Privacy Policy

Last Updated: August 21, 2026 Version: 1.4

Incremenza LLC ("Incremenza," "we," "us," or "our") operates the Incremenza platform at incremenza.com. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what choices you have.

This policy covers our website, our marketing pages, and the Incremenza application. It is written to be readable. Where a term has a specific legal meaning, we explain it in plain language first.


1. Our two roles

Incremenza handles two different kinds of personal information, and our responsibilities differ for each.

Information about you and your team. When you sign up, manage your account, and use the product, we decide what to collect and why. For this information we are the data controller.

Information about your customers and your business contacts. When you connect an accounting system, a payment processor, or a bank feed, we receive information about the people your business deals with. We process that on your instruction, and you decide what happens to it. For this information you are the controller and we are the data processor.

If you are subject to the GDPR, the UK GDPR, or a comparable law, our Data Processing Addendum governs how we act as your processor.


2. Information we collect

2.1 Information you give us

Account information. Your name, email address, company name, job title, team name, and role within your organization.

Single sign-on. If you sign in with Google or Microsoft, we receive your name, email address, and a unique profile identifier from that provider. We never receive your password. You can disconnect single sign-on at any time from your security settings.

Billing information. When you subscribe, we collect the billing contact details needed to process your payment. Card details are collected and stored by Stripe. We never see or store full card numbers.

Support and communications. Messages you send us, survey responses, and notes from support conversations.

Business profile information. Details you enter about your business, including your legal business name and mailing address, which are used in the footers of emails you send to your own customers.

2.2 Information from services you connect

When you connect a third-party service, we import data on your behalf. What we receive depends on which service you connect.

Bank and credit data, through Plaid. Transaction history, account balances, masked account identifiers, transaction descriptions, merchant names, dates, and amounts.

Payment processor data, from Stripe, Square, and PayPal. Your customer records, payment transactions, subscription details, invoices, refunds, transaction fees, and payment method details limited to the last four digits.

Accounting data, from QuickBooks Online. Your chart of accounts, invoices, bills, payments, customer records, vendor information, and account categories. We write data back to QuickBooks only if you enable two-way sync, and then only categorized transaction updates.

Product usage signals, from your own PostHog account. If you connect PostHog, we read usage events about your customers so they can inform customer health scoring. That remains your data in your account.

Connection credentials. Access and refresh tokens for connected services, encrypted at rest.

What we never store: full credit card numbers, full bank account numbers, card security codes, or your credentials for any connected service.

How connected data is used. Data imported from connected services is used only to provide the Service to you. We do not sell it, share it for advertising, or use it for any purpose other than delivering the product you asked for. Data obtained through Plaid is subject to this restriction specifically. By connecting a bank or financial account through Plaid, you acknowledge and agree that this information will also be treated in accordance with Plaid's End User Privacy Policy.

2.3 Information collected automatically

Usage information. Pages viewed, features used, actions taken, and time spent in the application. This is collected within the logged-in application only, using PostHog, and is described in Section 8.

Device and connection information. IP address, browser type and version, operating system, and device identifiers.

Cookies. A small number of cookies, described in Section 9 and in our Cookie Policy.

Server logs. Access times, request paths, and error records. Sensitive values such as tokens and credentials are automatically removed before logs are written or transmitted.

Security and authentication records. Sign-in events, sign-in location, failed sign-in attempts, active sessions, and changes to security settings. These are kept as a security audit trail.


3. How we use information

3.1 To provide the Service

  • Operate and maintain the platform
  • Import, reconcile, and categorize your financial transactions
  • Calculate metrics such as revenue, costs, profit, burn rate, and runway
  • Produce reports, scores, dashboards, and guidance
  • Track customer health, objectives, and team activity
  • Send email to your own customers when you configure automations to do so
  • Manage your account, subscription, seats, and billing
  • Process payments through the embedded payments feature, where you have enabled it

3.2 To communicate with you

  • Send service messages about your account, billing, security, and connected integrations
  • Respond to support requests
  • Send product updates and feature announcements
  • Send marketing messages, which you can opt out of at any time

Service and billing messages are necessary to operate your account and cannot be turned off while your account is active.

3.3 To keep the Service secure

  • Detect and prevent fraud, abuse, and unauthorized access
  • Monitor system health and integration connectivity
  • Investigate suspected violations of our Terms of Service or Acceptable Use Policy
  • Maintain audit records
  • Comply with legal obligations

3.4 To improve the Service

  • Understand which features are used and where people get stuck
  • Diagnose errors and performance problems
  • Develop new features and improve existing ones
  • Produce aggregated statistics and industry benchmarks

Benchmarks and statistics are produced from aggregated, anonymized information that does not identify you, your organization, your team, or your customers.


4. Legal bases for processing

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases.

Performance of a contract. Providing the Service you subscribed to, managing your account, and billing you.

