Legal center

Privacy Notice

How TightLedger collects, uses, shares, protects, and retains personal information.

Effective July 23, 2026Version 2026-07-23
On this page
  1. 1. Who we are and what this notice covers
  2. 2. Information we collect
  3. 3. Sources of information
  4. 4. Why we use information and our legal bases
  5. 5. AI and automated processing
  6. 6. How we disclose information
  7. 7. No sale or behavioral advertising
  8. 8. International transfers
  9. 9. Retention and deletion
  10. 10. Security
  11. 11. Your choices and rights
  12. 12. United States privacy disclosures
  13. 13. Canada
  14. 14. European Union, EEA, and United Kingdom
  15. 15. Cookies and similar technologies
  16. 16. Children
  17. 17. Changes, questions, and complaints

1. Who we are and what this notice covers

Ivorycom LLC, located at 5208 White Chicory Dr, Apollo Beach, FL 33572, United States, currently operates TightLedger. This notice explains how we handle personal information through our websites, applications, account administration, support, marketing, and financial-recovery service.

Ivorycom is a controller for account, website, billing, security, support, and marketing information. When a business customer connects sources or uploads records containing personal data and tells us how to process it, Ivorycom generally acts as that customer’s processor or service provider. The customer’s own privacy notice also applies to that data.

2. Information we collect

  • Account and identity data, such as name, email, organization, role, authentication identifiers, verification status, and security events.
  • Organization and subscription data, such as business details, team membership, policies, plan, billing contacts, invoices, and payment status. Payment-card details are handled by the selected payment provider rather than stored in full by TightLedger.
  • Customer Content, including connected financial, accounting, transaction, vendor, customer, contract, communication, file, and evidence records selected by the customer.
  • Integration data, such as provider, scopes, connection status, source identifiers, synchronization times, and provider responses. Provider credentials and tokens are protected and are not displayed in ordinary product interfaces.
  • Recovery workflow data, including findings, calculations, evidence provenance, approval decisions, actions, disputes, and authoritative outcome matches.
  • Support and communications data, such as messages, attachments, survey responses, and records of consent or unsubscribe requests.
  • Device and usage data, such as IP-derived security context, browser type, device identifiers, timestamps, pages, diagnostic logs, and cookie or storage choices.
  • Derived data, such as risk signals, classifications, summaries, evidence quality, and potential or verified recovery estimates.

3. Sources of information

We receive information directly from you; from an organization administrator or colleague; from connected services you authorize; from identity, email, hosting, security, and payment providers; and automatically when you use TightLedger. Customers may provide information about their employees, contractors, vendors, customers, or other people and are responsible for the required notices and permissions.

4. Why we use information and our legal bases

  • Provide the service and perform our contract: create accounts, connect selected sources, detect and verify findings, support approvals, track outcomes, bill, and provide support.
  • Pursue legitimate interests: secure the service, prevent fraud and abuse, troubleshoot, measure reliability, improve workflows, administer the business, and establish or defend legal claims, balanced against individual rights.
  • Comply with legal obligations: maintain required tax, accounting, consent, security, and transaction records and respond to lawful process.
  • Use consent where required: send optional marketing, use optional cookies or similar technologies, or conduct another activity for which the relevant law requires consent.

5. AI and automated processing

TightLedger uses automated systems to identify patterns, classify records, summarize evidence, and suggest next steps. Material external actions remain subject to the customer’s configured review and approval controls. TightLedger does not make decisions that produce legal or similarly significant effects about individuals on Ivorycom’s own behalf.

We and our AI providers do not use Customer Content to train general-purpose AI models unless the customer gives separate, explicit opt-in consent. We may use deidentified operational metrics only when they cannot reasonably identify a customer or person.

6. How we disclose information

We may disclose information:

  • to the customer organization and its authorized users according to configured roles;
  • to subprocessors that provide hosting, storage, databases, identity, queues, transactional email, payment, security, diagnostics, and support services under contractual safeguards;
  • to a connected provider when the customer directs a request or approved action;
  • to professional advisers, auditors, insurers, and financing or transaction counterparties subject to appropriate confidentiality;
  • to authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish or defend claims; and
  • in a merger, financing, reorganization, or sale, subject to appropriate notice and continued protection.

