This Privacy Policy explains how Green Ledger (“Green Ledger,” “we,” “us”) collects, uses, shares, and protects personal information when you use the Green Ledger platform, websites, and related services (the “Platform”). It applies to service providers and their team members, to customers using the customer portal, and to visitors of our public pages.
1. Our Role: Platform vs. Service Provider Data
Green Ledger is a multi-tenant platform used by independent landscaping businesses (“Service Providers”). For information those businesses collect about their own customers — names, property addresses, service notes, invoices — the Service Provider is the controller of that data and Green Ledger processes it on the provider’s behalf to deliver the Platform. For account, billing, and usage information about Platform users themselves, Green Ledger is the controller. Each Service Provider’s data is logically separated from other providers’ data.
2. Information We Collect
Information you provide
- Account information — name, email address, phone number, password (stored only as a salted hash), business details for Service Providers (company name, address, service area ZIP codes, website).
- Property and service information — property addresses, lot details, service preferences, quotes, contracts, job notes, and related records.
- Photos and files — property, equipment, and job photos you upload, stored in access-controlled cloud storage.
- Payment information — payments are processed by Stripe. We never store full card numbers or bank credentials; we retain only payment metadata (amounts, dates, status, last-four digits where provided by Stripe).
- Signatures and acceptances — electronic signature events, terms-acceptance timestamps, and verification-code confirmations.
- Support and bug reports — if you submit a bug report, we collect your description, technical context, and an optional screenshot of your current screen that you capture and submit.
Information collected automatically
- Security and audit data — IP address, browser user-agent, and timestamps for security-relevant actions such as sign-ins, password resets, payments, and contract signatures. We keep these records to protect accounts and provide an audit trail.
- Cookies — we use cookies strictly for authentication sessions and platform functionality. We do not use advertising or cross-site tracking cookies.
- Derived location data — property addresses may be geocoded into map coordinates to support scheduling and route planning.
3. How We Use Information
- Operate the Platform: scheduling, quotes, contracts, invoicing, team management.
- Process payments and subscriptions through Stripe.
- Send transactional email — account activation, invoices, receipts, password resets, signature requests, and service notifications.
- Secure the Platform: authentication, rate limiting, audit logging, fraud prevention.
- Provide support and investigate reported issues.
- Comply with legal obligations, including tax and financial record-keeping.
We do not sell personal information, and we do not use your data for third-party advertising.
4. How Information Is Shared
- Within your service relationship — customer information is visible to the Service Provider that serves that customer (and its authorized team members); invoices, quotes, and contracts are visible to both parties to them.
- Lead marketplace — if a Service Provider lists a lead, limited information (city, state, ZIP code, requested services, lot size) is shown to other providers. Full street addresses are never displayed in the marketplace; complete details transfer only to the purchasing provider after purchase.
- Processors — Stripe (payments), cloud infrastructure and storage providers (hosting, file storage), and Microsoft 365 (transactional email delivery). Processors receive only what they need to perform their function.
- Legal — we may disclose information when required by law or to protect the rights, safety, and security of the Platform and its users.
- Business transfers — if Green Ledger is involved in a merger, acquisition, or asset sale, information may transfer subject to this Policy.
5. Data Retention
We retain information for as long as your account is active and as needed for the purposes above. Financial records (invoices, payments, tax line items) are retained as required for accounting and legal compliance even after account closure. Audit and security logs are retained on a rolling basis. When retention is no longer required, data is deleted or de-identified.
6. Security
We protect information with industry-standard measures: encrypted transport (HTTPS), salted password hashing, role-based access control across every portal, tenant isolation, rate limiting on sensitive endpoints, signed time-limited links for private files, and audit logging of security-relevant events. No system is perfectly secure; please use a strong, unique password and notify us of any suspected compromise.
7. Your Choices and Rights
- Access and correction — you can review and update your account information in your portal settings.
- Deletion — you may request deletion of your account through the contact page. Customers of a Service Provider should direct requests about their service records to that provider; we will assist the provider in honoring them. Some records (e.g., financial history) may be retained where the law requires.
- Email — transactional emails (invoices, receipts, password resets) are part of operating the service and are sent as needed.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA) or similar state privacy laws. We honor verified requests to exercise applicable rights and do not discriminate against you for making them.
8. Text Messages (SMS)
With your consent, we and your Service Provider may send you text messages such as appointment confirmations and reminders, crew en-route alerts, schedule changes, invoice and payment notices, one-time verification codes, and other service-related notifications. Message frequency varies based on your service schedule and account activity. Message and data rates may apply.
We do not share, sell, or rent your mobile phone number to third parties or affiliates for their marketing purposes. Your number and text messaging opt-in consent are used only to deliver the messages described above through our messaging provider, which acts solely on our behalf.
You can opt out of text messages at any time by replying STOP to any message, or reply HELP for assistance. Opting out of texts does not affect transactional emails or your service itself. For full details on how consent is collected and managed, see our SMS Program & Opt-In Disclosure.
9. Children
The Platform is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
10. Changes to This Policy
We may update this Policy from time to time; the “Last updated” date above reflects the current version. For material changes we will provide notice through the Platform or by email.
11. Contact
Questions or requests about privacy? Reach us through the contact page.