Privacy Policy
Last updated: August 2, 2026
GapLedger is operated by Stratiback LLC (Louisiana, USA). This policy describes what personal data we collect when you use gapledger.com, why, and the choices you have. The short version: we collect what the service needs to function, we sell nothing, and there is no third-party advertising or tracking on this site.
What we collect
Account data: your name (if provided), work email address, and a salted hash of your password — never the password itself. Multi-factor authentication secrets are stored encrypted. Signup context: the IP address used at registration, kept for abuse prevention. Content you add: the compliance material your organization puts into the service — controls, risks, notes, evidence files — which may incidentally contain personal data your organization chooses to include. Operational records: an append-only audit trail of actions in your workspace (who did what, when), and server logs kept for security and troubleshooting.
What we use it for
Operating the service, authenticating you, sending the emails the service depends on (verification links, task and deadline reminders, billing notices), preventing abuse, and providing support when you contact us. We send no marketing email without separate consent. We do not sell or share personal data for advertising.
Who else touches your data
We use a small number of service providers: Stripe (payment processing — we never see your card number), Postmark (transactional email delivery), and US-based hosting infrastructure operated by Stratiback LLC. These providers process data only as needed to provide their service to us. We disclose data if required by law, and we will tell you when we are permitted to.
Cookies
Essential cookies, always set: a session cookie to keep you signed in and, where applicable, a cookie recording a consultant’s active client context. We also store your cookie choice itself in your browser’s local storage so we don’t ask again.
Analytics and advertising cookies from Google Analytics and Google Ads, used to measure which campaigns bring people here. These are set only if you accept them. Until you choose, and if you decline, Google’s tags run with all storage denied — no cookies are written and no advertising identifiers are collected. Declining changes nothing about how the product works. You can change your choice at any time:
Accepting means Google receives your IP address and page-view information and may use it to attribute advertising. Google acts as an independent controller for that data; see Google’s own privacy policy for what it does with it.
Retention
Account and workspace data is retained while your account exists and for a reasonable period afterwards to allow reactivation and export. Evidence files are special: they are stored in write-once storage under a one-year compliance retention lock, and cannot be deleted by anyone — including us — until that lock expires. If you ask us to erase your data, we will delete or de-identify everything within our control and confirm the date on which locked evidence will be destroyed. Database backups are retained for 14 days.
Security
Every account requires multi-factor authentication. Customer workspaces are isolated at the database layer with row-level security. Evidence is content-hashed and stored write-once. The audit trail is append-only and cannot be modified even by our own application. Data is encrypted in transit; MFA secrets are encrypted at rest.
Your rights
You can access and export your organization’s data at any time from within the service. You may request correction or deletion of personal data, subject to the evidence retention lock described above. If you are in the UK, EU, or another jurisdiction with statutory data rights, we will honor access, rectification, erasure, portability, and objection requests as those laws provide. Contact us via the contact form — it is the fastest route to a human.
International transfers
The service is hosted in the United States. If you use it from elsewhere, your data is processed in the US. Customers needing a data processing agreement for their own compliance obligations can request one via the contact form.
Changes
We will update this policy as the service evolves and note the date above. Material changes will be announced by email or in-app notice before they take effect.