Skip to content
PricingControlsWorkflowInterfaceIntegrations
CentralBookOpen app
CentralBook Legal

Privacy Policy

How CentralBook handles invoice, workspace, vendor, and connected accounting data.

Effective date: July 1, 2026

1. Scope

This Privacy Policy explains how CentralBook collects, uses, shares, and protects information when you use the CentralBook accounts payable service, public vendor request forms, and connected accounting integrations.

This policy applies to information processed by CentralBook. Third-party services such as Xero and QuickBooks process information under their own privacy policies when you use or connect those services.

2. Information We Collect

Account and workspace information, such as names, email addresses, roles, organization names, workspace settings, login records, MFA status, permissions, and audit events.

Accounts payable data, such as invoices, supplier names, contacts, addresses, email addresses, phone numbers, tax details, account codes, tracking categories, divisions, payment amounts, payment dates, approval decisions, notes, attachments, and uploaded documents.

Integration data from connected services, such as Xero and QuickBooks company identifiers, organization metadata, contacts, chart-of-account records, bills, payments, attachments, sync state, webhook events, and OAuth tokens.

Technical and security data, such as IP address, browser user agent, request metadata, session identifiers, error logs, and rate-limit records.

3. How We Use Information

We use information to provide and operate CentralBook, process invoice intake, extract invoice data, route approvals, export bills, sync payment state, send operational notifications, maintain audit history, troubleshoot issues, secure accounts, prevent abuse, and comply with legal obligations.

We do not sell customer data. We do not use Xero API Data, QuickBooks customer data, invoices, attachments, or accounting records to train artificial intelligence or machine learning models.

4. OCR, Automation, and Service Providers

CentralBook may process uploaded invoices and attachments with configured OCR or document-processing providers to extract bill fields. Provider use depends on the workspace configuration.

We may use service providers for hosting, storage, email delivery, monitoring, authentication, security, and document processing. These providers may process information only as needed to provide their services to CentralBook.

5. How We Share Information

We share information with connected services at your direction, such as sending approved bills, payment records, contacts, account coding, and attachments to Xero or QuickBooks after an authorized user connects and uses the integration.

We may share information with workspace administrators and authorized users according to their roles and permissions; with service providers that support CentralBook; and when required by law, legal process, security investigation, or to protect rights and safety.

6. Data Retention and Deletion

CentralBook retains workspace data while the workspace is active and as needed for audit history, security, backup, legal, and operational purposes.

Workspace owners may request export or deletion of workspace data. Some records may remain in backups, audit logs, or records that CentralBook is legally or operationally required to keep.

7. Security

CentralBook uses administrative, technical, and organizational safeguards designed to protect information, including role-based access controls, session protections, CSRF protections, security headers, audit logging, upload validation, and encryption for stored integration secrets where configured.

No system is perfectly secure. You are responsible for using strong passwords, enabling MFA where available, limiting workspace access, and keeping connected accounting-provider accounts secure.

8. International Processing

Information may be processed in the United States and other locations where CentralBook or its service providers operate. If you use CentralBook from another region, you authorize processing in those locations subject to applicable law.

9. Your Choices and Rights

You may update profile or workspace information in CentralBook where the product allows it. You may disconnect accounting integrations from CentralBook or from the provider dashboard.

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection. To exercise privacy rights, contact CentralBook using the email below.

10. Children

CentralBook is a business service and is not intended for children under 13 or for personal, household, or family use.

11. Changes and Contact

We may update this Privacy Policy from time to time by posting a new version with a new effective date.

Privacy questions or requests may be sent to support@craghawk.com.

Terms & ConditionsBack to CentralBook
CentralBook
ControlsWorkflowInterfaceIntegrationsPricingOpen appTerms & ConditionsPrivacy Policy