Privacy Policy
Last updated March 17, 2026
BeanStack AI, Inc. ("BeanStack," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect information when you use the BeanStack platform ("Service"). By using the Service, you agree to the practices described here.
The short version: We use your data to run the Service. We never use your financial data to train AI models. We do not sell your information.
1. Information We Collect
1.1 Information You Provide
Account information. Name, work email, company name, job title, and password when you register.
Organization information. Company details, industry, and settings provided during setup.
Customer Data. Financial documents, contracts, invoices, bank statements, and other business records you upload or create within the Service. This data is yours — see Section 5.
Payment information. Billing details processed by our payment provider. We retain only what is necessary for billing (such as the last four digits of a card and billing address). Full payment credentials are handled by our payment processor and are not stored on BeanStack systems.
Communications. Messages you send us via support channels, email, or in-product feedback.
1.2 Information Collected Automatically
Usage data. Pages visited, features used, actions taken, and session information as you interact with the Service.
Device and technical data. IP address, browser type, operating system, and similar technical identifiers.
Log data. Server logs, API requests, error reports, and performance data.
Cookies. See Section 7.
1.3 Information from Integrations
If you connect third-party integrations (accounting systems, banks, payment processors), we receive data from those services as authorized by you, solely to provide the integration functionality.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, operate, and improve the Service
- Process transactions and manage your subscription
- Authenticate users and protect account security
- Respond to your support requests and communications
- Send service-related notifications (billing, security, product updates)
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
- Analyze aggregated, de-identified usage statistics to understand how the Service is used and improve it
We do not use your Customer Data — your financial documents, extracted records, or AI interaction data — for general service improvement or any purpose beyond delivering the Service to you. See Section 5.
3. Legal Basis for Processing (GDPR)
For individuals in the European Economic Area, United Kingdom, or Switzerland, we process personal data under the following lawful bases:
| Purpose | Lawful Basis | |---------|-------------| | Providing the Service | Performance of contract (Art. 6(1)(b)) | | Billing and account management | Performance of contract (Art. 6(1)(b)) | | Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) | | Legal compliance | Legal obligation (Art. 6(1)(c)) | | Aggregated analytics | Legitimate interests (Art. 6(1)(f)) | | Marketing communications | Consent (Art. 6(1)(a)) |
4. Automated Decision-Making
BeanStack AI Features generate recommendations (journal entry proposals, document classifications, anomaly flags) that require human review. We do not make legally significant automated decisions about individuals using the Service. If we introduce automated decisions with significant legal or similarly significant effects in the future, we will update this policy and provide appropriate controls.
5. Your Customer Data and AI
5.1 Ownership
Your Customer Data — documents, records, extracted data, and outputs derived from your data — remains your property. BeanStack claims no rights to it.
5.2 Limited Processing
We process your Customer Data solely to provide and support the Service, including storing your records, processing documents, generating outputs you request, and maintaining backups.
5.3 No AI Training
BeanStack will not use your Customer Data to train, fine-tune, or improve any AI or machine learning model, including models used to serve other customers.
We may derive aggregated, de-identified, non-attributable statistics (such as system performance metrics) from Service usage, provided such data cannot reasonably be used to identify you or reconstruct your Customer Data.
5.4 Third-Party AI Providers
BeanStack uses third-party AI model providers to process certain requests. Our agreements with these providers require that your data not be used for model training and that it be handled with appropriate security controls. A current list of providers is maintained at beanstack.ai/subprocessors.
6. Data Sharing
We do not sell, rent, or trade your personal information or Customer Data.
We may share information in the following limited circumstances:
Service providers. We use vetted third-party vendors (subprocessors) to operate the Service, including cloud hosting, payment processing, email delivery, customer support, and analytics. Each is bound by contractual obligations restricting use to the purposes for which they are engaged. Our subprocessor list is maintained at beanstack.ai/subprocessors.
Legal compliance. We may disclose information when required by applicable law, court order, or government request. Where permitted, we will endeavor to provide notice before disclosing.
Business transfers. In connection with a merger, acquisition, or sale of assets, information may be transferred to a successor entity, subject to customary confidentiality protections.
Protection of rights. We may disclose information where we believe in good faith that disclosure is necessary to enforce our Terms, prevent harm, or protect the rights and safety of BeanStack, our customers, or others.
With your consent. For any other purpose with your explicit consent.
7. Cookies
We use cookies and similar technologies to operate and improve the Service. Cookie categories include:
Strictly necessary. Required for authentication and core Service functionality. These cannot be disabled.
Functional. Store your preferences and settings to improve your experience.
Analytics. Used for aggregated product analytics to help us understand Service usage and performance. You may opt out through the cookie settings in the Service.
We do not use cookies for advertising or cross-site tracking.
8. Data Retention
We retain your information for as long as your account is active and as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
After account closure or subscription termination, we will retain Customer Data for a limited period to allow for export, after which it will be deleted in accordance with our data retention practices. Specific retention periods may vary by data type and are subject to legal requirements. Billing records are retained as required by applicable tax and financial regulations.
You may request deletion of your account and associated Customer Data at any time by contacting privacy@beanstack.ai. We will process deletion requests in accordance with applicable law.
9. Data Security
BeanStack implements technical and organizational measures to protect your information, including encryption in transit and at rest, access controls and authentication requirements, and logical separation between customer data environments. No system is completely secure, and we cannot guarantee absolute protection.
In the event of a security incident involving unauthorized access to your personal data, we will notify affected customers in accordance with applicable law.
10. International Data Transfers
BeanStack is based in the United States. If you are located in the EEA, UK, or Switzerland, your data may be transferred to and processed in the US and other countries. We rely on lawful transfer mechanisms, including EU Standard Contractual Clauses, when transferring personal data internationally. You may request information about our transfer safeguards by contacting privacy@beanstack.ai.
11. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal information, and to receive a portable copy of your data. Residents of California have additional rights under CCPA/CPRA.
To exercise your rights, contact privacy@beanstack.ai. We will respond in accordance with applicable law. We may need to verify your identity before processing requests.
We do not discriminate against users for exercising their privacy rights.
12. Children
The Service is not directed to individuals under 18. We do not knowingly collect information from children. If you believe a child has provided us personal information, contact privacy@beanstack.ai.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will provide notice of material changes through the Service or by email. Your continued use of the Service after notice of a change constitutes acceptance.
14. Contact
For privacy questions or rights requests:
Email: privacy@beanstack.ai
BeanStack AI, Inc.
[Address]