Legitimate interests. Securing the platform, preventing fraud and abuse, improving the product, and communicating with existing customers about the service they use. We balance these against your rights and interests.

Legal obligation. Meeting tax, accounting, and other legal requirements.

Consent. Optional marketing communications. You can withdraw consent at any time without affecting your use of the Service.


5. How we share information

We do not sell your personal information. We do not rent it, and we do not share it with advertisers or data brokers.

We share information only in the situations below.

5.1 Service providers

We use a small number of specialist providers to deliver the Service, covering hosting, backups, email delivery, error monitoring, product analytics, payment processing, and the automated features described in Section 8.

The complete, current list is published at incremenza.com/legal/sub-processors, including what each provider does, where it is located, and how international transfers are handled.

Every provider is bound by a written agreement requiring it to protect your information, to use it only for the purpose we specify, and to meet standards at least as protective as those in this policy.

We give at least 30 days' notice before adding a new provider that will process personal information. Details of how to receive those notices, and how to object, are on the sub-processor page.

5.2 Within your organization

Information you and your team enter into Incremenza is visible to other authorized users in your organization according to their role. Administrators can see all data within your organization. This is how the product is designed to work.

5.3 Legal requirements

We may disclose information where we reasonably believe it is necessary to comply with a law, regulation, legal process, or government request, to enforce our agreements, to investigate fraud or security issues, or to protect the rights, property, or safety of Incremenza, our customers, or the public.

Where we are legally permitted to do so, we will notify you before responding to a request for your data.

5.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

5.5 With your direction

We share information with third parties when you ask us to, including when you connect an integration or configure an automation that sends data elsewhere.


6. International transfers

Incremenza is based in the United States. Customer Data is stored on servers in the United States. Product usage analytics are stored in the European Union.

If you use the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your own country.

For personal data transferred from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission, together with the corresponding UK and Swiss mechanisms. These are contained in our Data Processing Addendum, which is published and takes effect automatically with no signature required. If your organization needs a countersigned copy, write to [email protected].


7. How we protect information

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle. Our Security page describes these in detail. In summary:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Connection tokens for integrations are encrypted at rest
  • Passwords are hashed and never stored in a recoverable form
  • Multi-factor authentication is required for every user. Administrators and managers must use a passkey, which is phishing-resistant
  • Data is strictly isolated by organization at the database query level
  • Backups are encrypted at rest, with an additional independently maintained backup for redundancy
  • Error monitoring automatically removes tokens, credentials, and payment data before transmission

Staff access. Authorized Incremenza staff may access your account for support and quality assurance. Every such access is logged with the staff member's identity, the account accessed, and the time and duration.

Security incidents. If a breach affects your personal information, we will notify you without undue delay and within 48 hours of becoming aware of it.

No system is completely secure. You are responsible for keeping your credentials confidential and for managing access within your own organization.


8. Automated features and machine learning

Some features of Incremenza use machine learning models operated by third parties to classify transactions, produce summaries, and generate guidance.

Which providers. Google (Gemini) is the primary provider. Anthropic (Claude) is used as a standby when the primary is unavailable. Both are listed on our sub-processor page.

Your data is not used to train their models. We use paid enterprise tiers under agreements that prohibit training on customer data. Neither provider retains your data beyond the duration of the request.

What we send, and what we do not. Before sending anything, we minimize it:

  • Merchant names have personal details such as addresses and phone numbers removed
  • Only aggregated financial summaries are sent for insight generation, not individual transaction records
  • Account numbers, card numbers, and credentials are never sent

Most classification happens without these providers. Transactions are first matched against known merchants, learned patterns, and fuzzy matching. External models are the last step, which substantially reduces how much data leaves our systems.

Output is informational. Automated output can be incomplete or incorrect. It is not financial, tax, accounting, or legal advice, and you should review it before relying on it.

Product usage analytics

We use PostHog to understand how the application is used, so we can improve it. PostHog runs inside the logged-in application only and is not present on our marketing website.

PostHog is hosted on our behalf in the European Union, in Frankfurt, Germany. We collect a user identifier, an account identifier, and records of feature interactions. We do not use PostHog for advertising, retargeting, session recording, or cross-site tracking. Usage records are retained for up to 12 months.


9. Cookies

We use a small number of cookies. Most are strictly necessary for the Service to function, including your session cookie, a security token that protects against cross-site request forgery, and an optional cookie that keeps you signed in.

We also set a referral attribution cookie if you arrive through a partner link, so the correct partner receives credit.

We do not use advertising, retargeting, session recording, or third-party analytics cookies, and we do not use Google Analytics.

Because we set no advertising or third-party tracking cookies, no cookie consent banner is shown. Our Cookie Policy lists every cookie we set by name, along with its purpose and lifetime, and explains how to manage cookies in your browser.

