Privacy Policy

Last updated: March 26, 2026

KiwiBooks Inc. ("Kiwibooks," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services at kiwibooks.ai.

1. Information We Collect

Personal Information You Provide

  • Account Information: Name, email address, password, and business name
  • Financial Data: Bank account connections, transaction data, invoices, receipts, and expense records
  • Payment Information: Billing address and payment method details (processed securely by our payment provider)
  • Communications: Messages you send us via email or support channels
  • Tax Information: Business type, tax ID, and information needed for tax reporting

Information Collected Automatically

  • Device Information: IP address, browser type, operating system, and device identifiers
  • Usage Data: Pages visited, features used, time spent on the service, and interaction patterns
  • Cookies and Similar Technologies: See our Cookie Policy for details

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our bookkeeping and tax preparation services
  • Process transactions and manage your subscription
  • Generate financial reports and tax documents
  • Use AI to categorize transactions and provide insights
  • Send service-related communications (billing, security, updates)
  • Provide customer support and respond to inquiries
  • Detect and prevent fraud, security incidents, and abuse
  • Comply with legal obligations and tax reporting requirements
  • Improve our AI models and service quality (using anonymized data)

3. Legal Basis for Processing (GDPR)

For users in the European Economic Area, we process your data based on:

  • Contract Performance: To provide our services as agreed
  • Legitimate Interests: To improve our services, prevent fraud, and market our products
  • Legal Compliance: To meet tax, accounting, and regulatory requirements
  • Consent: For optional marketing communications and certain cookies

4. Information Sharing and Disclosure

We do not sell your personal information. We may share your data with:

  • Service Providers: Companies that help us operate (payment processors, cloud hosting, analytics)
  • Your Accountant: If you invite them through our Partner Program
  • Bank Partners: For secure bank account connections (using encrypted APIs)
  • Legal Requirements: When required by law, subpoena, or court order
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: For any other purpose you authorize

5. Data Security

We implement strong security measures to protect your data:

  • 256-bit SSL/TLS encryption for data in transit
  • AES-256 encryption for data at rest
  • SOC 2 Type II compliant infrastructure
  • Regular security audits and penetration testing
  • Multi-factor authentication options
  • Strict access controls and employee training

While we use industry-leading security practices, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your information for as long as:

  • Your account is active and you use our services
  • Necessary to comply with legal obligations (typically 7 years for tax records)
  • Required to resolve disputes and enforce agreements

Upon account deletion, we will remove or anonymize your personal data within 30 days, except where retention is required by law.

7. Your Rights and Choices

All Users

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request deletion of your account and data
  • Export: Download your data in a portable format
  • Opt-out: Unsubscribe from marketing emails at any time

EEA/UK Residents (GDPR)

  • Right to restrict processing
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

California Residents (CCPA/CPRA)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale/sharing (we do not sell your data)
  • Right to non-discrimination for exercising your rights

To exercise any of these rights, contact us at privacy@kiwibooks.ai.

8. International Data Transfers

Your data may be transferred to and processed in the United States and other countries where our service providers operate. For transfers from the EEA/UK, we use Standard Contractual Clauses and other appropriate safeguards to ensure your data is protected.

9. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.

10. Third-Party Links

Our service may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

11. CAN-SPAM Act Compliance

Kiwibooks Inc. ("Kiwibooks," "we," "us," or "our") sends commercial email communications in compliance with the federal CAN-SPAM Act of 2003 (15 U.S.C. § 7701 et seq.). The following applies to all marketing, promotional, and transactional emails sent from kiwibooks.ai or on our behalf.

What Types of Emails We Send

We may send you the following categories of email:

  • Transactional emails — account confirmations, receipts, invoice notifications, security alerts, and other messages necessary to administer your Kiwibooks account.
  • Marketing and promotional emails — product updates, feature announcements, tax tips, offers, and other communications about Kiwibooks services.
  • Partner communications — if you are enrolled in our Accountant Partner Program, relevant program updates and client activity summaries.

How We Identify Our Emails

All commercial emails we send will:

  • Clearly identify the sender as Kiwibooks Inc. or Kiwibooks in the "From" name and email address.
  • Include an accurate, non-deceptive subject line that reflects the content of the message.
  • Include our valid physical mailing address in the footer of every email.
  • Be clearly labeled as advertising or promotional where required.

Our contact address is:

Your Right to Opt Out

You may opt out of receiving marketing and promotional emails from us at any time by:

  • Clicking the "Unsubscribe" link included in the footer of any marketing email; or
  • Emailing us directly at contact@kiwibooks.ai with "Unsubscribe" in the subject line.

We will process all opt-out requests within 10 business days of receipt, as required by law. After opting out, you will no longer receive promotional communications from us, though you may continue to receive transactional or account-related emails necessary to service your account.

We do not charge any fee, require you to provide any personally identifiable information beyond your email address, or make you take more than one step to unsubscribe.

No Third-Party Marketing Without Consent

We do not sell, rent, or transfer your email address to third parties for their independent marketing purposes without your explicit consent. If we engage third-party service providers to send emails on our behalf (such as email delivery platforms), those providers act under our instructions and are contractually prohibited from using your information for their own marketing.

Enforcement

We take CAN-SPAM compliance seriously. If you believe you have received an email from us that violates these requirements or applicable law, please contact us at contact@kiwibooks.ai so we can investigate and address the issue promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our service. Your continued use after changes constitutes acceptance of the updated policy.

13. Contact Us

For questions or concerns about this Privacy Policy or your data: