Privacy Policy

Effective Date: April 9, 2026 · Last Updated: April 9, 2026

1. Introduction

ShepherdBooks (“we,” “us,” or “our”) is a pastoral tax management platform that helps pastors and clergy track financial transactions, manage receipts, and prepare year-end tax reports. This Privacy Policy describes how we collect, use, store, and protect your personal and financial information when you use our website and services at shepherdbooks.app.

2. Information We Collect

Account Information: When you create an account, we collect your name, email address, church name, and denomination. If you sign in with Google, we receive your name and email from Google.

Financial Data via Plaid: When you connect a bank account through Plaid, we receive transaction data (dates, amounts, merchant names, categories), account information (institution name, account type, last four digits), and account balances. We do not receive your bank login credentials. Plaid handles authentication directly.

User-Provided Data: You may provide receipts (uploaded images), transaction notes, business entity details, housing allowance designations, and tax category assignments.

Automatically Collected Data: We collect basic usage data through our hosting provider (Vercel), including IP address, browser type, and pages visited. We do not use third-party analytics or advertising trackers.

3. How We Use Your Information

We use your information solely to provide the ShepherdBooks service:

  • Displaying and categorizing your financial transactions
  • Generating year-end tax summary reports
  • Tracking housing allowance usage under IRC Section 107
  • Storing receipts for tax documentation
  • Sending service-related emails (account verification, report delivery to your accountant)

We do not sell, rent, or share your personal or financial data with third parties for marketing or advertising purposes.

4. Plaid Integration

We use Plaid Inc. to connect your bank accounts. When you use Plaid Link, you are interacting directly with Plaid’s service. Your bank credentials are provided to Plaid, not to ShepherdBooks. We receive only the transaction and account data described above. Plaid’s use of your data is governed by the Plaid End User Privacy Policy.

5. Data Storage and Security

Hosting: Our application is hosted on Vercel. Our database is hosted on Supabase (PostgreSQL).

Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (TLS 1.3 is enforced by default).

Encryption at Rest: All data stored in our database is encrypted at rest using AES-256 encryption provided by Supabase.

Authentication: We support email/password login, Google OAuth, and email-based multi-factor authentication (MFA) to protect your account.

Access Controls: All API endpoints enforce authentication. Users can only access their own data. No ShepherdBooks personnel other than the sole operator have access to production systems, and all administrative access requires MFA.

6. Data Retention and Deletion

We retain your data for as long as you maintain an active ShepherdBooks account. You may request deletion of your account and all associated data at any time through the Settings page of the application.

Upon account deletion:

  • All transaction data, receipts, reports, and business entity records are permanently deleted.
  • Plaid access tokens are revoked and deleted.
  • Your account record is removed from our database.
  • Deletion is completed within 30 days of your request.

We may retain anonymized, aggregated data that cannot identify you for service improvement purposes.

7. Consumer Consent

Before connecting a bank account through Plaid, we request your explicit consent for the collection, processing, and storage of your financial data. You may withdraw consent and disconnect your bank accounts at any time.

8. Your Rights

You have the right to:

  • Access the personal and financial data we hold about you (available in the application)
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Withdraw consent for data collection at any time by disconnecting your bank accounts
  • Export your data (via year-end report generation)

9. Children’s Privacy

ShepherdBooks is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email of any material changes. The “Last Updated” date at the top of this page indicates when the policy was last revised.

11. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: charlestark@gmail.com

ShepherdBooks · Pastoral Tax Management · © 2026