Privacy Policy

Effective September 4, 2026

Xtreme Book (“Xtreme Book”, “we”, “us”) provides cloud bookkeeping software for small businesses. This policy explains what personal and business data we collect when you or your organization uses Xtreme Book, why we collect it, who we share it with, and the choices and rights you have over it. It applies to everyone who uses Xtreme Book — account holders, the team members they invite, and, to a limited extent, the customers and vendors whose details an organization stores in Xtreme Book on its own behalf.

If you’re an individual whose invoice, receipt, or contact details were entered into Xtreme Book by a business you deal with, that business is the one that controls and is responsible for that data (see “If you’re a customer or vendor of an Xtreme Book user” below) — we process it on their behalf, under their instructions.

1. Data we collect

Account & organization data

  • Your name, email address, and password (we store a salted hash of your password, never the password itself) or, if you sign in with Google or Facebook, the name, email, and profile photo those providers share with us.
  • Your organization’s name, legal name, logo, contact details, address, currency, fiscal year, and the document numbering, tax, and template preferences you configure.
  • Your role within the organization, and login/session activity (timestamps, rough device/browser identification from your user agent) used for security and for the “last seen” and login-history features.

Business data you enter

Everything you or your team record in Xtreme Book to run your books: customers, vendors, items, invoices, quotes, bills, expenses, sales receipts, credit notes, purchase orders, journal entries, bank transactions you import, employees and payroll figures, budgets, fixed assets, and any files you attach to a record. This is your data — see “Your rights” and our Terms of Service for how ownership and export work.

Payment data

When your organization collects a payment via Mobile Money (Flutterwave) on an invoice, or pays for a Pro or Ultimate subscription, the payment itself is handled by Flutterwave — we never see or store full card or mobile money account numbers. We store the transaction reference, amount, currency, status, and the Flutterwave transaction ID, so the payment shows up correctly against your invoice or subscription.

Technical data

Standard web request data (IP address, browser type, pages requested, timestamps) generated by using the app, kept in server and hosting-provider logs for a limited time for security, debugging, and abuse prevention. We do not run any advertising or analytics trackers — see our Cookie Policy.

2. How we use it

  • To provide the service: create your account, run your organization’s bookkeeping, generate documents and reports, and process payments.
  • To communicate with you: transactional emails (email verification, password reset, invoices you send to your customers, notifications you’ve opted into — overdue invoices, low stock, bills due, unusual spending) and, occasionally, service announcements.
  • To keep the service secure: detecting suspicious logins, enforcing plan limits and access control, and maintaining the audit trail described in our Security page.
  • To improve Xtreme Book: understanding aggregate, non-identifying usage patterns to prioritize what we build next.
  • To meet legal obligations: tax, accounting, and record-keeping requirements we’re subject to as a business.

We do not sell your data, and we do not use your business data to train third-party AI models.

3. Who we share it with

We share data with the sub-processors listed on our Sub-processors page — the infrastructure, payment, and email providers that make Xtreme Book work — each bound by a contract to protect your data and use it only to provide their service to us. We otherwise disclose personal data only:

  • Within your organization, according to the roles and permissions your organization’s owner configures.
  • When you direct us to — for example, when you send an invoice or shared link to your customer.
  • To comply with a legal obligation, court order, or lawful request from a competent authority.
  • To protect the rights, property, or safety of Xtreme Book, our users, or the public, including investigating fraud or abuse.
  • If Xtreme Book is involved in a merger, acquisition, or asset sale — we’d notify you before your data becomes subject to a different privacy policy.

4. If you’re a customer or vendor of an Xtreme Book user

If a business using Xtreme Book has stored your name, email, phone number, or address as one of their customers or vendors, or sent you an invoice, quote, or receipt through Xtreme Book, we process that information solely as instructed by that business, to provide Xtreme Book to them. We’re not able to respond to a request to access, correct, or delete that data directly — please contact the business you dealt with, and they can act on it (including exporting or deleting the record) from within Xtreme Book.

5. Data retention

We keep account and business data for as long as your organization’s account is active, plus a reasonable period after closure to allow you to reactivate, to meet accounting and legal record-keeping obligations, and to resolve disputes. You can request deletion at any time — see “Your rights” below. Server and access logs are kept for a limited rolling window and then purged.

6. Where your data is stored

Xtreme Book’s infrastructure is hosted with cloud providers that may process data outside Uganda. Where that happens, we rely on our providers’ own security and contractual safeguards (see Sub-processors and Security) to keep your data protected to the same standard wherever it’s processed.

7. Your rights

Subject to applicable law — including Uganda’s Data Protection and Privacy Act, 2019, and, where it applies to you, the EU/UK GDPR — you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data — most of your own account and organization data can be edited directly in Settings.
  • Export your organization’s data — Settings > Data Export gives you a full CSV/PDF export at any time.
  • Delete your account and organization’s data, subject to the retention needs described above — do this yourself anytime from Settings > Privacy & Security > Danger Zone, or by emailing us.
  • Object to or restrict certain processing, and, where applicable, withdraw consent you previously gave.
  • Lodge a complaint with your local data protection authority.

To exercise any of these, email privacy@xtremebook.com. If you’re a member of an organization rather than its owner, some requests may need to go through your organization’s owner, since they control the account.

8. Children

Xtreme Book is a business tool and isn’t directed at, or knowingly used by, children under 18.

9. Changes to this policy

If we make a material change, we’ll update the effective date above and, where the change is significant, notify organization owners by email before it takes effect.

10. Contact us

Questions, requests, or concerns about this policy: privacy@xtremebook.com.

Questions about any of this? Contact us at legal@xtremebook.com.

Privacy Policy — Xtreme Book