This page describes what LedgerCopy does. It is a description of practice, not an external validation: no third party has audited it, and nothing here is offered as a certification. What is not claimed is listed at the foot of the page.

Source connection

Access to the source

LedgerCopy connects to one authorised organisation at the source platform and reads from it. You hold the connection, and you end it without us.

What is authorised

LedgerCopy requests read scopes for the object groups in the agreed copy scope. Where the source platform separates read from write, read-only scopes are requested. Where a platform grants a single accounting scope that covers both, the authorisation is wider than what LedgerCopy uses: runs read, and no part of the product creates, edits, voids or deletes anything in QuickBooks Online or Xero. The scope requested for your organisation is listed in writing during trial scoping, before the connection is made.

  • One organisation per connectionA connection authorises the company file or organisation you name, and a run reads that one.
  • No credentials are heldThe connection uses the source platform's own authorisation. LedgerCopy does not ask for, or store, your ledger login.

Revoking access

Access is withdrawn at the source platform, using that platform's own controls for the applications connected to a company or organisation. The authorisation is granted by you at the source and withdrawn by you at the source, so neither route requires contacting LedgerCopy or waiting for a reply. QuickBooks Online and Xero each document where that control sits in their own help centres; LedgerCopy does not restate their instructions here, because it does not control them and they change without notice.

  • Revocation stopsThe next scheduled run and every run after it. A run that cannot authorise against the source is reported as incomplete, not presented as current.
  • Revocation does not stopCopies already made. They stay in independent storage until you request deletion, which is a separate request described in retention and deletion.
  • If the disconnection is permanentSay so at mail at ledgercopy.com and the schedule is stopped. Otherwise runs continue on the agreed cadence and continue to report incomplete.

Storage

Where the copy is held

In storage LedgerCopy operates, separate from the platform the data was read from.

The copy is not held inside your QuickBooks Online or Xero account, and it is not a second file on that platform. The separation is the product: a copy that lives inside the ledger platform shares that platform's access model, its availability and the state of the account it sits in. An independent copy can be read when the account it came from cannot be.

Each connected organisation's copy is identified by the source it was read from, so a dated run report and the record counts it carries always refer to one organisation.

The storage location for your organisation is confirmed in writing during trial scoping, before any run reads production data. LedgerCopy does not offer a data-residency guarantee; a location confirmed in writing is not the same commitment, and the difference is stated in what this page does not claim.

Retention

Retention and deletion

Revoking access at the source stops future runs. Deletion removes copies already made. They are two separate actions, and this is the second one.

How to request
Email mail at ledgercopy.com from an address on the account, naming the organisation to be deleted. A deletion request from an address that is not on the account is not acted on.
What is removed
The copied records and the attachments copied with them, for the organisation you name. State in the request whether the dated run reports should be removed as well or kept as a record of what ran.
Confirmation
We reply to the requesting address when the removal is done and state what was removed.
Retention period
Agreed with the copy scope during trial scoping and recorded in writing. No fixed period is published here, because no single period fits every scope. Copied ledger data is product data; the 24-month periods in the privacy policy apply to website records only.

Access control

Who can reach the data

Access to a stored copy exists to operate LedgerCopy, and for nothing else.

There are three operational reasons to reach a stored copy: running the copy, investigating an exception a run has raised, and answering a question raised from your account.

  • Named individual accountsAccounts that can reach stored copies are individual and named. There is no shared operator login.
  • No route back into your ledgerOperating LedgerCopy does not create a write path into QuickBooks Online or Xero. The connection reads; nothing in the product writes to the source.
  • Not sold, shared or reusedCopied ledger data is not sold, licensed or passed to third parties, and it is not used to train models.

Run operations

How runs are scheduled and monitored

A run is scheduled, dated and reported. An interrupted run stays visible as an interrupted run.

Runs are scheduled per connected organisation, at the cadence agreed during scoping and recorded in writing before the first run. Each run is dated, and it closes with a report stating its source, completion time, supported object groups, record counts and exceptions.

A run that fails or finishes incomplete is recorded as incomplete on its own dated report. It does not replace the last complete run as the current one, and it is not shown as a plain success. An exception stays attached to the run that raised it, and the following run retries the object group.

An interruption is communicated by email to the account address, from mail at ledgercopy.com. The email names the organisation, the run date, what is known about the interruption, and whether the next scheduled run is expected to retry it.

No uptime target, service-level commitment or response-time guarantee is offered, and nothing on this page implies one. What LedgerCopy offers instead is that the state of every run is legible: dated, complete or incomplete, with counts and exceptions attached to the run that produced them.

This website

What this website collects

One form, one record, and no third-party scripts.

ledgercopy.com runs on Cloudflare Workers. The only data it collects is the trial request you submit. There is no account area on this site and nothing to sign in to. A trial request is stored as a lead record in Cloudflare D1 before the confirmation page is shown, and it holds four things.

  • Your work emailUsed to reply about LedgerCopy. There is no mailing list.
  • The source platform, if you choose oneThe optional QuickBooks Online, Xero or not-sure-yet answer on the form.
  • Referring URL and campaign parametersThe page you came from, and any campaign parameters carried in the link you arrived from.
  • Your browser's user-agent stringRecorded with the request as the browser sent it.

A trial request record is kept for 24 months from the last contact and then deleted, and a verified deletion request is actioned within 30 days. That period covers website records. It does not cover copied ledger data, which is agreed per engagement under retention and deletion.

The site loads only Fathom's cookieless aggregate analytics, no advertising pixels, no advertising scripts, no remote fonts and no remote images. Every visual on it is drawn with local CSS. Its own interaction script submits the trial form without reloading the page, and the form works when that script does not run.

Boundary

What this page does not claim

Stated directly, so that none of it is read into the sections above.

  • No SOC 2, ISO 27001, PCI DSS or HIPAA status is held or claimed.
  • No penetration-test report or external security review is published.
  • No compliance attestation of any kind is offered.
  • No data-residency guarantee is offered. The storage location is confirmed in writing during scoping, which is a statement of fact, not a guarantee of where it will remain.
  • No uptime target, service level or response-time guarantee is offered.

If one of these is a requirement you have to satisfy, LedgerCopy is not currently the right fit. Say so in your trial request and we will answer that directly, rather than scoping a copy that cannot meet it.

LedgerCopy trial

Request a trial and scope the copy.

A trial conversation establishes four things: the source platform you use, the ledger objects that matter to you, the cadence you need, and the review or continuity workflow the copy has to fit.

What to have ready

  • Which organisation or company file the copy would cover.
  • Who can authorise a read-only connection at the source platform.
  • Which object groups you check at close.
Source platform (optional)

The trial runs for 14 days. No credit card is required to start it.

We use your email only to reply about LedgerCopy. No mailing list. Read the privacy policy.