Privacy Notice
How DeltaLedger handles information.
Effective July 29, 2026
Information we collect
Account information supplied by Google or Microsoft when you sign in, including your name, verified email address, profile image when available, provider account identifier, and authentication/session data.
Workspace information submitted by authorized users, including engineering-change descriptions, BOM and purchase-order data, supplier terms, mappings, exposure calculations, mitigation activity, reports, and audit records.
Technical and security information processed by our hosting providers when the service is used, such as request timestamps, IP address, browser or device information, and error logs.
How we use information
To authenticate users, enforce invitation-only workspace access, provide the requested DeltaLedger workflows, generate reports, maintain evidence and audit history, troubleshoot the service, and protect against unauthorized access.
We do not sell personal information or use workspace data for advertising. We do not use Google or Microsoft identity data for purposes unrelated to authentication, account administration, and service security.
How information is shared
Information is processed by service providers needed to operate DeltaLedger, currently including Vercel for application hosting, Neon for PostgreSQL hosting, and Google or Microsoft for sign-in. Those providers process information under their own terms and privacy commitments.
We may disclose information when required by law, to protect the service or its users, or as part of a business transaction subject to appropriate safeguards. Workspace content is not intentionally disclosed to other DeltaLedger customers.
Retention and deletion
Account, workspace, evidence, and audit information is retained while needed to provide the service, preserve an authorized decision record, meet security obligations, or resolve disputes. Some records are intentionally append-only so prior decisions remain reconstructable.
To request access, correction, or deletion of personal information, contact mail@delta-ledger.com. A workspace administrator may also manage workspace access. We will evaluate requests against applicable obligations and any legitimate need to preserve security or audit records.
Security
DeltaLedger uses invitation-only access, server-side role and workspace checks, read-only demo isolation, encrypted provider connections, and attributed audit records. No system is completely secure, and DeltaLedger has not yet undergone a third-party security audit or obtained a compliance certification.
International processing and children
Our service providers may process information in the United States and other locations where they operate. DeltaLedger is a business service and is not directed to children.
Changes to this notice
We may update this notice as the product, providers, or legal obligations change. Material changes will be reflected on this page with a revised effective date. A customer pilot involving real operational data may also be governed by a separate written data-handling agreement.