7. No sale or behavioral advertising

Under the current product model, Ivorycom does not sell personal information for money and does not share personal information for cross-context behavioral advertising or targeted advertising based on activity across unrelated businesses. We do not use Customer Content for third-party advertising. If these practices change, we will update this notice and provide legally required choice mechanisms before the change.

8. International transfers

Ivorycom is based in the United States, and our service providers may process information in the United States and other countries. Those countries may have privacy laws different from the place where information was collected.

For restricted transfers from the EU/EEA, we use an available lawful mechanism, which may include an adequacy decision or the European Commission’s Standard Contractual Clauses with supplementary safeguards. For UK restricted transfers, we may use the UK International Data Transfer Addendum or another approved mechanism. Contact privacy@tightledger.com to request information about applicable safeguards.

9. Retention and deletion

We retain Customer Content while the customer account is active and as directed by the customer. Following termination or a valid deletion request, we delete or anonymize Customer Content within 30 days unless applicable law, an unresolved dispute, security needs, or documented customer instructions require a longer period. Encrypted backups expire within 90 days through normal rotation.

We keep billing, tax, consent, suppression, security, fraud-prevention, and audit records only for documented periods needed for law, dispute resolution, security, and accountability. When exact deletion is not technically feasible in an immutable audit record, we restrict use and retain only what is necessary.

10. Security

We use safeguards designed for the sensitivity of the information, including access controls, encryption in transit, protected secrets, tenant isolation, audit logging, least-privilege service identities, dependency and vulnerability controls, backups, and incident procedures. No security measure eliminates all risk.

Customers are responsible for account security, user access, connected-source permissions, endpoint security, and reviewing high-risk actions.

11. Your choices and rights

Depending on where you live and the context, you may have rights to know or access personal information, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, opt out of certain sharing or targeted advertising, appeal a denied request, and complain to a regulator. We will not unlawfully discriminate against you for exercising a right.

Submit a request to privacy@tightledger.com. We may verify identity and authority before acting. If data is controlled by a TightLedger customer, contact that customer first; we will assist it as required. Authorized agents must provide proof of authority. Legal exceptions may apply.

12. United States privacy disclosures

Residents of US states with applicable comprehensive privacy laws may request access, correction, deletion, portability, and information about processing, and may opt out of sale, targeted advertising, or certain profiling where those rights apply. TightLedger’s current practices do not involve sale or cross-context behavioral advertising.

Florida’s Digital Bill of Rights and other state laws apply only when their statutory scope and thresholds are met. We extend the request channels described above without representing that every statute applies to Ivorycom or every business-use record.

13. Canada

Where PIPEDA or substantially similar provincial law applies, Ivorycom follows accountability, identified purposes, meaningful consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, correction, and challenge principles. Collection, use, and disclosure must remain appropriate in the circumstances.

You may request access to or correction of personal information and challenge our practices through privacy@tightledger.com. You may also complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.

14. European Union, EEA, and United Kingdom

Where EU GDPR or UK GDPR applies, the legal bases described above support our processing. Individuals may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. They may complain to their local EEA supervisory authority or the UK Information Commissioner’s Office.

Ivorycom has not currently designated a data protection officer, EU representative, or UK representative. If applicable law requires an appointment for particular processing, Ivorycom will make the appointment and publish the relevant contact details before that processing begins.

15. Cookies and similar technologies

Our Cookie Notice describes browser storage and similar technologies. Strictly necessary technologies support sessions, security, routing, and consent records. Optional analytics or marketing technologies will not be activated unless the required consent has been obtained.

16. Children

TightLedger is a business service for adults and is not directed to children under 18. We do not knowingly collect personal information directly from children through account registration. Customer Content may incidentally contain information about other people; the customer is responsible for ensuring lawful processing.

17. Changes, questions, and complaints

We may update this notice to reflect changes in law, technology, or our practices. We will identify the version and effective date and provide additional notice when required.

Contact privacy@tightledger.com for questions, rights requests, or complaints. Contractual and DPA questions may be sent to legal@tightledger.com. Postal correspondence may be sent to Ivorycom LLC, 5208 White Chicory Dr, Apollo Beach, FL 33572, United States.