If you run your business on Weafbooks, we hold your customers, your suppliers, your prices, your margins and your payroll. That is not a small thing to hand over. This page says what happens to it, in plain words. The formal version is in the Privacy Policy.
We do not sell your data. Ever.
Not to advertisers, not to data brokers, not to a partner, not in aggregate, not "anonymised". Your business data is not a product we have and it is not used to build one. We make money from subscriptions, which is the whole of it.
We do not use your data to train anything, and we do not look at it to research the market you operate in.
Who can see it
Your people
Access is controlled by role. Permissions apply to every screen and to the API behind it, so a cashier cannot reach the margin report by finding a different URL. You decide who gets what, and you can change it at any time.
Our people
Our staff do not browse customer data. Someone looks at your records when you have asked us for help with them — a wrong figure on a report, an invoice that will not fiscalise — and for that reason only. Administrative actions are logged.
What leaves the system, and when
Two things, both of which you switch on yourself:
- Your revenue authority. If you use EFRIS (Uganda) or MRA (Malawi), the documents you fiscalise are transmitted to that authority using your own credentials. That is the point of the feature. Nothing else is sent, and nothing is sent for documents you do not fiscalise.
- An app you connect. QuickBooks Online, for example, receives nothing until you complete the authorisation, and stops receiving anything the moment you disconnect it.
Beyond that: the companies that host our servers and process subscription payments, acting on our instructions; and a valid legal demand, which we would answer as the law requires.
Where it is kept
On servers we control, reached over HTTPS. The database is mirrored to a second server in a different country, kept in step continuously, and backed up on top of that — so a failed machine costs you time rather than records. Backups exist so that an accidental deletion can be undone, which means a deletion is not instantly irreversible; that is deliberate.
Credentials and integration tokens — your EFRIS keys, your QuickBooks tokens — are encrypted where they are stored, not held as readable text.
Every change has a name on it
Weafbooks keeps an audit trail because it is an accounting system, not because it is a security feature: who created the invoice, who edited it, when, and what it said before. Login history and session details are recorded for the same reason. If you need to answer "who changed this", the system can answer it.
It is your data, and you can leave with it
- Export any report to PDF or Excel, whenever you like, without asking us.
- Ask us for a full copy of your data and we will provide it.
- Ask us to correct or delete personal data, and we will, except where we are required to keep records for tax or legal reasons.
- Close your account and we keep your data for a limited period so you can still ask for that export, then delete it.
What we do not claim
We are not going to tell you we are "bank grade" or wave a certification at you. We do not currently hold ISO 27001 or SOC 2. What we have is described above, honestly, and you are welcome to ask us anything it does not cover.
No system is perfect. If your data is ever affected by a breach, we will tell you.
Found a problem?
If you believe you have found a security flaw, write to [email protected] and describe it. We will not take action against anyone who reports one in good faith and gives us a reasonable chance to fix it before telling anyone else.
Ask us
If anything here is unclear, or your own compliance people need something specific, ask: [email protected].