If this changes in the future, for example if we introduce advertising measurement, we will update the Cookie Policy and add consent controls where required before doing so.


10. How long we keep information

Information Retention period
Account and business data, active account Kept for as long as your subscription is active
Account and business data, after cancellation or closure Kept for 90 days to allow reactivation, then permanently deleted automatically
Data from disconnected integrations Kept while your account remains open, so your historical records stay intact. Deleted when your account is closed
Billing, subscription, and tax records Kept for 7 years to meet financial record-keeping requirements
Support communications Kept for 2 years
Product usage analytics Kept for up to 12 months
Security and authentication audit records Kept for 2 years
Backups Deleted data may persist in backups for up to 90 days before being overwritten
Aggregated, anonymized statistics Kept indefinitely. This contains no information that identifies any person or organization

Deletion is automatic. When your account is closed or your subscription ends, a retention clock starts. After 90 days, a scheduled process permanently deletes your business data. You receive advance notice by email before deletion occurs.

One narrow exception. If someone unsubscribes from email sent through the platform, we keep a record of that unsubscribe even after the related contact record is deleted. Without it, a re-imported contact could start receiving email again despite having opted out. The record kept is limited to the email address, the reason, and the date.

Faster deletion on request. You can ask us to delete your data sooner by writing to [email protected]. We complete these requests within 30 days.


11. Your rights and choices

11.1 Access and portability

Admins can export the company's data at any time from Settings, under "Export company data." The export is a single download containing your transactions, customers and customer notes, invoices, objectives, key results, initiatives, team member records, and knowledge base content, as structured, commonly used, machine-readable CSV files.

If you need a copy of your own personal information specifically, or you are not an Admin, write to [email protected] and we will provide it.

11.2 Correction

You can update your account details, company profile, and team information directly in the application. If something we hold is inaccurate and you cannot correct it yourself, contact us.

11.3 Deletion

You can close your account from your settings, which starts the deletion process described in Section 10. You can also request deletion by writing to [email protected].

Account closure is permanent and cannot be undone.

11.4 Objection and restriction

You can object to processing based on legitimate interests, and you can ask us to restrict processing in certain circumstances.

11.5 Marketing preferences

Every marketing email includes an unsubscribe link. You can also update your notification preferences in your settings. Service, billing, and security messages continue while your account is active.

11.6 Withdrawing consent

Where we rely on consent, you can withdraw it at any time. This does not affect processing that already happened.

11.7 How to exercise these rights

Write to [email protected]. We respond within 30 days. We may need to verify your identity first, which protects you from someone else making a request in your name.

Exercising these rights is free, and we will not treat you differently for doing so.

If your data is in an account belonging to one of our customers, for example if you are a customer of a business that uses Incremenza, please contact that business directly. They control that data. If you contact us, we will refer you to them and assist them in responding.


12. California privacy rights

If you are a California resident, you have rights under the California Consumer Privacy Act, as amended.

Right to know. Request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclose to.

Right to delete. Request deletion of your personal information, subject to legal exceptions such as our obligation to keep billing records.

Right to correct. Request correction of inaccurate personal information.

Right to opt out of sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. There is nothing to opt out of. We do not run advertising or retargeting technology on our sites or in our product. If that ever changes, we will update this policy and provide an opt-out mechanism before the change takes effect.

Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right.

Right to non-discrimination. We will not deny service, charge different prices, or provide a different level of service because you exercised a privacy right.

To exercise these rights, contact [email protected]. You may use an authorized agent, in which case we will ask for proof of their authority.

Categories collected in the last 12 months: identifiers, commercial information, internet activity information, professional or employment information, and financial account information obtained through connected services. We collect these for the business purposes described in Section 3, and we disclose them only to the service providers listed on our sub-processor page.


13. European, UK, and Swiss privacy rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 11, which correspond to the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR and the UK GDPR.

You also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

Our GDPR Compliance page explains our approach in more detail. For a signed Data Processing Agreement, contact [email protected].


14. Children's privacy

Incremenza is a business product and is not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn that we have, we will delete it promptly. If you believe a child has provided us information, contact [email protected].


15. Changes to this policy

We may update this policy to reflect changes in our practices, our technology, or the law.

For material changes, we will give at least 30 days' notice by email to account administrators, by notice within the application, or both, before the change takes effect.

For minor changes, such as clarifications or corrections, we will update the "Last Updated" date at the top of this page.

We encourage you to review this policy periodically. Continued use of the Service after a change takes effect means you accept the updated policy.


16. Contact us

Incremenza LLC

2108 N ST STE N Sacramento, CA 95816 United States

We aim to respond to privacy inquiries within 5 business days, and to formal requests within 30 days.


This Privacy Policy was last updated on August 21, 2026. It is effective immediately for new customers and 30 days after posting for existing customers.