EFFECTIVE ON PRODUCTION ACTIVATION · VERSION 1
Privacy & data use
The service and the data we use
Opening Ledger provides sourced commercial-kitchen opening and operator-change research to kitchen-exhaust cleaning businesses. Account records include your business name, work email, password hash, service territories, delivery preferences and billing identifiers. We process public business records and permitted business-source evidence to produce research. Passwords are hashed; payment-card details are handled by Stripe, not stored by Opening Ledger.
Private customer records
Exclusions, uploaded existing-customer names or addresses, annotations and feedback stay within your organization. We use them to filter your research and improve your service. They are not sold to other customers or repurposed into our acquisition lists. The optional exclusion CSV is parsed for preview in your browser; only the confirmed entries are submitted. Downloads of account records and customer briefs require an authenticated account.
Public business research
We retain limited evidence, source URLs, dates, event classifications, verification decisions and brief revisions. A public business contact is not proof of marketing consent, buying intent or an individual’s role. We do not contact restaurants on a customer’s behalf. Where source terms permit, public evidence may inform more than one customer’s brief; private customer notes are never shared.
Service providers
The web application runs on Netlify, with PostgreSQL and background work on Render when configured. AWS SES, S3 and SNS provide service email and private storage. Stripe processes payments and hosted billing. Exa retrieves permitted public sources; OpenAI assists with structured evidence extraction under deterministic validation. The separate central outreach workspace uses its own scoped SuperSend and Hunter accounts for our business acquisition. Only the minimum sample and customer-status information crosses that integration. Optional Sentry error reporting removes bodies, credentials and signed URLs. Providers may process information in the United States under their own contractual obligations.
Email and cookies
A first-party session cookie is necessary to sign in. This release does not enable advertising trackers or email-open tracking. We distinguish message submission from recipient-server acceptance; neither proves the person read the message. Account, password, explicitly requested sample and paid service emails use the service channel. Commercial sequence opt-outs are handled in the central outreach workspace and are not bypassed by another sender.
Retention and deletion
Delivered briefs remain accessible for up to twelve months after the last paid term, subject to source rights. Account exports are generated on request after sign-in. Private exclusions are removed thirty days after the last paid term; a service reminder links to the export controls. Unconverted sample context is removed after thirty days. Raw inbound email is limited to thirty days; attachments remain quarantined and are not redistributed. Operational event bodies are minimized after ninety days. Necessary billing and transaction records are retained under the business’s configured accounting and dispute policy. Minimal recipient suppression identifiers may be retained to honor opt-outs. Backups expire on their configured retention schedule and are not used for routine processing after a deletion request.
Your controls and requests
You can edit preferences, remove exclusions, export account records and request deletion in account settings. A deletion request stops future research while active billing and legal retention are reconciled. We verify account authority before releasing or deleting data. If a public business fact is wrong, send the brief ID and a correction source through support. We preserve correction relationships so recipients can understand changes.
Security and contact
Customer records are scoped to the authenticated organization. Provider credentials are stored server-side, encrypted where persisted, and never returned to the settings page. We use short-lived file authorization and signed callback verification. No system is risk-free. Contact the configured privacy address below or use the support form. Material policy changes will be dated and communicated to affected account holders.
Service provider & contact
Jolli Apps
388 Santana Row, San Jose, CA 95128, United States
admin@jolliapps.com