Privacy Policy
Effective October 1, 2026
Mastro is bookkeeping software for accounting firms and the businesses they keep books for. This policy explains what information Mastro ("we", "us") collects through app.mastroledger.com (the "Service"), how we use it, who we share it with, and the choices you have.
Who this covers
Accounting firms ("firms") use the Service to keep books for their clients, and those clients use the Service's client portal. The financial records a firm keeps in the Service for a client are processed by us on the firm's behalf and under its instructions. If you're a firm's client, your firm decides what is kept about your business; you can contact your firm, or us, with questions.
What we collect
Account and sign-in information
- Your email address, and the firms and businesses you belong to, with your role in each.
- One-time sign-in codes we email you. We store them only as a one-way hash, and they expire after 10 minutes. There are no passwords to collect.
- If you set up two-step sign-in, your authenticator secret (stored encrypted) and recovery codes (stored only as one-way hashes).
- For each signed-in session: when it started and was last used, the IP address, and the browser type.
Bookkeeping records
The chart of accounts, journal entries, bank and card transactions, categorization rules, reconciliations, month-end closes, and reports that a firm creates or imports, along with documents uploaded to the Service and the questions, answers, and messages exchanged between a firm and its client.
Bank connections, through Plaid
When a business connects a bank or card account, it signs in to its bank through Plaid Inc. ("Plaid"). We never see or store bank usernames or passwords. Plaid gives us the account's name, type, and last four digits, and its transactions (date, amount, description, and merchant name). We store the access key Plaid issues for the connection, encrypted. Plaid's handling of your information is described in the Plaid End User Privacy Policy. A connection can be ended at any time by asking the firm, or through Plaid at my.plaid.com.
QuickBooks connections, through Intuit
When a firm connects a client's QuickBooks Online company to move its books into Mastro, we read that company's information and settings, its chart of accounts, and its transactions and reports, including the names of customers and vendors on those transactions. We only read; we never create, change, or delete anything in QuickBooks. We store the access tokens Intuit issues, encrypted. A firm can disconnect QuickBooks at any time from the client's QuickBooks migration page in Mastro, or from the Apps settings inside QuickBooks; disconnecting in Mastro revokes our access at Intuit and deletes the stored tokens. Books already imported stay in Mastro as part of the firm's records.
We send sign-in codes, invitations, and notices that something new is waiting. Notices contain counts and a link, never financial details, document contents, or message text.
How we use information
- To provide the Service: keeping books, bringing in bank transactions, importing QuickBooks history, producing reports, and running the client portal.
- To keep accounts secure: sign-in codes, two-step sign-in, limits on sign-in attempts, and an audit trail of changes.
- To send the emails described above, and to answer support requests.
- To meet legal obligations.
Mastro's own team can see, for every firm, firm-level details: its name, the people in it with their roles and email addresses, how many clients and connections it has, and when it was last used, so we can support firms and run the Service. They don't see a client's books (amounts, transactions, documents, or messages) unless a firm adds them to its team.
We do not sell personal information. We do not use customer financial data for advertising, and we do not use it to train artificial intelligence or machine learning models.
Cookies
The Service sets one cookie, named session, which keeps you signed in. It is sent only to our site, can't be read by scripts, and expires after 30 days, or after 7 days without use. We use no analytics, advertising, or third-party tracking cookies. When a business connects a bank, Plaid's connection window loads from Plaid's servers and is governed by Plaid's policy.
Who we share information with
We share information only with the service providers that run the Service, each limited to what its job needs:
- Hetzner Online GmbH hosts the Service. Our servers are in Hillsboro, Oregon, USA. Backups are encrypted on our server before they leave it and are stored by Hetzner in Germany; Hetzner cannot read them.
- Resend delivers our email (your email address and the email itself).
- Plaid Inc. connects bank and card accounts, only when a business chooses to connect one.
- Intuit Inc. provides access to QuickBooks Online, only when a firm chooses to connect one.
- Cloudflare, Inc. provides DNS for our domain name. It does not carry or see the Service's traffic.
Inside the Service, a firm sees the books of the businesses it serves. A business's users see only their own company: its closed months, documents, questions, and messages. Other firms and other businesses never see your information; the database itself enforces this on every request.
We may also disclose information when the law requires it, or to protect the rights and safety of our customers or the public. If Mastro is ever sold or merged, the successor must honor this policy for information collected under it.
Security
- All traffic is encrypted with HTTPS.
- Firm staff must use two-step sign-in. Sign-in codes expire quickly, and repeated attempts are limited.
- The database checks who may see and change what on every request, so one customer's data is never visible to another.
- Bank and QuickBooks access tokens and authenticator secrets are encrypted with AES-256-GCM. Uploaded documents are encrypted on our servers.
- Posted bookkeeping entries can't be edited or deleted, only corrected by new entries, and changes are recorded in an audit trail.
- Backups run every hour, are encrypted before leaving our server, and a test restore runs every week.
No system is perfectly secure. If a breach affects your information, we will notify the affected customers as the law requires.
How long we keep information
We keep a firm's records while it uses the Service. Bookkeeping records are kept complete by design: corrections are added, not erased. When a firm stops using the Service, it can export its reports, general ledger, and documents first. On written request after that, we delete the firm's data from our live systems within 30 days. Encrypted backups are deleted on a rolling schedule and are gone within 24 months. We may keep information longer where the law requires.
Your choices and rights
- You can ask to see, correct, export, or delete your personal information. Firms can do much of this in the Service; anyone can email support@mastroledger.com. We respond within 30 days.
- If you're a firm's client, some requests about your business's records may need your firm's approval, because the firm keeps those records.
- California residents have the right to know, delete, and correct personal information, and to not be discriminated against for using these rights. We do not sell or share personal information for advertising, so there is nothing to opt out of.
Children
The Service is for businesses. We don't knowingly collect information from anyone under 18.
Changes to this policy
We'll post any changes on this page and update the effective date. If a change is significant, we'll also email the firms using the Service before it takes effect.
Contact
Questions or requests: support@mastroledger.com.