TreasuryFlow
Product General Ledger Demo
By role
For firmsFractional CFOs & bookkeepers For CFOsFinance leads at growing companies
By industry
ConstructionJob costing, WIP & bonding LandscapingCrews, seasons & equipment RestaurantsMulti-location, tight margins Property managersTrust accounts & owner draws Multi-entityConsolidated across companies
Pricing Help center
Sign in Start free trial
Sign in Start free trial
Legal

Privacy Policy

Last updated: July 5, 2026 · what changed

TreasuryFlow ("we", "our", "us") is operated by Pantoll Ventures LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

Account Information: When you sign up, we collect your email address and optional full name. We generate a hashed API key for authentication; we never store the raw key.

Financial Data (via Plaid): When you connect a bank account, Plaid transmits transaction data to our servers. We process this data using our privacy-first architecture:

  • Exact transaction amounts are securely stored and delivered to your authenticated Excel ledger for precise cross-bank reconciliation
  • For internal categorization and ML, amounts are converted into privacy-preserving magnitude buckets (Micro, Small, Medium, Large, XLarge)
  • We store merchant names, transaction dates, direction (inflow/outflow), amounts, and magnitude categories
  • We never store bank account numbers or routing numbers
  • Exact amounts never appear in application logs, error reports, or ML training data

Billing Information: Payment processing is handled entirely by Stripe. We store your Stripe customer ID and subscription status. We never see or store your credit card details.

2. How We Use Your Information

  • To provide the TreasuryFlow service: transaction categorization, cash flow forecasting, variance analysis, bank fee analysis, working capital metrics, runway projections, and vendor intelligence
  • To generate AI-powered insights (forecasts, scenario analysis, the treasury assistant, and AR narratives) using Google Gemini. The assistant and these narratives are sent your actual figures (amounts, balances, and merchant or customer names) so they can answer questions about specific transactions. We do not train any TreasuryFlow models on your data. The categorization engine, by contrast, only ever sees magnitude ranges, never exact amounts.
  • To authenticate your API requests via hashed API key lookup
  • To manage your subscription and billing through Stripe
  • To send transactional communications (account creation, billing events)

3. Privacy-First Architecture

TreasuryFlow is built on a privacy-first principle. Your exact transaction amounts are securely stored and delivered only through authenticated API endpoints to your Excel ledger. Our internal systems are designed to minimize exposure:

  • Exact amounts are accessible only via your authenticated API key, never through logs, analytics, or internal tools
  • Internal categorization and ML pipelines operate exclusively on magnitude buckets, not raw amounts
  • Logs contain only request IDs and metadata, never financial data

Where data has been deidentified (for example, amounts reduced to magnitude buckets), we maintain and use it only in deidentified form and never attempt to re-identify it.

4. Third-Party Services

This is the complete list of services that process your data on our behalf, and what each one receives:

  • Plaid: Bank account linking and read-only transaction data. See Plaid's Privacy Policy
  • Stripe: Payment processing. We never see or store your card details. See Stripe's Privacy Policy
  • Google Cloud Platform: Hosting infrastructure: our application servers and encrypted databases run on Google Cloud. See Google Cloud Privacy
  • Google Gemini: AI features. For transaction categorization, Gemini receives transaction descriptions and merchant names with amounts bucketed into magnitude ranges (never exact amounts) and runs deterministically (temperature 0.1). The treasury assistant and narrative features are sent the actual figures described in Section 2 so they can answer questions about specific transactions. We never send account numbers or credentials, and your data is not used to train models. See Google AI Terms
  • Intuit QuickBooks: Optional. If you connect QuickBooks Online, we sync your invoices, bills, and accounting data read-only. See Intuit's Privacy Statement
  • Xero: Optional. If you connect Xero, we sync your accounting data read-only. See Xero's Privacy Notice
  • Square: Optional. If you connect Square, we read your sales and settlement data to reconcile it against your bank deposits. See Square's Privacy Notice
  • Resend: Email delivery: receives your email address and the content of the emails we send you (for example, your morning cash brief). See Resend's Privacy Policy
  • Sentry: Error monitoring: receives technical error reports so we can fix failures. Our logging is designed to exclude financial data (see Section 3). See Sentry's Privacy Policy
  • Google Ads: We use Google Ads conversion tracking and Enhanced Conversions to measure the performance of our advertising. If you sign up or book a demo after clicking one of our ads, we send Google a one-way hashed (SHA-256, irreversible) version of your email address so the conversion can be attributed. We never send Google your financial data, transaction amounts, or bank information. See Google's Privacy Policy; you can opt out of personalized advertising at adssettings.google.com.

5. Data Retention & Deletion

Your data is retained for as long as your account is active. Upon account cancellation, we delete all associated transaction data, Plaid tokens, and profile information within 30 days. You may request immediate deletion by contacting us.

6. Security

We implement industry-standard security measures including:

  • API key authentication with one-way hashing of stored tokens
  • Rate limiting on public endpoints
  • CORS origin restrictions
  • HTTPS-only communication
  • No sensitive data in application logs

7. Your Rights

You have the right to:

  • Access your stored data through your TreasuryFlow account dashboard
  • Request deletion of your account and all associated data
  • Disconnect your bank account at any time

8. Contact

For privacy-related inquiries, contact us at privacy@treasuryflow.ai.

9. Changelog

  • July 5, 2026: Listed every service that processes your data (added Google Cloud Platform, Intuit QuickBooks, Xero, Square, Resend, and Sentry to Section 4) and clarified exactly what data Google Gemini receives for categorization versus the assistant.
  • May 22, 2026: Added the Google Ads conversion tracking and Enhanced Conversions disclosure (one-way hashed email addresses).
  • March 23, 2026: First published version.
The CFO morning brief, weekly.

Cash, runway, and benchmark insights from finance teams running TreasuryFlow.

Start free trial See the product tour
TreasuryFlow

Live cash visibility for $1M–$50M companies and the fractional-CFO firms that serve them.

$99/mo per company · 90-day free trial · Live in 5 minutes Read-only bank access via Plaid
Product
Features AI General Ledger Pricing Product tour For CFOs For firms Excel & Sheets
Industries
Construction Landscaping Restaurants Property managers Multi-entity
Compare
vs Float vs Mercury vs Trovata vs Ramp All comparisons
Company
About Manifesto Help center Status
© 2026 Pantoll Ventures LLC · 35 Miller Ave #1112, Mill Valley, CA 94941 · TreasuryFlow™
Help center Status Contact Security Privacy Terms