we hold about you.
- Right to Rectification — to request correction of inaccurate or outdated personal data.
- Right to Erasure or Blocking — to request the suspension, withdrawal, blocking, removal, or destruction of your personal data, subject to legal exceptions.
- Right to Object — to object to the processing of your personal data, including for direct marketing.
- Right to Data Portability — to obtain and reuse your personal data in an electronic, structured, and commonly used format.
- Right to Damages — to be indemnified for damages sustained due to unlawful or unauthorized processing.
- Right to Lodge a Complaint — to file a complaint with the National Privacy Commission (NPC) at privacy.gov.ph.
To exercise these rights, contact our Data Protection Officer at dpo@matchledger.ai. We will verify your identity before processing your request and respond within the timeframes required by applicable law.
6.4 Residents of the EEA, United Kingdom, and Switzerland
If you are in the European Economic Area, the United Kingdom, or Switzerland, the EU General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection gives you the following rights in relation to personal data we hold about you:
- Access — to confirm whether we process your personal data and to receive a copy of it.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to have your personal data deleted, subject to legal exceptions (for example, records we must keep under Section 5).
- Restriction — to require us to limit how we use your personal data while a dispute about it is resolved.
- Portability — to receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another provider where technically feasible.
- Objection — to object to processing based on our legitimate interests (Section 2.1), and at any time to processing for direct marketing.
- Withdrawal of consent — where processing is based on your consent, to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Complaint — to lodge a complaint with a supervisory authority, in particular in the country where you live or work. For Ireland, this is the Data Protection Commission (dataprotection.ie); for the United Kingdom, the Information Commissioner's Office (ico.org.uk); for Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would welcome the chance to address your concern first.
To exercise any of these rights, contact our Data Protection Officer at dpo@matchledger.ai. We will respond within one month of receiving your request; where a request is complex or we receive several from you, we may extend that period by up to two further months and will tell you if so. We do not charge for handling a request unless it is manifestly unfounded or excessive, and exercising your rights never affects the service you receive. We may ask you to verify your identity before acting.
Where we are your processor (Section 2.2) — that is, for personal data inside documents that a business customer uploaded about you — the business customer is responsible for responding to your request. If you contact us, we will refer your request to them and assist them in responding.
EU and UK representative. We have not designated a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR. We rely on the exemption for processing that is occasional and unlikely to result in a risk to your rights; should our processing of EEA or UK personal data cease to be occasional, we will designate a representative and update this Policy. In the meantime, dpo@matchledger.ai is the contact point for you and for supervisory authorities.
6.5 Do Not Track
Some browsers transmit “Do Not Track” (DNT) signals. The MatchLedger application does not track users across third-party websites and does not respond to DNT signals because no cross-site tracking occurs. Our marketing website uses Google Analytics and Google Ads conversion tracking, both of which may be affected by browser-level tracking prevention settings. See Section 7.2 for how to opt out.
7. Cookies and Browser Storage
7.1 MatchLedger Application (app.matchledger.ai)
The application stores information in your browser in two ways: in browser localStorage, which is used to run the application, and in cookies set by the analytics tools described in Sections 1.6 and 1.7.
Strictly necessary (localStorage — required to run the application):
| Key | Purpose | Duration |
|---|---|---|
| Authentication token (JWT) | Keeps you logged in between page loads | Until you log out or the token expires |
| Organization and plan information | Displays your current organization and subscription status | Until you log out |
| UI preferences (tooltip dismissals) | Remembers which first-visit hints you have dismissed | Until you clear browser storage |
Analytics and measurement (not required to run the application):
| Cookie or key | Set by | Purpose | Duration |
|---|---|---|---|
_ga, _ga_[ID] | Google Analytics | Distinguishes visitors and maintains session state | 2 years |
_gcl_au, _gcl_aw | Google Ads | Attributes a completed signup to the advertisement that brought you here (Section 1.6) | 90 days |
ph_[key]_posthog (cookie and localStorage) | PostHog | Recognises your browser across visits so product-usage events can be grouped (Section 1.7) | 1 year |
All of these are first-party cookies. No third-party advertising cookies are set by the application, and nothing from your financial documents, reconciliations, or account activity is used for advertising. If you are visiting from the EEA, the United Kingdom, or Switzerland, the analytics and measurement cookies are set only with your consent — see Section 7.3.
7.2 Marketing Website (matchledger.ai)
Our marketing website uses Google Analytics (GA4) and Google Ads conversion tracking, which set the following first-party cookies:
| Cookie | Purpose | Duration |
|---|---|---|
_ga | Distinguishes unique visitors | 2 years |
_ga_[ID] | Maintains session state | 2 years |
_gcl_au | Google Ads conversion linker — attributes a new signup to the advertisement that brought you to the site | 90 days |
_gcl_aw | Set only if you arrive by clicking one of our advertisements; stores the click identifier used for that attribution | 90 days |
The Google Analytics cookies collect anonymous, aggregated data about how visitors use the website (pages viewed, time on site, referral source). The Google Ads cookies are used for advertising measurement as described in Section 3. No financial data, document contents, or application activity is collected through any of these cookies.
