01Who we are and what this covers
Serbell, Inc. (“Serbell,” “we,” “us”) provides a financial operations platform for small and mid-sized businesses. This policy applies to our website, our web and mobile applications, and any service that links to it.
Our customers are businesses. The people who use Serbell are typically business owners, their staff, and the accountants they authorize. Where this policy refers to “you,” it means the individual using Serbell.
02Information we collect
Information you give us
Your name, email address, and password when you create an account. Your business name, industry, and similar details. Anything you send us in a support conversation. Invoices, customer records, and other documents you upload.
Financial account information
When you connect a bank account, we receive account balances, account names and types, masked account identifiers, transaction history including amounts, dates, descriptions, and counterparties, and account holder details such as name and address.
This access is read-only. Serbell can see your account activity. It cannot initiate payments, transfers, or withdrawals, cannot move funds between accounts, and does not hold or custody money on your behalf.
Serbell uses third parties to gather your data from financial institutions. By using Serbell, you grant Serbell and those third parties the rights, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution.
Specifically, we use Plaid Inc. to connect your accounts. You agree that your information will be treated in accordance with Plaid’s End User Privacy Policy. Your bank login credentials are provided directly to Plaid and are never transmitted to, seen by, or stored by Serbell.
Accounting and business system information
v1 does not require an accounting platform such as QuickBooks. If you later choose to connect an accounting system, or you upload invoices, statements, or similar records, we receive the bookkeeping data you provide: categories, invoices and bills, customer and vendor records, and related documents.
Each connection or upload is authorized by you and can be disconnected or deleted. The categories of data are the same regardless of how you provide them.
Information collected automatically
IP address, browser and device type, pages viewed, and actions taken in the product. We use this to keep the service secure, diagnose problems, and understand which features are used. We do not use third-party advertising trackers.
03How we use your information
- To run the service you signed up for: matching incoming payments to open invoices, tracking receivables, forecasting cash position, and flagging overdue accounts.
- To learn how your business actually behaves: Serbell records rules specific to you, such as which customers reliably pay late or how a particular expense should be categorized, so the product gets more accurate over time for you.
- To communicate with you: service notifications, alerts you configure, security notices, and support responses.
- To keep the service secure: detecting fraud, abuse, and unauthorized access.
- To meet legal obligations and enforce our terms.
- Not to move money. Serbell does not initiate payments, transfers, or withdrawals, does not hold or custody funds, and is not a bank, money transmitter, or payment processor. Where you decide to pay or collect, you do so through your own bank or payment provider.
- To improve Serbell: we may use aggregated and de-identified information, which cannot reasonably be used to identify you or your business, to improve accuracy and develop features. We do not sell this information or provide it to third parties as a product.
04Automated processing and AI
Serbell uses automated systems, including artificial intelligence models, to categorize transactions, match payments to invoices, and answer questions you ask about your finances in plain language. This processing may involve your transaction and accounting data.
AI processing is performed inside our cloud provider’s infrastructure by service providers operating under contract. Your data is not retained by the model provider and is not used to train any model.
These systems support your decisions; they do not make decisions about you that produce legal or similarly significant effects. You can reach a person at any time at privacy@serbell.com.
05How we share your information
Service providers
We share information with companies that help us operate Serbell, under contracts that limit them to providing services to us:
| Provider | What they do |
|---|---|
| Amazon Web Services | Hosts our infrastructure, stores data, manages encryption keys, and provides AI inference |
| Plaid Inc. | Connects your bank accounts and retrieves financial data |
| Stripe, Inc. | Processes subscription payments as our payment processor and a subprocessor of billing data (customer email, payment method tokens, invoices). Serbell does not store card numbers. |
People you authorize
If you invite your accountant, bookkeeper, or a colleague, they can see the information their role permits. They sign in under their own account, and you can revoke their access at any time.
Legal and business transfers
We may disclose information if required by law, subpoena, or court order, or where necessary to protect our rights or someone’s safety. If Serbell is acquired or merged, information may transfer as part of that transaction; you will be notified and this policy will continue to apply until you are told otherwise.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. We do not provide your financial data to credit bureaus or consumer reporting agencies, and we do not use it to generate consumer reports.
06Your consent and how to withdraw it
Before we collect any financial account data, we show you what we will receive, how we will use it, and who we share it with, and we ask you to accept. We keep a record of the exact wording you agreed to and when.
You can disconnect a bank account in Serbell at any time, or email privacy@serbell.com. Disconnecting deletes the bank connection and its tokens immediately and stops future collection from that account. Bookkeeping entries and documents you already saved stay. To manage what Plaid itself retains, visit my.plaid.com. Deleting the books for one account, or closing the organization, is a separate action described in section 8.
Withdrawing consent does not affect processing that already happened, and some features will stop working without a connected account.
