Arcaiva · Legal
Privacy Policy
Last updated: August 20, 2026
Overview
Arcaiva (“Arcaiva,” “we,” “us”) provides accounting and bookkeeping software at arcaiva.app (the “Service”). This policy explains what information we collect, how we use and protect it, who we share it with, and the choices you have. By using the Service you agree to the practices described here.
Information we collect
We collect the following categories of information:
- Account information — name, email address, mobile phone number (if provided), organization name, and authentication credentials.
- Billing information — payment method details processed by our payment processor; we do not store full card numbers ourselves.
- Accounting data you enter — chart of accounts, customers, vendors, transactions, invoices, bills, and supporting documents you upload.
- Connected-service data — data received from third-party services you connect, including QuickBooks Online, bank-feed providers, and email/calendar integrations.
- Usage data — log data such as IP address, browser, pages viewed, and timestamps, used for security and product improvement.
Data received from QuickBooks Online
When you connect a QuickBooks Online (“QBO”) company to Arcaiva, we receive and store the following categories of data from Intuit on your behalf:
- Chart of accounts, classes, and items
- Customers, vendors, and employees
- Invoices, bills, payments, deposits, transfers, journal entries, and other transactions
- Attachments and notes associated with the above
- Company metadata (company name, fiscal year, base currency, etc.)
We use this data solely to provide the Service to you and your organization — including mirroring, categorization, reporting, reconciliation, and AI-assisted bookkeeping features. We do not sell QBO data, and we do not share it with third parties for their own marketing or advertising purposes.
You can disconnect QuickBooks Online from Arcaiva at any time from Integrations → QuickBooks, or from your Intuit account’s “My Apps” page. Disconnecting stops further data synchronization. To request deletion of QBO data previously received, see Data retention and deletion below.
Data received through Plaid
When you choose to connect a financial account, Arcaiva uses Plaid to request the account access you authorize. Plaid provides Arcaiva with institution and account metadata, account names and types, masked account numbers, current or available balances, and transaction history. Arcaiva requests Transactions access only; it does not receive or store the username or password you enter in Plaid Link.
We use Plaid data to synchronize transactions, display balances, support reconciliation, and provide bookkeeping and categorization features. Plaid access tokens are encrypted and used only by Arcaiva’s server-side integration. We do not sell Plaid data or use it for third-party advertising.
You can disconnect a bank connection from Integrations → Bank connections. Arcaiva will request removal of the Plaid Item before deleting the local connection; this stops future Plaid access and Transactions billing for that Item. If Plaid’s response is uncertain, local deletion is paused so the outcome can be reconciled safely. Local transaction history is retained while your account or connection remains active and is deleted when you complete the applicable connection or account deletion workflow, except for records we must retain by law.
Plaid’s own handling of information is described in the Plaid End User Privacy Policy.
How we use information
We use the information we collect to:
- Operate, maintain, and improve the Service
- Mirror and synchronize data between Arcaiva and your connected services
- Generate reports, suggestions, and AI-assisted categorizations
- Authenticate you and protect your account
- Process payments and manage your subscription
- Send transactional and account-related messages (see SMS Notifications Terms for SMS specifics)
- Comply with legal obligations and enforce our Terms of Service
Service providers we share data with
We share information only with vendors that help us operate the Service, each bound by contractual confidentiality and data-protection obligations. These currently include:
- Supabase — database hosting and authentication
- Stripe — payment processing
- Twilio — SMS delivery (for users who opt in)
- Resend — transactional email delivery
- Intuit — QuickBooks Online API access
- Plaid — user-authorized bank connection and Transactions API access
- AI providers — language-model providers used to power assistant and categorization features; data sent for these features is governed by the providers’ zero-retention or limited-retention enterprise terms where available
We do not sell personal information. We may disclose information when required by law, subpoena, or court order, or to protect the rights, property, or safety of Arcaiva, our users, or others.
Data retention and deletion
We retain your data for as long as your account is active and for a reasonable period afterward to comply with legal, tax, and accounting record-keeping obligations.
You can request deletion of your account and associated data — including data received from QuickBooks Online and through Plaid — by emailing support@arcaiva.app from the email address on your account. We will confirm and complete the deletion within 30 days, except for records we are required to retain by law.
Security
We use industry-standard technical and organizational measures to protect your information, including TLS in transit, encryption at rest for credentials and tokens, least-privilege access controls, and audit logging. No system is perfectly secure; if you believe your account has been compromised, contact us immediately at support@arcaiva.app.
Your choices
You can:
- Update your account information from Settings
- Disconnect any third-party integration from Integrations
- Opt out of SMS notifications at any time (see SMS Notifications Terms)
- Request a copy of your data or its deletion by contacting support
Children
The Service is not directed to children under 13, and we do not knowingly collect information from children under 13. If you believe a child has provided us information, contact us so we can delete it.
Changes to this policy
We may update this policy from time to time. We will update the “Last updated” date above and, for material changes, notify users by email or in-product notice.