Privacy Policy
Last updated July 7, 2026
This Privacy Policy explains how Pertally (“Pertally,” “we,” “us”), a product of Lash Digital Solutions LLC, collects, uses, discloses, and safeguards information when you visit our websites and use our project-accounting and billing application (the “Service”).
Pertally is a business-to-business service. Firms that use Pertally (each, a “Customer”) control the business data they put into their workspace and act as the controller of that data; Pertally acts as a processorhandling it on the Customer's instructions. For questions about data a particular firm holds about you, contact that firm.
1. Information we collect
We collect the following categories of information:
- Account & profile data.Name, work email, hashed password, role, job title, and the firm/workspace you belong to. Optional security data such as two-factor settings and recovery codes. If your firm enables single sign-on, we process the identity your firm's provider sends us to sign you in.
- Workspace business data (Customer Data).Information firms enter to run the Service — clients and contacts, vendors and bills, projects, phases, time entries, expenses, invoices and payments, ledger and financial records, bank-account details used for reconciliation (such as the institution name and a masked account number), compensation and payroll inputs, and similar records. This may include personal data about a firm's employees, vendors, and its own clients, which the firm provides and controls.
- Files and attachments.Documents you upload to a workspace (for example, receipts, contracts, or files attached to a project, invoice, client, or expense) are stored in our cloud file storage. You control what you upload; don't upload anything you don't have the right to store.
- Subscription & payment data.When your firm subscribes to a paid plan, payments are processed by our payment provider (Stripe). We do not store full card numbers; we retain limited billing metadata (e.g., plan, seat counts, status, card last four, amounts, and invoice history). If your firm enables payment acceptance to collect invoice payments from its own clients, those charges run on the firm's own Stripe account, and we record only the resulting payment in the firm's ledger.
- Developer credentials. If your firm creates API keys or configures outbound webhook endpoints, we store a hashed form of each API key and an encrypted webhook signing secret, plus the endpoint URLs and delivery logs.
- Usage, device & log data. IP address, browser/device type, pages and actions, timestamps, request identifiers, and error diagnostics, used to operate, secure, and improve the Service.
- Cookies. We use strictly-necessary cookies to keep you signed in — an HTTP-only refresh/session cookie, plus a small non-sensitive flag cookie that records only whether a session likely exists (so a signed-out page load skips unnecessary auth requests). We do not use third-party advertising or cross-site-tracking cookies.
2. How we use information
- Provide, operate, maintain, and improve the Service.
- Authenticate users and protect accounts (including 2FA, single sign-on, and lockout).
- Bill and administer subscriptions, trials, and any add-ons.
- Send transactional messages — email confirmation, password reset, team invitations, invoices, and payment reminders the firm chooses to send.
- Provide support and respond to requests.
- Monitor performance, debug errors, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
Where required by law, our bases for processing include performance of a contract, our legitimate interests in operating and securing the Service, your consent, and compliance with legal obligations.
3. Our service providers
We do not sell personal information. To operate the Service we use a small set of service providers (“subprocessors”) bound to protect the information they handle on our behalf:
- Amazon Web Services — cloud hosting, database (RDS), file storage (S3), and secrets management (United States).
- Vercel — hosting and delivery of the web frontend.
- Resend — transactional email delivery.
- Anthropic — AI features (see “AI features” below).
- Sentry — error monitoring and performance diagnostics.
- Stripe — subscription billing and, where a firm enables it, payment acceptance.
We may also disclose information to comply with law, enforce agreements, protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).
4. Third-party connections you enable
Some optional features let a firm connect Pertally to services the firm already uses. These connections are turned on by the firm, and they send the firm's data to the firm's own accounts at those providers, at the firm's direction. Your use of each provider is governed by that provider's own terms and privacy policy, and the firm is responsible for the connection.
- QuickBooks Online (Intuit)— when connected, we push the firm's customers, invoices, credits, and payments to the firm's QuickBooks company so its books stay current.
- Gusto— when connected, we push the firm's approved employee time (matched to employees by email) to the firm's Gusto company for payroll.
- Plaid— when connected, we use Plaid to import the firm's bank transactions for reconciliation. Bank credentials are entered with Plaid, not stored by us.
- Single sign-on (SSO)— when a firm configures its identity provider (for example, Okta, Microsoft Entra, or Google Workspace), that provider authenticates the firm's users into Pertally.
- API keys & webhooks— a firm may issue API keys that grant programmatic access to its own workspace data, and configure webhook endpoints that we send the firm's event data to. The firm controls who holds its keys and where its webhooks point.
5. AI features
Some optional features use Anthropic's models to generate suggestions and drafts (for example, summarizing field memos or drafting an invoice cover note). When you use one, the relevant text from your workspace is sent to Anthropic to produce the result. This data is processed only to provide the feature and is not used to train the models. AI output is a suggestion — it is never applied or sent on your behalf without your action, and you should review it.
6. Data retention
We retain information for as long as your account/workspace is active and as needed to provide the Service, comply with legal, tax, and accounting obligations, resolve disputes, and enforce agreements. When a workspace is closed, we delete or de-identify Customer Data within a reasonable period, except where retention is required by law.
7. Security
We apply layered safeguards, including:
- Encryption in transit (TLS) and at rest for the database and file storage.
- Strict per-tenant isolation — every record is scoped to its workspace, enforced at the application layer and by database row-level security.
- Hashed passwords, optional two-factor authentication, single-use rotating sessions, and account lockout.
- Encryption of sensitive connected-service credentials and signing secrets with a managed key.
- Least-privilege access, secrets stored in a managed vault, and continuous error and security monitoring.
No method of transmission or storage is perfectly secure, but we work to protect your information and continually improve our controls.
8. International data transfers
Pertally is operated from, and stores data in, the United States. If you access the Service from outside the United States, you understand your information is processed in the United States, which may have different data-protection laws than your country.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, or object to or restrict processing of your personal data. To exercise rights, contact us at the address below. Because much of the information in the Service is Customer Data controlled by your firm, we may direct your request to that firm or act on its instructions. We will not discriminate against you for exercising your rights.
10. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date and, where appropriate, by additional notice. Your continued use of the Service after changes take effect constitutes acceptance.
12. Contact us
Questions or requests? Email privacy@pertally.com or hello@pertally.com. Pertally is a product of Lash Digital Solutions LLC.