Privacy Policy
Last updated: September 27, 2026
1. Introduction
ERP Sync is operated by Silo Solutions, Inc. ("Silo Solutions," "we," "our," or "us"). ERP Sync is an accounting and financial reporting platform for businesses and the accountants who work with them, available at erpsync.silosinc.com (the "Application"). This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices you have.
The Application is intended for business use. Our users are people who access the Application on behalf of a company, such as owners, controllers, bookkeepers, and outside accountants.
2. Information We Collect
2.1 Account information
When you are invited to or create an account, we collect your name, email address, and password (stored only in hashed form), the companies you can access, and the role and permissions you hold for each.
2.2 Data from connected business systems
When you or your organization connect a business system, such as QuickBooks Online, NetSuite, Microsoft 365, or Google, we receive and store the access tokens needed to connect and the data you authorize us to access. This can include company details, the chart of accounts, customers, vendors, invoices, bills, journal entries, transactions, reports, and documents.
2.3 Bank and card account data (through Plaid)
If you choose to connect a bank or credit card account, we use Plaid Inc. ("Plaid") to do so. Through Plaid we receive:
- The financial institution name, and the name, type, and subtype of each account you select
- The last four digits of the account number (not the full account number)
- Current and available balances
- Transaction history, including dates, amounts, descriptions, merchant names, and categories
We never receive or store your online banking username or password. You enter those only in Plaid's interface. We do not use Plaid to move money or initiate payments.
2.4 Files you upload
Documents you upload, such as statements, invoices, and receipts, and the text we extract from them so they can be searched and matched to your records.
2.5 Usage and security data
We automatically collect information about how the Application is used, such as sign-in times, IP addresses, browser type, and the features you use. We also keep records of security events, such as sign-ins and verification codes issued, to protect your account.
3. How We Use Information
We use the information we collect only to:
- Provide the Application, including syncing, categorizing, and reporting on your financial data
- Import bank and card transactions, match them to your general ledger, reconcile accounts, and produce cash reports
- Authenticate you, including sending one-time verification codes before sensitive actions such as connecting a bank account
- Secure the Application, prevent fraud and abuse, and investigate security incidents
- Provide support and send service-related messages
- Comply with legal obligations
We do not use your financial data for advertising, and we do not use it to build profiles of individuals.
4. How We Share Information
We do not sell your personal information or financial data, and we do not share it for advertising. We share information only as follows:
- Within your organization: with other users your organization has authorized to access the same company in the Application, according to the permissions they hold.
- With systems you direct us to: for example, when you post a categorized transaction to QuickBooks Online or NetSuite.
- With Plaid: to establish and maintain your bank connections, as described in Section 5.
- With service providers that process data on our behalf under contract and only to operate the Application: Supabase (database and hosting), Vercel (application hosting), Resend (email delivery), Cloudflare (bot protection at sign-in), Google Cloud (text extraction from uploaded documents), and OpenAI (indexing document text for search). Our AI service providers process data through their business APIs and do not use it to train their models.
- With AI assistants you connect: if you connect an AI assistant, such as Claude, to the Application, it can access data within your permissions when you ask it to. That provider's own privacy policy governs its handling of that data.
- For legal reasons: when required by law, subpoena, or court order, or to protect the rights, property, or safety of our users or others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy, with notice to you.
5. Plaid
We use Plaid to gather your data from financial institutions. By connecting an account through Plaid, you acknowledge and agree that information about you will be treated in accordance with Plaid's End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy.
You can disconnect a bank account in the Application at any time. You can also review and remove the connections Plaid holds for you at my.plaid.com.
6. Data Security
We protect your information with safeguards that include:
- Encryption of all data in transit using TLS 1.2 or higher
- Encryption of all stored data at rest using AES-256, including backups
- Bank connection tokens that are additionally encrypted within the Application, kept on our servers, and never sent to your browser
- A one-time code emailed to you, which you must enter before connecting a bank account
- Role-based permissions and database-level separation between companies
- Restricted, multi-factor-protected administrative access, reviewed quarterly
- Ongoing vulnerability monitoring and patching of the software we use
No system is completely secure. If we learn of a security incident affecting your information, we will notify you as required by law.
7. Data Retention and Deletion
We keep information only as long as needed to provide the Application or as required by law.
- Bank connections: when you disconnect a bank account, we revoke the connection at Plaid and delete its access token. We delete the bank data we retrieved within 30 days, except for transactions that have become part of your accounting records at your direction (for example, entries posted to your books).
- QuickBooks Online and other connected systems: when you disconnect, we revoke and delete the access tokens and delete cached data within 30 days.
- Your account: when your account is closed, or when you ask us to delete it, we delete your account information within 30 days.
- Backups and legal holds: residual copies in backups are overwritten on their normal schedule. We may retain information longer where the law requires it.
8. Your Rights and Requests
You can ask us to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your information, including the data retrieved from your bank accounts
- Export your information in a portable format
- Disconnect any bank account or connected system at any time
To make a request, email support@silosinc.com from the address on your account. We will verify your identity and respond within 30 days. If your access to the Application is provided by an organization, such as your employer, we may refer your request to that organization and assist it in responding. We will not discriminate against you for exercising these rights.
9. Other Services
The Application connects to services operated by others, including Intuit QuickBooks Online, Oracle NetSuite, Microsoft 365, Google, and Plaid. Your use of those services is governed by their own terms and privacy policies, for example Intuit's at https://www.intuit.com/privacy/.
10. Children's Privacy
The Application is not intended for anyone under 18 years of age. We do not knowingly collect personal information from children.
11. Where Data Is Processed
We store and process data in the United States. If you access the Application from elsewhere, your information will be transferred to and processed in the United States.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and change the "Last updated" date. If we make material changes, we will notify you by email or in the Application before they take effect.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
Silo Solutions, Inc.
Privacy requests and questions: support@silosinc.com
Security concerns: security@silosinc.com