Privacy
Totter privacy policy.
This policy explains what information Totter collects, how it is used and protected, and the choices you have — including for bank account data you connect through Plaid.
Last updated: July 30, 2026
1. Information we collect
Account information. Name, email address, and sign-in credentials. Authentication is handled by our identity provider, Clerk — Totter does not store passwords for Clerk-managed accounts.
Business information. Details about the businesses you manage in Totter: legal names, entity types, state registrations, addresses, ownership structure, and tax identifiers such as EINs. EINs are encrypted before storage.
Financial account data. When you connect a bank account through Plaid, we receive account details (such as account name, type, and mask), balances, and transactions so we can import activity into your books. Totter never sees or stores your bank username or password — those go directly to Plaid.
Payments, banking, and payroll data. Payment cards and bank instruments are vaulted with Stripe; payroll data, including Social Security numbers, is collected and held by Gusto through provider-hosted flows. Totter stores references to these records, not the sensitive contents. Totter never stores Social Security numbers.
Usage information. Standard technical logs (such as IP address and browser type) used for security and reliability.
2. How we use information
We use your information to operate Totter: importing and categorizing transactions, keeping your books, generating reports and documents, running the products you enable (such as invoicing, payroll, banking, or formation), providing support, securing the service, and meeting legal obligations. We do not sell your personal information, and we do not use your financial data for advertising.
3. Plaid
Totter uses Plaid to connect your financial accounts. By using the service, you grant Totter and Plaid the right to process information about your financial accounts as described in Plaid's End User Privacy Policy. You can disconnect a linked account at any time in Totter; when you do, we delete our access credentials and instruct Plaid to remove the connection.
4. How we share information
We share information only with the service providers that make Totter work, each under their own security and privacy obligations: Plaid (bank connectivity), Stripe (payments, banking, and cards), Clerk (sign-in), Gusto (payroll), our cloud hosting and database providers, and — where you enable them — formation and verification partners. We may also disclose information when required by law, or as part of a corporate transaction with notice to you.
5. How we protect information
All traffic is encrypted in transit with TLS. Data is encrypted at rest, and the most sensitive fields — including bank connection tokens and EINs — are additionally encrypted at the application layer before they reach our database. Access is limited, authenticated, and audit-logged. Security questions or reports: security@gettotter.com.
6. Retention and deletion
Because Totter is a bookkeeping system of record, financial records (books, posted transactions, invoices, and audit history) are retained for the statutory bookkeeping period — generally seven years — even after an account closes. Bank connection credentials are deleted when you unlink an account. If you ask us to delete your account, we delete your personal information within 30 days except records we are legally required to keep, and we will tell you exactly what was retained and why.
7. Your choices and rights
You can access and update your information in the app, disconnect linked accounts at any time, and request a copy or deletion of your data by emailing security@gettotter.com. Depending on where you live, you may have additional rights under laws such as the CCPA; we honor verified requests regardless of state.
8. Children
Totter is a business service and is not directed to anyone under 18. We do not knowingly collect information from children.
9. Changes to this policy
If we make material changes, we will update this page and note the date above, and for significant changes we will notify you in the app or by email. Questions about this policy: security@gettotter.com.
See also the Totter terms.