Privacy Policy
Last updated: July 28, 2026
Who we are
Vaulted OS is the secure client portal of Endless Winning LLC, a Florida limited liability company that provides bookkeeping services.
11124 Great Neck Road, Riverview, FL 33578
Questions about this policy: privacy@vaultedos.com
Our role
Endless Winning is a bookkeeping firm, and Vaulted OS is the portal we use to do your books. You engage us for bookkeeping services; Vaulted OS is how we deliver them and how you see the results.
That means we are directly responsible for the information described in this policy. We decide what is collected and how it is used, in order to perform the bookkeeping services set out in your engagement letter. There is no other company standing between you and us — if you have a question or a request about your information, it comes to us.
Information we collect
Information you or your bookkeeper provides
- Contact and identity details — name, email address, phone number, and business contact details.
- Postal addresses — for you, your business, and your customers where you record them.
- Notes and messages — free-text notes and message content created in the portal.
- Documents you upload — bank statements, receipts, and other financial documents, including everything printed on them. See Documents and automated processing below.
- Government-issued identifiers — an optional feature that is currently switched off. The portal is capable of storing taxpayer identification numbers (SSN, ITIN, IRS Identity Protection PIN) and business EINs. This capability is disabled by default and no such identifier is stored in our systems. If it is ever enabled, those values are encrypted, readable only through a restricted database function, and every access is recorded.
Information from your bank, through Plaid
See Bank account connections below. In summary: transactions, balances, account names and last-four digits, and location information about individual purchases.
Information we generate or receive automatically
- Transaction records — including the original, unmodified description recorded by your bank, a merchant category code, and a personal-finance category.
- Technical records — when documents are accessed, we record the IP address and browser user-agent associated with the request.
- Account and authentication records — sign-in events and session records needed to operate the portal.
Bank account connections
We use Plaid Inc. to connect your bank accounts to Vaulted OS.
We never receive your bank credentials. When you connect an account, you enter your bank username and password directly with Plaid, inside a secure window operated by Plaid. Those credentials are never transmitted to, seen by, or stored on our systems. Plaid's handling of your information is governed by Plaid's End User Privacy Policy (opens in a new tab).
What Plaid provides to us. We request the Transactions product only. Through it we receive:
- Transaction date, amount, and description, including the original unmodified description as recorded by your financial institution
- A merchant category code and a personal-finance category for each transaction
- Location information for individual purchases, which may include street address, city, region, postal code, store number, and latitude and longitude
- Account balances
- Account names, account types, and the last four digits of the account number
- The complete data payload Plaid returns for each transaction, which we retain in full
We do not request identity information, full account or routing numbers, liabilities, investment holdings, or income data from Plaid, although Plaid offers these products.
History. When an account is first connected, we request up to two years (730 days) of transaction history. The amount actually returned depends on your financial institution.
Disconnecting. You may disconnect a linked account at any time. Disconnecting stops Vaulted OS from importing new transactions from that account. Transactions already imported remain in your financial records. To withdraw your financial institution's authorization entirely, you may also manage the connection through Plaid directly or contact your institution.
Documents and automated processing
To read your bank statements and receipts, we send those documents — in full, as complete images or PDFs — to third-party optical character recognition and data-extraction providers. Today those are Google Document AI, Google Gemini, Anthropic, and OpenAI.
This means anything printed on a document you upload is transmitted to those providers, including information on the page that we did not ask for.
We do not send the structured taxpayer identifier or EIN fields described above to these providers. But that protection applies to the fields, not to the page: if an identifier is printed on a statement or receipt you upload, it is part of the image we transmit.
We also send merchant name and description text (not amounts, not account details) to Perplexity to help identify unfamiliar merchants.
Automated categorization suggests how transactions should be classified. These suggestions are reviewed as part of the bookkeeping work performed under your engagement letter. These tools do not make decisions with legal or similarly significant effects about you.
Text-message receipts
If enabled for your account, you can send receipt photos to Vaulted OS by text message, handled by Twilio. We receive your phone number, the message, and any attached images.
The channel replies to you — for example, confirming a receipt was received. These are service messages about your own account; we do not send marketing or promotional text messages. Using the text channel is optional and is not a condition of using Vaulted OS or of engaging us for bookkeeping.
Message frequency varies with how often you send receipts. Standard message and data rates apply. Reply STOP to opt out or HELP for help.
We do not share mobile information, text-message opt-in data, or messaging consent with any third party or affiliate for marketing or promotional purposes. Twilio receives your phone number and message content solely to carry the messages on our behalf, and is not permitted to use them for its own marketing.
Who we share information with
We do not sell your personal information, and we do not share it for advertising.
