Privacy Policy
What we collect, why, where it is kept, and who can see it. Last updated 2 August 2026.
Who we are
Alevate Books is bookkeeping and accounting software operated by UKPACKAGES LIMITED, a company registered in England and Wales, 12 Constance Street, London E16 2DQ, United Kingdom. In this policy “we” means that company and “Alevate” means the software.
Questions, requests or complaints: support@alevatebooks.com.
Our role, and yours
This distinction matters more here than in most software, so we state it plainly.
Most of what Alevate holds is your accounting data, and often your clients’. Where an accountancy firm uses Alevate to keep books for the businesses it serves, that firm decides what goes in, who may see it, and how long it is kept. In data-protection terms the firm is the controller of that data and we are its processor: we hold and process it on the firm’s instructions and for no purpose of our own.
We are the controller only of the information needed to run the service itself — your account, your login, your billing details and our own security records.
What we hold
- Account details — name, email address, the businesses you have access to, and your role within them.
- Accounting records you enter or import — invoices, bills, payments, journal entries, ledgers, stock, payroll figures, and the contact details and tax registration numbers of the customers and suppliers you trade with.
- Documents you capture — photographs and files of receipts, bills and bank slips, and the figures read from them.
- Technical records — sign-in times, IP address and an audit trail of actions taken in your books, which exists so that a change can always be traced to a person.
We do not run advertising or analytics trackers. The mobile app contains no third-party advertising, analytics or tracking software of any kind, and we do not build profiles of you or sell data to anyone, ever.
Camera and photos
The app asks for camera access so you can photograph a bill, and for photo access so you can pick one you have already taken. We use those permissions for nothing else. We do not read your photo library in the background and we only ever receive the specific images you choose to send.
Documents are read by AI
This is the disclosure most worth your attention.
When you scan or upload a document, the image is sent to an artificial-intelligence provider that reads it and proposes the accounting entry. Today those providers are Google (Vertex AI) and Anthropic. That means the contents of that document — including any client names, amounts and tax numbers on it — leave our systems and are processed on theirs.
We use these providers on business terms under which your content is not used to train their models. We send only the document and the information needed to read it. Nothing the AI proposes is ever posted to your books automatically: it produces a draft, and a person approves it.
If you do not want a document read this way, enter the transaction by hand instead — typed entries are never sent to an AI provider.
If you connect a Shopify store
We read your orders so that your sales reach your books. From each order we take three pieces of personal data and no more:
- The customer’s name, so a sale in your ledger can be identified as belonging to a particular order.
- Their phone number, so a cash-on-delivery parcel can be matched to its order and to the courier’s settlement.
- The delivery city — the city alone. Courier charges and COD settlements are reconciled by city.
We do not read or store the street address, the postcode, or the customer’s email address. Shopify order data is never sent to an AI provider.
We read from your shop and never write to it. Alevate cannot change a price, a product, an order or a fulfilment in Shopify — it records what is there.
If one of your customers asks what is held on them or asks to be erased, Shopify passes the request to us and we act on it. Erasing clears the name, phone and city from the affected orders; the transaction itself remains, because it is an accounting record with its own retention obligation, and what is left identifies nobody.
Remove the app and we stop reading immediately, delete the access token and the cached product list, and delete the connection entirely once Shopify confirms the removal. Your books stay — they are yours. The full terms are in our Data Processing Agreement.
Where it is kept, and who else touches it
We use a small number of established suppliers to run the service. They may hold or transmit your data strictly to provide their part of it:
- Neon — the database holding your accounting records
- Cloudflare R2 / Cloudinary — storage for the documents you upload
- Railway and Vercel — hosting for the application
- Google (Vertex AI) and Anthropic — reading scanned documents
- Resend — sending emails such as invitations, password resets and scheduled reports
Data is held on servers in the United States and the United Kingdom. Where data is transferred out of the UK or the EEA we rely on the standard contractual clauses offered by these suppliers.
Beyond those suppliers we share your data with no one. We do not sell it, rent it, or hand it to anyone for marketing. We would disclose it only where the law requires us to, and we would tell you unless we were forbidden from doing so.
Every business is separate
Each business’s books are walled off from every other. Access is by invitation and by role, so a person sees only the businesses they have been added to, and only what their role allows. Reports shared by link expire after seven days and can be revoked at any time.
How long we keep it
Accounting records are kept for as long as your account is active, because that is what a set of books is for — and because tax law in most countries requires records to be retained for several years. Corrections are made by reversal rather than deletion, so the history of a ledger stays intact by design.
If you close your account, tell us and we will delete or return your data, subject to any period we are legally required to retain it. Backups are overwritten on a rolling basis.
Security
Passwords are hashed and never stored in readable form. Traffic is encrypted in transit. On your phone, your session is held in the device’s secure storage. Access is role-based, and actions in your books are recorded in an audit trail.
We do not claim any system is impossible to breach. If a breach affected your data we would tell you, and the relevant regulator, without undue delay.
Your rights
Depending on where you live you may have the right to ask for a copy of your data, to have it corrected or deleted, to object to how we use it, or to have it sent to another provider. Write to support@alevatebooks.com and we will respond within one month.
Deletion has a page of its own: how to delete your account, what is removed, and what we are required to keep.
If the data concerns you but was entered by an accountancy firm using Alevate, that firm decides what happens to it — ask them, and we will support them in answering you. In the UK you may also complain to the Information Commissioner’s Office.
Children
Alevate is business software and is not intended for anyone under 18. We do not knowingly collect data about children.
Changes
If we change this policy we will update the date at the top, and we will tell account holders directly where the change is significant.
UKPACKAGES LIMITED · 12 Constance Street, London E16 2DQ, United Kingdom · support@alevatebooks.com