Privacy Policy
Last updated: June 21, 2026
This Privacy Policy describes how AbroadLedger ("AbroadLedger", "we", "us", or "our") collects, uses, shares, and protects personal information when you use our website and informational products (the "Service"). It forms part of, and should be read together with, our Terms of Service and Disclaimer. By using the Service, you acknowledge the practices described here. For the purposes of applicable data protection laws, AbroadLedger is the controller of the personal information described below.
1. Information we collect
- Contact information. Your email address, provided when you request a free risk check or purchase a report.
- Questionnaire responses. Information you submit about your residency, citizenship, time spent in countries, income types and ranges, assets, and filing history. We deliberately design the questionnaire to use ranges and categories. We do not request government identification numbers, account numbers, or exact financial figures, and you should not enter them.
- Payment information. Payments are processed by PayPal. We receive confirmation of payment status, a transaction identifier, and the email address associated with the purchase. We never receive or store your full card or bank account details.
- Technical information. Standard server logs (such as IP address, device, and browser type) and basic security and anti-abuse data may be processed by our hosting provider for security, fraud prevention, and operational purposes.
- Documents you upload (Deepdive only). If you choose the Verified Deepdive tier, you may upload documents such as a passport photo page, a tax return, a bank statement, a payslip or employment contract, or a property document. Uploading is optional, and you choose which documents, if any, to provide. These documents are held in your own browser until checkout and are then sent to our systems only to extract the facts needed for your report. Please redact or omit any detail that is not necessary for your report.
- Correspondence. If you contact us, we keep your message and our reply so we can respond and keep records.
2. How we use your information and our legal bases
- To generate and deliver the report or risk summary you requested. Your questionnaire responses are processed by automated systems to produce your report. (Legal basis: performance of a contract.)
- To process your payment and prevent fraud. (Legal basis: performance of a contract and our legitimate interests.)
- To send transactional emails related to your purchase or request. (Legal basis: performance of a contract.)
- To send occasional marketing communications about our products, where permitted. Every marketing email includes an unsubscribe link, and you may opt out at any time. (Legal basis: consent or legitimate interests, as applicable.)
- To operate, secure, debug, and improve the Service, and to keep records and resolve disputes. (Legal basis: legitimate interests.)
- To comply with legal, tax, accounting, and regulatory obligations, and to establish, exercise, or defend legal claims. (Legal basis: legal obligation and legitimate interests.)
- For the Verified Deepdive tier, to extract relevant facts from the documents you upload so your report can reflect them. Extraction is performed by automated systems for the sole purpose of preparing your report. (Legal basis: performance of a contract.)
We do not use your information to make decisions that produce legal or similarly significant effects about you. Reports are general educational information and are not decisions about you. We do not use your questionnaire responses or uploaded documents to train machine-learning models.
3. Service providers
We share personal information only with the service providers needed to operate the Service, and only as needed for them to perform their function for us:
- PayPal (payment processing). PayPal processes your payment and shares with us the payment status, a transaction identifier, and the associated email address. Your questionnaire responses are stored by us in a temporary session record (Cloudflare KV) keyed to the order so we can prepare and deliver your report; this record expires automatically.
- Resend (email delivery and contact list management).
- Cloudflare (website hosting, edge compute, and short-lived session storage). We use Cloudflare's key-value store to hold the data needed to fulfill a request, with an automatic expiry.
- Automated document-processing provider (Verified Deepdive only). Documents you upload are sent to a third-party processing provider solely to extract the facts needed for your report. The provider processes the documents to return that information and does not use your documents to build or train its own products.
Each provider processes data under its own privacy terms and applicable data-processing agreements. We may also disclose information where required by law, to comply with legal process, to enforce our Terms, to protect the rights, safety, or property of AbroadLedger or others, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honor this Policy). We do not sell or rent personal information, and we do not share it with third parties for their own advertising purposes.
4. Data retention
We keep personal information only for as long as necessary for the purposes described in this Policy. Session records used to fulfill a request are short-lived and expire automatically. We retain contact information and purchase records for as long as needed to provide the Service, comply with legal obligations (including tax and accounting requirements), and establish or defend legal claims, after which we delete or anonymize it.
Deepdive documents. Documents you upload for the Verified Deepdive tier are held in your own browser until checkout and are sent to our systems only to extract the facts needed for your report. They are not added to any marketing list and are not retained beyond what is needed to prepare and deliver your report. If you would like any uploaded document deleted sooner, contact us using the details in the Contact section.
5. Security
We use reasonable technical and organizational measures intended to protect personal information, including transport encryption and limiting access to data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You provide information to the Service at your own risk, and you are responsible for keeping access to your email account secure.
6. Your rights
Depending on your place of residence, you may have rights to access, correct, export, or delete the personal information we hold about you; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. If you are in the European Economic Area or the United Kingdom, these include rights under the GDPR. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them; note that we do not sell or share personal information as those terms are defined under California law. To exercise any right, contact us at the address in the Contact section; we may need to verify your identity, and we will respond within the timeframe required by applicable law. You may unsubscribe from marketing emails at any time using the link in any such email.
7. Cookies
The Service does not use advertising or cross-site tracking cookies. Strictly necessary cookies or similar technologies, and essential cookies set by our payment processor during checkout, may be used to operate the Service and enable secure payment.
8. International transfers
We and our service providers may process and store data in countries other than your own, including the United States, whose data protection laws may differ from those in your country. Where required, such transfers are protected by appropriate safeguards, such as the European Commission's standard contractual clauses or an equivalent mechanism.
9. Children
The Service is not directed to persons under 18 years of age, and we do not knowingly collect personal information from them. If you believe a minor has provided us personal information, contact us and we will delete it.
10. Third-party links
The Service may link to third-party websites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their policies before providing them with information.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date on this page and, where appropriate, by other reasonable means. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
12. Contact
To exercise your rights or ask questions about this Policy, please reach us through the Contact page.