Effective: 26 July 2026 · Last updated: 26 July 2026
Lavola (“Lavola”, “we”, “us”, or “our”) provides simple accounting software designed for sole traders, small businesses, and market vendors in Fiji.
This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our website (lavola.io), web app, and related services (the “Service”). We are committed to protecting your privacy under the laws of the Republic of Fiji. Data lives primarily on your device (local-first). Optional cloud backup uses Supabase (user-scoped rows with Row Level Security). We use Vercel for hosting, Resend for transactional email when configured, and Paddle for payments when enabled.
We collect:
We do not buy or scrape third-party marketing lists.
Lavola is local-first. Your primary books are stored in your browser (or installed PWA) on your device. Anyone with access to that device and browser profile can open the app data. Protect your device with a lock screen and avoid shared public computers for live client books.
You can export a full JSON backup anytime under Billing & Settings.
If you sign in for cloud backup, we store a snapshot of your account data in Supabase under your user id. Access is controlled by Supabase authentication and Row Level Security so other customers cannot read your row. Infrastructure providers encrypt data at rest and in transit (HTTPS / TLS). This is not end-to-end encryption where only you hold a private key — Lavola and its processors can process snapshots to provide backup and (where you invite them) accountant access.
Restoring from cloud is an explicit action in the app (not a silent overwrite). Local data remains the day-to-day source of truth unless you choose to restore.
If you invite an accountant, they may access your books according to the access level you choose (limited or full) and the technical controls in the Service. You can limit or remove access in People. Shared access is intended for trusted professionals you invite.
We use these providers (their policies also apply):
We only share what is needed to run those services. We do not sell your data.
We use browser storage needed for the app (session, preferences, local books). We do not use third-party advertising cookies. Optional analytics, if ever added, will be described here and controllable where required.
You can:
Contact: info@lavola.io.
We use HTTPS, security headers, authenticated APIs, and database access policies. No system is 100% secure. During early access, export regularly. See our internal security checklist for engineering practices; formal certifications (e.g. ISO 27001 / SOC 2) are not claimed.
The Service is not intended for individuals under 18.
If we become aware of a security incident affecting your personal data we control, we will take reasonable steps to investigate and, where appropriate and required, notify affected users and authorities. Report concerns to info@lavola.io.
Lavola is in early access. Features and providers may evolve. We recommend regular exports and careful testing before relying on the Service for sole critical records without a backup.
We may update this policy; the effective date above will change. Questions: info@lavola.io.
Governed by the laws of the Republic of Fiji.