Privacy Policy
Effective Date: March 10, 2026
FreePNL (“we,” “our,” or “us”) operates the FreePNL platform at freepnl.com (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
By using FreePNL, you agree to the collection and use of information as described in this policy. If you do not agree with this policy, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account information: your email address when you create an account
- Authentication credentials: passwords or magic link tokens
- Payment information: processed securely through Stripe (we do not store your credit card numbers)
- Communications: any messages you send to our support team
1.2 Information from Third-Party Integrations
- Ecommerce transaction data: when you connect your Shopify store via the Rutter API, we access your transaction records including order amounts, dates, product categories, fees, and refunds
- Store metadata: your store name and connection status
1.3 Information Collected Automatically
- Usage data: pages visited, features used, and interaction patterns
- Device information: browser type, operating system, and IP address
- Cookies: we use essential cookies for authentication and session management
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process your ecommerce transaction data to generate P&L statements
- Categorize transactions using AI (Anthropic’s Claude API)
- Process subscription payments through Stripe
- Send transactional emails (account verification, password resets)
- Respond to customer support requests
- Detect and prevent fraud and abuse
- Comply with legal obligations
3. AI Data Processing
FreePNL uses Anthropic’s Claude AI to automatically categorize your ecommerce transactions into standard accounting categories (revenue, cost of goods sold, operating expenses, etc.).
What this means for your data:
- Transaction descriptions and amounts are sent to Anthropic’s Claude API for categorization
- Anthropic retains API request data for up to 30 days for abuse prevention, then deletes it
- Your data is not used to train Anthropic’s AI models
- AI categorizations are automated estimates — you can review and correct them at any time
For more information, see Anthropic’s privacy policy.
4. How We Share Your Information
We do not sell your personal information. We share data only with the following service providers who help us operate the Service:
- Stripe — payment processing
- Supabase — database hosting and authentication
- Vercel — application hosting
- Rutter — ecommerce data integration
- Anthropic — AI transaction categorization
We may also disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of FreePNL, our users, or the public.
5. Data Retention
- Account data: retained while your account is active and for 30 days after deletion
- Transaction and P&L data: retained while your account is active; deleted within 30 days of account deletion upon request
- Payment records: retained as required by law for tax and financial compliance (typically 7 years)
- Server logs: automatically deleted after 90 days
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption in transit (TLS/SSL) and at rest
- Secure authentication with optional two-factor authentication (2FA)
- Role-based access controls for internal systems
- Regular security reviews of our infrastructure
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Your Privacy Rights
7.1 All Users
You may:
- Access your account information at any time through the dashboard
- Update or correct your information in account settings
- Delete your account by contacting support@freepnl.com
- Export your P&L data as PDF
7.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know: request what personal information we collect and how it is used
- Right to Delete: request deletion of your personal information
- Right to Correct: request correction of inaccurate information
- Right to Opt-Out: we do not sell personal information, so this right does not apply
- Right to Non-Discrimination: we will not discriminate against you for exercising your rights
To exercise these rights, contact us at support@freepnl.com. We will respond within 45 days.
8. Cookies
We use strictly necessary cookies for authentication and session management. We do not use advertising or tracking cookies. You can configure your browser to block cookies, but this may prevent you from using certain features of the Service.
9. Children’s Privacy
FreePNL is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
10. International Data Transfers
FreePNL is based in the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the “Effective Date” above. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at support@freepnl.com.