Privacy Policy

Effective: 26 July 2026 · Last updated: 26 July 2026

Lavola (“Lavola”, “we”, “us”, or “our”) provides simple accounting software designed for sole traders, small businesses, and market vendors in Fiji.

This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our website (lavola.io), web app, and related services (the “Service”). We are committed to protecting your privacy under the laws of the Republic of Fiji. Data lives primarily on your device (local-first). Optional cloud backup uses Supabase (user-scoped rows with Row Level Security). We use Vercel for hosting, Resend for transactional email when configured, and Paddle for payments when enabled.

1. Information We Collect

We collect:

  • Business details you enter (name, TIN, address, contact info)
  • Financial records you create (invoices, expenses, bank transactions, payroll, inventory, etc.)
  • Login details (email/password via Supabase authentication), when you use cloud features
  • Technical data needed for the Service to run (e.g. session tokens, device id for sync conflict avoidance)
  • Messages you send to support (e.g. info@lavola.io)

We do not buy or scrape third-party marketing lists.

2. Local-first storage

Lavola is local-first. Your primary books are stored in your browser (or installed PWA) on your device. Anyone with access to that device and browser profile can open the app data. Protect your device with a lock screen and avoid shared public computers for live client books.

You can export a full JSON backup anytime under Billing & Settings.

3. Optional cloud backup

If you sign in for cloud backup, we store a snapshot of your account data in Supabase under your user id. Access is controlled by Supabase authentication and Row Level Security so other customers cannot read your row. Infrastructure providers encrypt data at rest and in transit (HTTPS / TLS). This is not end-to-end encryption where only you hold a private key — Lavola and its processors can process snapshots to provide backup and (where you invite them) accountant access.

Restoring from cloud is an explicit action in the app (not a silent overwrite). Local data remains the day-to-day source of truth unless you choose to restore.

4. Accountants and sharing

If you invite an accountant, they may access your books according to the access level you choose (limited or full) and the technical controls in the Service. You can limit or remove access in People. Shared access is intended for trusted professionals you invite.

5. Third-party providers

We use these providers (their policies also apply):

We only share what is needed to run those services. We do not sell your data.

6. Cookies and local storage

We use browser storage needed for the app (session, preferences, local books). We do not use third-party advertising cookies. Optional analytics, if ever added, will be described here and controllable where required.

7. Retention and deletion

  • On your device: data remains until you clear site data, uninstall the PWA, or use reset/export flows in the app.
  • Cloud snapshots: kept while your account exists so you can restore. Request deletion by emailing us; we will delete or anonymise cloud rows we control within a reasonable period (typically within 30 days), subject to legal holds.
  • Support email: may be retained as needed to handle your request and for basic operational records.

8. Your rights

You can:

  • Export your data (Billing → export JSON)
  • Correct information in the app
  • Stop using cloud backup (sign out / stop syncing)
  • Request account/cloud deletion via email

Contact: info@lavola.io.

9. Security

We use HTTPS, security headers, authenticated APIs, and database access policies. No system is 100% secure. During early access, export regularly. See our internal security checklist for engineering practices; formal certifications (e.g. ISO 27001 / SOC 2) are not claimed.

10. Children

The Service is not intended for individuals under 18.

11. Incidents

If we become aware of a security incident affecting your personal data we control, we will take reasonable steps to investigate and, where appropriate and required, notify affected users and authorities. Report concerns to info@lavola.io.

12. Early access

Lavola is in early access. Features and providers may evolve. We recommend regular exports and careful testing before relying on the Service for sole critical records without a backup.

13. Changes & contact

We may update this policy; the effective date above will change. Questions: info@lavola.io.

Governed by the laws of the Republic of Fiji.

Last updated: 16 June 2026 • lavola.io