VIGIL ("we", "us", "our") provides AI-powered general ledger intelligence software. Our service is operated by VIGIL Technologies, LLC ("the Company"). References to "you" mean the individual or organisation using our service.
Our contact address for privacy matters: support@vigilgl.com
When you create an account we collect your username, email address, and a hashed version of your password. We never store your password in plain text.
To provide GL analysis, VIGIL processes general ledger data you provide — either by connecting QuickBooks Online via OAuth 2.0 or by uploading a CSV/XLSX export. This data includes journal entries, account names, transaction amounts, and dates.
We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate and improve the service. This data is retained for up to 90 days.
Payments are processed by Paddle. We do not store your card details. We receive a customer ID and subscription ID from Paddle to manage your account status.
If you use the free GL health check without creating an account, your GL data is processed in memory and results are held for 24 hours only, after which they are deleted. A privacy-safe hash of your IP address is retained for 30 days solely to enforce the one-check-per-30-days rate limit.
We do not use your financial data to train general AI models. GL data is processed solely to produce findings for your workspace.
We may send you product update and feature announcement emails. You can opt out of non-transactional emails at any time by clicking the unsubscribe link in any such email or by emailing support@vigilgl.com. We will continue to send essential transactional emails (account verification, billing receipts, security notices) regardless of marketing preferences.
For users in the UK and EU, our lawful bases are:
We share data only with the third parties necessary to operate the service:
We do not sell your data to third parties. We do not share your financial data with advertisers.
We retain your account data and GL findings for as long as your subscription is active. Upon cancellation, your data is retained for 30 days to allow for re-activation or export, then permanently deleted. You may request earlier deletion at any time by emailing support@vigilgl.com.
We implement industry-standard security measures including:
In the event of a personal data breach that is likely to result in a risk to your rights or freedoms, we will notify you and relevant supervisory authorities within the timeframes required by applicable law (within 72 hours under GDPR where feasible). Our notification will describe the nature of the breach, the categories of data affected, likely consequences, and the steps taken or proposed to address it.
VIGIL is hosted on AWS infrastructure. If you are located in the UK or EU, your data may be processed in the United States. Where this occurs, we rely on Standard Contractual Clauses (SCCs) as the legal mechanism for the transfer.
Depending on your location, you may have the following rights:
To exercise any of these rights, email support@vigilgl.com. We will respond within 30 days.
If you are in the UK or EU and believe we have not handled your data correctly, you have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK).
VIGIL uses a single httpOnly cookie to maintain your authenticated session (the refresh token). We do not use tracking, advertising, or analytics cookies. No third-party cookies are set by our service.
Some browsers offer a "Do Not Track" (DNT) signal. VIGIL does not currently respond to DNT signals because no industry-wide standard has been established. We do not track users across third-party websites and do not use cross-site behavioural advertising.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise these rights, email support@vigilgl.com with "California Privacy Request" in the subject line. We will verify your identity and respond within 45 days, with a possible 45-day extension where permitted by law.
VIGIL is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this policy from time to time. We will notify you of material changes by email and by updating the "Last updated" date above. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.
For any privacy-related questions or to exercise your rights, contact us at: support@vigilgl.com