Overview

This Privacy Policy explains how TallyArk handles personal data when visitors use the public website, create an account, use the invoicing workspace, access a client portal, contact support, or receive invoice-related emails.

TallyArk is business software. The service may process information about account users, organizations, clients, invoice recipients, portal users, payment records, communication logs, support messages, and technical activity needed to operate the platform.

Data controller and processor roles

For most data entered into an organization workspace, the organization decides what data is added and why. In that situation, the organization is normally the controller and TallyArk provides the software service as a processor.

For account registration, public website activity, support requests, security monitoring, billing administration, and platform operations, TallyArk may act as an independent controller.

Information we collect

Account data may include name, email address, password authentication data, email verification status, organization membership, role, preferences, and sign-in activity.

Workspace data may include organization settings, business profiles, clients, invoices, quotations, line items, payment schedules, payment records, bank-transfer details, terms templates, portal shares, comments, document history, and generated PDFs.

Communication data may include contact form messages, support requests, invoice and quotation email delivery records, verification emails, notification preferences, and related metadata.

Technical and security data may include IP-derived request information, browser or device details, API activity, rate-limiting signals, audit logs, error logs, and approximate usage patterns.

When card payment features are used, TallyArk stores provider references needed to connect invoices to payment activity. Full card numbers and card security codes are handled by the payment provider and are not stored by TallyArk.

How we use information

We use information to provide the service, including authentication, organization management, invoice and quotation creation, PDF generation, email delivery, client portal sharing, payment recording, dashboards, reporting, and support.

We use operational information to protect accounts, enforce permissions, prevent abuse, investigate errors, maintain audit history, improve reliability, and meet legal or accounting obligations.

We may use contact details to respond to enquiries, service messages, security notices, and product-related support requests. Marketing messages should only be sent where permitted by law and with appropriate unsubscribe controls.

Legal bases

Where data protection law requires a legal basis, TallyArk may process data because it is needed to provide the service, because there is a legitimate interest in operating and securing the platform, because the user or organization has given consent, or because processing is needed to comply with legal obligations.

Examples include using contract necessity for account and workspace features, legitimate interests for security and product reliability, consent for optional cookies or marketing, and legal obligation for tax, accounting, fraud-prevention, or regulatory records.

Sharing and processors

TallyArk does not sell personal data. Data is shared only where needed to operate the service, comply with law, protect the platform, or provide requested functionality.

Typical processors may include hosting providers, database infrastructure, SMTP/email providers, payment providers such as Stripe, DNS providers, analytics or monitoring providers if enabled, backup providers, and support tools configured for production.

Data may also be disclosed where required by law, court order, regulator request, fraud investigation, security incident response, professional advice, business transfer, merger, acquisition, or reorganization.

International transfers

TallyArk may use service providers in different countries depending on production hosting, email, payment, monitoring, and support configuration.

Before a broad public launch, the production deployment should confirm hosting regions, backup regions, payment provider terms, email provider terms, and any cross-border transfer safeguards required for the customers being served.

Retention

Workspace records are retained while an organization account is active, unless deleted by authorized users or removed under an agreed retention process.

Some audit, security, email, payment, tax, accounting, backup, and legal records may be retained for longer where needed to protect the platform, resolve disputes, meet legal obligations, or preserve business records.

Deleted records may remain in backups for a limited period until backup rotation removes them.

Your rights and choices

Users can update account profile details, notification preferences, organization settings, clients, invoices, payment records, and other workspace records through the app, subject to role permissions.

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, objection to processing, withdrawal of consent, or to complain to a data protection authority.

To request a privacy action, contact TallyArk with enough information to identify the relevant account, organization, and request. Some requests may need to be handled by the organization that controls the workspace data.

Security

TallyArk uses organization-scoped access, role permissions, httpOnly authentication cookies, email verification, server-side validation, rate limiting, and audit logs to reduce common risks.

No internet service can be guaranteed completely secure. Users should use strong passwords, protect admin accounts, and avoid entering unnecessary sensitive information into invoice descriptions or comments.

Children and age

TallyArk is intended for business users and is not directed to children. Users should not create an account unless they are legally able to enter into or use a business software service in their location.

If you believe a child has provided personal data to TallyArk, contact us so the issue can be reviewed.

Updates and contact

This policy may be updated as the product, providers, laws, or production configuration changes. Material changes should be communicated through the website, app, or email where appropriate.

Questions about privacy or data handling can be sent through the public contact page.

Questions about these terms or how TallyArk handles data? Contact us.