We share information with service providers who help us operate. Here is each one, and what it receives:
| Provider | What it receives |
|---|---|
| Supabase | Database, authentication, and file storage — all customer data |
| Vercel | Application hosting — all application traffic and server logs |
| Google Cloud (Run, Tasks, Secret Manager) | Job payloads referencing tenant identifiers; no customer data in payloads |
| Plaid | Bank connectivity — connection and account identifiers |
| Google Document AI | OCR — full statement PDFs and receipt images |
| Google Gemini | OCR and extraction — statement page images, receipt images |
| Anthropic | Extraction and categorization — statement text and images, transaction descriptions and amounts, receipt content |
| OpenAI | Alternative receipt extraction — receipt images |
| Perplexity | Merchant identification — merchant name and description text only |
| SendGrid | Email delivery — recipient email addresses, names, invoice contents |
| Twilio | Receipt messaging — phone numbers, receipt images |
| Slack | Internal failure alerting — alert text and connection/entity identifiers |
| Airtable | A one-time historical data import — client financial records |
| Sentry | Error diagnostics — technical error data |
| Ignition | Proposals and billing — client name and email address |
| Google Analytics | Public marketing website visits only — no customer data |
| Meta | Public marketing website visits only — no customer data |
| Public marketing website visits only — no customer data |
Text-message opt-in data is excluded from all of the above. Every category in this section excludes mobile information, text-message originator opt-in data, and messaging consent. That information is never shared with any third party or affiliate for marketing or promotional purposes. Twilio appears above only as the carrier of the messages themselves, acting on our behalf.
Our own personnel. A small number of authorized personnel may access your information as necessary to operate, support, and troubleshoot the portal. Access is governed by role-based permissions enforced by the platform.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger or sale of the business.
Cookies and tracking
We use no analytics, tracking, session-recording, or advertising technology inside the Vaulted OS portal. Once you sign in, there are no marketing cookies, no advertising pixels, and no third-party trackers on any page where your financial information appears.
The only cookies we set in the portal are first-party authentication cookies required to keep you signed in. They are set httpOnly and SameSite=Lax, and Secure in production. These are strictly necessary to provide the service.
Our public website
Our public marketing website at vaultedos.com is excluded from the above. On that site only, we use:
| Technology | Purpose |
|---|---|
| Google Analytics | Understanding which pages visitors read |
| Meta pixel | Measuring and targeting our advertising |
| LinkedIn Insight Tag | Measuring and targeting our advertising |
These collect standard web-visit information — pages viewed, approximate location derived from IP address, browser and device type, and the site you arrived from.
What these never receive:
- No customer or financial information of any kind. These technologies are not present on any signed-in page, so they cannot observe your accounts, transactions, documents, or balances.
- No mobile information, text-message opt-in data, or messaging consent. That information is excluded here exactly as it is excluded everywhere else in this policy, and is never shared with any third party or affiliate for marketing or promotional purposes.
- No personal information sold. We do not sell personal information, and nothing in this section changes that.
If you visit our public website but never create an account, the information above is all we hold about you.
How we protect information
- Encryption in transit across the service, with HTTP Strict Transport Security.
- Encryption of the most sensitive fields at the column level — taxpayer identifiers, EINs, and bank connection tokens. Decryption is restricted to a privileged database function, and every decryption writes an audit record.
- Row-level security on every database table, with database privileges pinned to a manifest that is enforced automatically on every build.
- Role-based access control enforced on the server, with protections against access across organizations.
- An immutable ledger audit trail. Changes to the accounting ledger are recorded by database triggers, and that record is protected against modification at the database level.
- Bank credentials never traverse our systems.
- Signature verification on all inbound integrations.
No system is perfectly secure, and we cannot guarantee absolute security.
How long we keep information
We retain your information for the life of your account. We do not currently operate automated deletion, and we do not delete information on a fixed schedule.
Some short-lived technical items expire automatically — sign-in tokens, password-reset and magic links, and time-limited file access links all expire within an hour or less.
If you want information removed, contact privacy@vaultedos.com and see the next section.
Your choices and requests
You can contact privacy@vaultedos.com to:
- Ask what information we hold about you
- Correct information that is wrong
- Ask us to delete information
- Get a copy of your information
How this works today, stated plainly: we handle these requests manually. There is no self-service button in the portal that deletes or exports your data. When you contact us, a person carries the request out. We will acknowledge your request and tell you what we can do and by when.
Some financial records are kept for legitimate accounting and tax purposes even when you ask us to remove other information, and your engagement letter may describe records we are expected to retain.
Children
Vaulted OS is a business tool. It is not directed to children, and we do not knowingly collect information from anyone under 13.
Changes to this policy
If we make material changes we will update the date at the top and notify account owners.
Contact
Privacy questions: privacy@vaultedos.com Security matters: security@vaultedos.com Mail: Endless Winning LLC, 11124 Great Neck Road, Riverview, FL 33578