You can opt out of Google Analytics and Google Ads measurement by:
- Using the Google Analytics Opt-out Browser Add-on
- Turning off ad personalization in your Google My Ad Center settings
- Adjusting your browser's cookie settings to block third-party cookies
- Using your browser's “Do Not Track” setting
We hold no advertising identifier linked to your name or email address, so there is nothing of that kind for us to delete. You can still request deletion of your account data at any time — see Section 6 (Your Rights).
7.3 Visitors from the EEA, United Kingdom, and Switzerland
If you visit the Website or the application from the European Economic Area, the United Kingdom, or Switzerland, we ask for your consent before setting any cookie or starting any analytics tool that is not strictly necessary to provide what you asked for. You can accept or decline with equal ease, decline without losing access to anything, and change your choice at any time from the cookie settings link in the page footer. Until you choose, the Google and PostHog cookies described in Sections 7.1 and 7.2 are not set, and Google's tags run in a mode that sends no cookies and no identifiers. The strictly necessary localStorage keys in Section 7.1 do not require consent. We determine your location from your browser's settings and connection, which is not always exact; if you are in one of these territories and were not shown a choice, write to dpo@matchledger.ai.
8. Third-Party AI Processing
The Service uses Anthropic's Claude artificial intelligence to extract structured data from your uploaded financial documents. When you upload a document and extraction is triggered:
- The contents of your document are transmitted to Anthropic's API servers via encrypted HTTPS connection
- Anthropic processes the document and returns extracted structured data
- We do not control how Anthropic handles data transmitted through their API — Anthropic's use of this data is governed by their own Usage Policy and Privacy Policy
We encourage you to review Anthropic's policies. This processing is how the Service produces its results: it is carried out to provide the Service to you (Section 2.1), and Anthropic acts as our sub-processor under its commercial API terms, which govern its handling of the data.
We send only the document content necessary for extraction. We do not send your account information, organization details, or data from other users to Anthropic.
9. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@matchledger.ai and we will delete that information.
10. International Users and Cross-Border Transfers
The Company is based in the United States and the Service is operated from the United States. We offer the Service to customers in multiple countries, including the United States, the Philippines, the European Economic Area, and the United Kingdom.
Regardless of where you are located, your information — including Customer Data and personal information — is transferred to, stored, and processed in the United States by us and by the sub-processors listed in Section 3. The United States may have data-protection laws that differ from those of your country of residence.
Where the Philippine Data Privacy Act of 2012 applies, we transfer and process your personal data on the legal bases described in Section 2.1, and we remain accountable for personal data transferred to our sub-processors, which are contractually bound to protect it.
Transfers from the EEA, the United Kingdom, and Switzerland. The United States has not been found by the European Commission to provide an adequate level of data protection for the purposes of the GDPR (nor by the UK or Swiss authorities under their laws). We therefore transfer personal data from those territories under the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), together with the UK International Data Transfer Addendum and the Swiss addendum, which we enter into with our business customers as part of our Data Processing Addendum (Section 2.2) and with each sub-processor in Section 3 that receives such data. We have assessed the laws and practices of the United States as they apply to the data we transfer and apply the safeguards in Section 4.3. A copy of the clauses as they apply to you is available on request from dpo@matchledger.ai. We do not rely on your consent as the basis for these transfers.
If you are a Philippine resident, your rights under the Data Privacy Act are described in Section 6.3, and you may contact our Data Protection Officer at dpo@matchledger.ai or lodge a complaint with the National Privacy Commission (privacy.gov.ph). If you are in the EEA, the United Kingdom, or Switzerland, your rights and how to complain are described in Section 6.4.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Publish the revised Privacy Policy with a new effective date
- Notify you by email at least 30 days before material changes take effect
- Note the changes in an in-app notification
Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes. If you do not agree with the updated Privacy Policy, you may export your data and close your account.
12. Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about how your data is handled, please contact us at:
MatchLedger, Inc.
1908 Thomes Ave, STE 68447, Cheyenne, Wyoming 82001, United States
General privacy inquiries: support@matchledger.ai
Data Protection Officer: dpo@matchledger.ai
For CCPA-specific requests, please include “CCPA Request” in the subject line. Philippine data subjects may contact our Data Protection Officer at dpo@matchledger.ai and may lodge complaints with the National Privacy Commission at privacy.gov.ph. Data subjects in the EEA, the United Kingdom, and Switzerland may contact the same address, which also serves as our contact point for supervisory authorities (see Section 6.4).