Privacy Policy
Last Updated: September 29, 2026
This Privacy Policy describes how Money OS ("we", "us", or "our") collects, uses, and protects your information. Money OS is an enterprise-grade financial command center and agency operating system designed to manage business ledgers, client projects, timesheets, invoices, and payments.
1. Data Minimization & Collection
We process only the data explicitly entered into the platform by authenticated users or authorized team members. Our database schema stores:
- Authentication & Identity Metadata: Usernames, verified email addresses, organization memberships, and role assignments managed through Clerk and our internal database bridge.
- Financial & Operational Records: Bank accounts, core double-entry transaction ledgers, category budgets, recurring transaction rules, client CRM records, project work items, and rate cards.
- Agency & Billing Records: Timesheet logs, timer sessions, bank-linked expense receipts, client markup percentages, GST/HSN tax profiles, and generated invoices.
- Workforce Resource Data: Profiles and cost/billing rates for portal members and billable-only contractors (who participate in project economics without portal accounts).
- Payment & Gateway Data: Razorpay payment link references, transaction statuses, and webhook delivery records. Tenant payment gateway credentials stored in settings are encrypted at rest with AES-256-GCM.
- Support Queries: Sender name, email address, priority level, and ticket descriptions entered through our contact system.
2. System Architecture & Tenant Isolation
Security and data boundaries are enforced directly in our core application and query handlers:
- Strict Tenant Scoping: All database queries require and filter by a verified
tenantIdresolved from the session principal. Cross-tenant queries are blocked with fail-closed security checks. - Referential Integrity Guards: Financial transactions, expenses, and bank accounts are locked to the caller's tenant boundary, preventing orphaning or unauthorized modifications.
- Super Admin Controls: Platform administrators can access diagnostic analytics and support tooling with full audit tracking.
3. Authentication, Cookies & Telemetry
We believe in transparent session management and clean data practices:
- Essential Session Cookies: Secure session cookies set by Clerk and our edge proxy to verify identity, manage organization context, and maintain active logins without exposing credentials to client scripts.
- Product Telemetry: First-party behavioral telemetry (via PostHog and optional Google Analytics) is utilized strictly to understand feature adoption, detect application errors, and measure platform latency.
- No Third-Party Ad Trackers: We never sell user data, deploy cross-site advertising trackers, or share your financial records with marketing networks.
4. Audit & Security Logging
To maintain audit-proof compliance, critical workspace activities (such as member invitations, role changes, expense approvals, ledger edits, and payment reconciliations) generate un-deletable records in an immutable audit trail.
5. Contact Us
For any data protection requests, privacy inquiries, or deletion requests, contact platform operations at support@moneyos.tech.