07How long we keep your information
We keep information only as long as we need it to provide the service, meet legal obligations, or as permitted by your consent.
| Type of information | How long we keep it |
|---|---|
| Bank connection tokens | Only while the connection is active. Deleted immediately when you disconnect the account or withdraw consent. You can also manage Plaid-held data at my.plaid.com. |
| Financial and bookkeeping data | While the organization is open. Canceling the subscription does not delete it: you keep 30 days of read-only access to export or reactivate, and we email you when you cancel and again about 7 days before that window ends. If you do not reactivate, the organization closes at that date and live data is deleted within 24 hours. You can also request closure yourself, with 7 days to cancel the request, or ask us not to wait. After a firm request, live data is deleted within 24 hours. |
| Account and profile information | For as long as your account is open, plus any period required by law. |
| Billing agreements (Terms/Privacy versions and timestamp) | Retained as evidence of acceptance for as long as legally required. |
| Trial anti-abuse markers | Cognito sub and an HMAC of the email (never the email in the clear), retained 24 months after consumption so deleting an organization does not grant another trial. |
| Stripe billing records | Stripe retains what its legal obligations require. We do not promise deletion of copies Stripe must keep. |
| Consent records | Retained as evidence that consent was obtained, including after deletion of the underlying data, for as long as legally required. |
| Security and audit logs | As long as operationally and legally necessary. |
| Encrypted backups and point-in-time recovery | Expire with the database backup window of the environment: 7 days in development, 35 days in production. A restore does not bring deleted customer data back as a live organization. |
We review these periods and update this policy when they change.
08Deleting your information
The owner can export or close an organization in the product. You can also email privacy@serbell.com. You do not need to give a reason.
- Closing an organization asks you to confirm and enter your password again. You then have 7 days to cancel that request and keep exporting. You can also confirm that you do not want to wait. The 24 hours start when the request is firm (the wait ended, or you skipped it): live data leaves our systems within 24 hours of that firm request.
- If you only cancel the subscription, the 30-day read-only window is the waiting period. At the end of it, the same 24-hour deletion applies. We email you when you cancel and again about 7 days before the window ends. Export and reactivation stay available until that date.
- Disconnecting a bank account is not closing the organization. It deletes the connection and stops future collection. Entries and documents remain until you delete that account or close the organization. Plaid-held data is managed at my.plaid.com.
- Copies held in encrypted backups and point-in-time recovery expire with the backup window of the environment (7 days in development, 35 days in production). A restore does not bring a closed organization back as live data.
- If closing the organization leaves you with no other organization, we delete that Cognito sign-in. Closing one organization does not remove your access to another.
- We keep a minimal record that the closure happened, the trial anti-abuse marker (Cognito sub and an HMAC of the email, never the email in the clear) for 24 months, and whatever Stripe must retain under its own legal duties. We do not promise deletion of copies a provider is required to keep.
Deleting your data with Serbell does not delete data held by Plaid or by any accounting or ERP provider you have connected. To manage what Plaid holds, visit my.plaid.com.
09How we protect your information
Serbell maintains a written information security program covering how we handle, store, and dispose of your data. Measures include:
- Encryption in transit using TLS 1.2 or higher, and encryption at rest. Sensitive fields, including bank connection tokens, receive an additional layer of encryption.
- Multi-factor authentication required on your Serbell account before any bank connection can be made.
- Access to production systems limited to named individuals, with every action logged.
- A serverless architecture with no persistent servers and no interactive access to production systems.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your information, we will notify you as required by law.
10Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you and how we use it; to receive a copy in a portable format; to correct inaccurate information; to delete your information; and to withdraw consent.
To exercise any of these, email privacy@serbell.com. We will verify your identity before acting, and we respond within the timeframes required by applicable law. We will not discriminate against you for exercising a privacy right.
California residents
Under the California Consumer Privacy Act, you have the rights described above, plus the right to opt out of the sale or sharing of personal information. Serbell does not sell or share personal information, so there is nothing to opt out of. The categories we collect are identifiers, commercial information, financial information, and internet activity, as described in section 2. We collect them for the purposes in section 3, from you, your financial institution via Plaid, and any accounting or ERP system you connect. You may designate an authorized agent to make a request on your behalf.
11Where your information is stored
Serbell is a United States company. Your information is stored and processed on infrastructure located in the United States. If you access Serbell from outside the United States, you understand that your information will be transferred to and processed there, where privacy laws may differ from those in your country.
12Children
Serbell is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. Contact privacy@serbell.com if you believe this has happened.
13Changes to this policy
We may update this policy as Serbell changes. We will post the new version here and update the date at the top. If the changes are material, we will notify you by email or in the product before they take effect, and where the law requires it, we will ask for your consent again.
14Contact us
Questions, requests, or complaints about privacy:
Serbell, Inc.
Support: support@serbell.com
Privacy: privacy@serbell.com
Security: security@serbell.com
We aim to resolve any concern directly. You also have the right to complain to your local data protection authority.