1. Who We Are
IOLTAWatch is a product of Verona Strategic LLC ("Company," "we," "us," or "our"), a Florida limited liability company. This policy applies to the IOLTAWatch web application and all related services accessible at ioltawatch.com.
For privacy inquiries: privacy@ioltawatch.com
2. Data We Collect
| Category | What we collect | Why |
|---|---|---|
| Account data | Name or firm name, email address, state, password (hashed — never stored in plain text) | To create and manage your account |
| Bank data (via Plaid) | Read-only access to your IOLTA trust account balance and transaction history. We store an encrypted Plaid access token. We do not store your bank login credentials. | To run nightly reconciliation and retrieve live bank balance |
| Ledger data | Client matter IDs, client names, and ledger balances you upload via CSV | To perform three-way reconciliation against your bank balance |
| Reconciliation records | Results of each nightly reconciliation run: bank balance, ledger total, sub-ledger sum, status, discrepancy amount, timestamp | To provide your reconciliation history and generate PDF reports |
| Billing data | Subscription status. Payment card details are processed and stored exclusively by Stripe — we do not store card numbers. | To manage your subscription |
| Usage data | Standard web server logs (IP address, browser type, pages visited, timestamps) | To operate and improve the Service |
3. How We Use Your Data
We use the data we collect solely to:
- Provide, operate, and maintain the Service;
- Run nightly reconciliation and send alert emails;
- Generate reconciliation worksheets and PDF reports;
- Process your subscription and communicate with you about your account;
- Respond to support requests;
- Comply with legal obligations.
We do not use your data to train AI models, to target advertising, or for any purpose other than providing the Service.
4. Subprocessors
We rely on the following third-party services to operate IOLTAWatch. Each is bound by its own privacy and security policies.
By connecting your bank account through the Service, you acknowledge that Plaid's collection, use, and storage of your financial data is also governed by the Plaid End User Privacy Policy.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Plaid Technologies, Inc. | Bank account connection and balance retrieval (read-only) | Bank account data, encrypted access token |
| Supabase, Inc. | Database, authentication, and row-level data storage | All application data (account, ledger, reconciliation records) |
| Stripe, Inc. | Payment processing and subscription management | Billing information, subscription status |
| Twilio SendGrid | Transactional email delivery (alerts, welcome email) | Your email address and alert content |
| Railway Corp. | Application hosting and infrastructure | All data processed by the application |
5. Data Security
We implement the following security measures:
- Encryption in transit: All connections use TLS 1.2 or higher.
- Encryption at rest: Plaid access tokens are encrypted at the application layer before storage, and are held in a database that is encrypted at rest with AES-256 disk-level encryption. Tokens are never exposed to the browser or third parties.
- Access controls: Every request to our systems is authenticated and scoped to your firm's account, so each firm's data is isolated and inaccessible to other users.
- Least-privilege access: Bank account connections are read-only. IOLTAWatch can never initiate transactions on your behalf.
- Session security: Authentication cookies are HTTP-only, secure, and scoped to the application domain.
Operational access to customer data by the Company's small operations team occurs only as strictly necessary to run, support, and secure the Service, and is never used for any other purpose. In the event of a legally binding subpoena, court order, or other compulsory legal process, the Company will comply with the requirement; unless prohibited by law or by the terms of the legal process itself, we will provide you with prompt notice and a reasonable opportunity to seek a protective order or move to quash before your records are produced.
6. Data Retention
Active subscription: We retain your reconciliation records, ledger data, and account data for the duration of your active subscription.
On cancellation: Upon cancellation of your subscription, monitoring, reconciliation, and alerting stop at the end of the paid billing period. You may continue to log in to view and export your reconciliation records, or request an export by emailing support@ioltawatch.com. Your reconciliation records are retained for at least six (6) years from the date each record was generated, to support your bar recordkeeping obligations. After that period, we reserve the right to permanently delete records associated with canceled accounts upon at least thirty (30) days notice by email. To request earlier permanent deletion of your data, contact privacy@ioltawatch.com. Deletion requests are fulfilled within 30 days, subject to any legal retention obligations. We strongly recommend exporting all reconciliation PDFs promptly upon cancellation.
Your obligation: Your state bar's rules may require you to retain trust account reconciliation records for a specific period (typically five to seven years). It is your responsibility to export and retain those records. IOLTAWatch's retention practices do not substitute for your professional recordkeeping obligations.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you;
- Correction: Request correction of inaccurate data;
- Deletion: Request deletion of your data (subject to our retention policy and any legal obligations);
- Export: Download your reconciliation reports at any time from your dashboard.
To exercise these rights, email privacy@ioltawatch.com. We will respond within 30 days.
8. Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of the Company's assets, your data may be transferred to the successor entity as part of that transaction, subject to the commitments made in this Privacy Policy. We will notify you by email of any change in ownership, any material change in how your personal data is handled, and any choices available to you regarding your data.
9. California Residents
Regardless of whether the California Consumer Privacy Act's statutory thresholds apply to our business, we honor the following rights for California residents:
- Right to know and access: what personal information we have collected about you and how we have used it, provided in a portable and, to the extent technically feasible, readily usable format;
- Right to correct: inaccurate personal information we hold about you;
- Right to delete: your personal information, subject to our retention policy in Section 6 and any legal obligations;
- Right to non-discrimination: for exercising any of these rights.
We do not sell or share your personal information with third parties for monetary or other valuable consideration, so there is no sale or sharing to opt out of.
To exercise any of these rights, email privacy@ioltawatch.com. To protect your data, we verify each request by matching the email address of the request to the email address associated with your account, and we may require you to reply to a confirmation email to demonstrate control of that inbox. You may also designate an authorized agent to submit a request on your behalf, provided the agent supplies signed written permission from you or a valid power of attorney under California law. We will respond to all verifiable requests within 30 days.
10. Cookies and Do Not Track
We use a single session cookie ("sb_token") to maintain your authenticated session. This cookie is HTTP-only, secure, and expires after seven days. We do not use tracking cookies, analytics cookies, or advertising cookies.
Because we do not track users across third-party websites and do not sell or share personal information, there is nothing for "Do Not Track" or Global Privacy Control browser signals to opt out of, and the Service does not respond to them.
11. Children's Privacy
The Service is intended for licensed attorneys and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email at least 14 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
Privacy questions or requests: privacy@ioltawatch.com
Verona Strategic LLC · Boca Raton, FL