Privacy Policy

Last updated: July 9, 2026

1. Who we are and what this policy covers

Clo & Do, Inc. ("Amadae," "we," "us," or "our"), a Delaware corporation doing business as Amadae, provides accounting and financial software to businesses through amadae.co and its related applications (the "Services"). This policy explains what personal information we collect, how we use and share it, how long we keep it, and the choices available to you. It does not cover third-party websites or services that maintain their own privacy policies.

Where our Services include banking features, the underlying bank accounts and payment services are provided by our partner bank. Amadae is a financial technology company, not a bank. The partner bank's own privacy notice also applies to the deposit relationship, and required bank privacy language will be provided with those features.

2. Information we collect

Information you provide: identity and contact data (name, email address, phone number, business name and address); business onboarding and verification information where required for financial features; account and transaction data you enter into or authorize through the Services; support requests and the content of your communications with us.

Information collected automatically: usage, device, log, and approximate location data, and cookies and similar technologies. We use cookies to authenticate you, remember preferences, protect the security of the Services, and understand usage. You can control cookies in your browser settings; disabling strictly necessary cookies may prevent parts of the Services from working.

Information from third parties: bank-account and transaction information from Plaid for external accounts you choose to connect; payment records from Stripe; and information from other integrations you enable. We never collect or store full card numbers or card security codes; those values are held by our payment processor.

3. How we use your information

We use personal information to provide, operate, secure, maintain, and improve the Services, including AI-assisted features that process data on our behalf; to process payments; to verify identity and meet legal obligations, including fraud prevention; to communicate with you, including service messages and, where permitted, marketing messages you can opt out of at any time; and to comply with applicable law and enforce our terms.

4. How we share information

We share personal information with service providers who process data on our behalf under contract, limited to what each provider needs to perform its function. Our current providers include Google Cloud Platform / Firebase (hosting and infrastructure), Stripe (payment processing), Plaid (bank-account connectivity), Twilio (SMS messaging), Google Workspace (email), and Anthropic and OpenAI (AI-assisted processing). We also disclose information to legal and regulatory recipients where required or permitted by law, and in connection with a corporate transaction, subject to confidentiality protections.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act.

5. Data security

We maintain technical and organizational safeguards to protect personal information, including encryption in transit, access controls, and audit logging. No method of transmission or storage is completely secure; we work to protect your information but cannot guarantee absolute security. Report suspected security issues to phoenix@amadae.co.

6. Your privacy rights

Depending on where you live, you may have rights to know what personal information we process about you and to access it, correct it, delete it, obtain a portable copy, or restrict certain processing. You will not receive discriminatory treatment for exercising a privacy right. Some rights are subject to exceptions, including records we must retain under federal recordkeeping obligations. To exercise a right, contact phoenix@amadae.co; we verify each request before acting on it and respond within the timeframes required by applicable law.

7. Data retention

We keep personal information only as long as necessary for the purposes described here and to meet legal and regulatory obligations. Our standard retention period for records supporting financial features is five years. When a retention period ends, we delete or de-identify the information.

8. International transfers and children's privacy

We are based in the United States and process information in the US. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses. The Services are for businesses and are not directed to children, and we do not knowingly collect personal information from children.

9. Changes and contact

We may update this policy from time to time and will post the updated policy with a new effective date, providing additional notice where required by law. Privacy questions and requests: phoenix@amadae.co.