1. Who we are
Simple Books is operated by Adam Elvin trading as Simple Books, a sole trader in England. Adam Elvin is the data controller for personal information used to run accounts, provide the service, handle support, keep the service secure and administer subscriptions.
Adam Elvin trading as Simple BooksLoxley House
Station Street
Nottingham
NG2 3NG
United Kingdom
Email hello@simple-books.co.uk.
Business customers may enter information about their clients, suppliers, workers or others. The customer normally decides why it is recorded and is responsible for using it lawfully. Where Simple Books handles it only to provide the service, Simple Books acts on the customer’s behalf.
2. Information we handle
- Account and contact information: name, business name, email, account identifier, sign-in state, profile details and support messages.
- Business records and files: information in customers, suppliers, invoices, bills, expenses, mileage, projects, budgets, banking records, journals, notes and references, plus uploaded documents and logos.
- Subscription information: Stripe customer and subscription references, status, price and billing mode, and limited payment-method details such as card brand and last four digits. Simple Books does not store full card numbers.
- Technical and usage information: IP address, device and browser details, requested pages, timestamps, error information, account activity and limited feature-usage events.
A bank-statement CSV selected for import is mapped in the browser. That workflow stores confirmed mapped transaction fields, not the raw CSV.
3. Why we use information
- Provide the service and manage subscriptions
- For authentication, records, exports, optional AI features, support and billing. We rely on taking requested pre-contract steps and performing our contract.
- Secure, maintain and improve Simple Books
- For access controls, misuse prevention, fault diagnosis, account activity and operational product analysis. We rely on legitimate interests in operating a safe, reliable business service, where individual rights do not override them.
- Meet legal obligations and protect rights
- Where the law requires it or information is reasonably needed to establish, exercise or defend legal claims.
- Optional consent
- Firebase Analytics browser collection relies on your choice. Consent may be withdrawn at any time without affecting earlier lawful use.
4. AI features
The optional AI Assistant and document scanner send information to OpenAI through authenticated Firebase Functions only when invoked.
- The AI Assistant sends the user’s question and a limited, question-relevant summary. The generated summary removes email-address patterns and web links, but a user may type personal information into a question.
- Document scanning sends the selected supported image or PDF and an extraction instruction. Scanning alone does not save a bill or expense.
Provider requests currently set store: false. This setting is not a promise that suppliers keep no operational or legally required records. Do not submit unnecessary sensitive information. AI output can be wrong and must be checked.
5. Browser storage, analytics and monitoring
Local and session storage hold some account and record caches, preferences, export reminders, consent choices, and session or demo safeguards. Someone with access to the same browser profile may see locally stored information.
Firebase Analytics is disabled unless you select Accept analytics. If accepted, it records restricted product events such as login method, coarse invoice creation details, scan file type and plan, AI-question plan and the start of a Pro checkout. Custom event parameters exclude invoice values, names and free-text descriptions. Firebase may collect standard device, session and request information. You can change or withdraw your choice at any time through Privacy choices; selecting Essential only disables future Firebase Analytics collection without disabling the service.
Separate operational account activity, feature-usage and Demo events are stored through Simple Books and Firebase services to provide, secure and understand use of the product. They are not controlled by the browser analytics choice.
Sentry provides production error monitoring on approved hosts. The integration removes selected user, request, cookie, query-string and other context. Error and stack information may still contain technical details, so these controls reduce risk but do not make every event anonymous.
6. Who receives information
We use service providers as needed to operate Simple Books:
- Google Firebase for hosting, authentication, database, file storage, Cloud Functions and analytics;
- Stripe for subscription checkout, payments and the billing portal;
- OpenAI for optional AI and document-scanning requests;
- Sentry for production error monitoring; and
- Google-hosted Firebase SDK files and jsDelivr for frontend software.
We may disclose information where law requires it, to protect legal rights or security, or in a business transfer subject to appropriate protections. We do not sell customer business records.
7. International transfers
Some providers may process information outside the UK. Where UK data-protection law requires a safeguard, personal information must be covered by an applicable adequacy regulation, approved contractual protection or another lawful transfer mechanism. The relevant mechanism depends on the provider and processing involved. Ask us for information about the safeguard relevant to your information.
8. Retention, exports and deletion
We keep information only as long as reasonably needed. The period depends on the record, whether the account is open, security and support needs, legal claims, and legal or financial record-keeping duties. We do not apply one fixed period to every category.
Supported JSON, workbook, report and Accountant Pack exports are not complete copies of every service record. They may omit authentication and billing data, administrative records, attachments, logos, parts of payment or settlement history, and generated reports.
The irreversible Account deletion process requires recent reauthentication. It cancels a linked subscription, removes user-uploaded files and Simple Books Firestore data, deletes the Firebase Authentication user, and clears identified browser caches in the completing browser. Provider transaction, security, backup or legal records may remain where required or reasonably necessary.
9. Security
Measures include authenticated Firebase access, owner-based database rules, user-specific file paths, server-side billing controls and restricted production monitoring. No internet service is completely secure or continuously available. Users must protect credentials, devices and exports and report suspected unauthorised access.
10. Your rights and complaints
Depending on the circumstances, UK law may give you rights to be informed, access and correct information, ask for erasure or restriction, object, receive portable information, and withdraw consent. Legal limits may apply and we may verify identity.
Send requests to hello@simple-books.co.uk. If a customer entered your information, contact that business first where it is the controller; we will assist where required.
You may complain through the ICO complaint service. We would appreciate the chance to address your concern first.
11. Changes and contact
We may update this policy for changes to Simple Books or the law. We will post the updated version, change the effective date and give additional notice where appropriate.
