Back to sign in

Privacy policy

Plata, operated by Buena Agency, Inc. · effective September 7, 2026

What Plata is

Plata is a private financial workspace for Buena Agency, Inc. and the people who run it. It connects to bank and card accounts, keeps the books for personal, business, and nonprofit workspaces, and sends invoices to clients. It is not a public service: people sign in by invitation to one workspace, and clients reach their own invoices through a private link.

This policy explains what data Plata handles, where it comes from, why, where it is stored, for how long, and what you can ask us to do with it. It covers two groups of people: the people who sign in to Plata (“users”) and the clients who receive invoices and open the client portal (“clients”).

Data Plata collects, and where it comes from

From financial institutions, through Plaid

When a user connects a bank or card account, Plaid provides account names, types, the last four digits of account numbers, balances, and transactions (date, merchant, description, amount, and Plaid’s category). Plata never sees or stores online banking credentials; those go to Plaid’s own secure flow. Plata stores the access token Plaid issues so it can refresh transactions, encrypted as described below. Plaid’s handling of your data is governed by the Plaid End User Privacy Policy.

From Ramp

With a Ramp API connection, Plata reads the business’s cards (names, last four digits, cardholder, limits), card transactions, and, when the scope is granted, bills paid through Ramp Bill Pay (vendor, amount, date, invoice number). The API credentials are stored encrypted.

From imports

Users can import bank or card statements as CSV files. The rows become transactions like any other. Receipt images a user attaches are stored in a private bucket.

About clients

For invoicing, Plata stores a client’s company name, billing address, billing and contact email addresses, the invoices sent, the payments received, and when an invoice was opened in the portal. When a client pays by bank transfer, Stripe collects and holds the bank account details; Plata receives only the payment status and a Stripe customer reference, never the account number. Stripe’s privacy policy applies to that step.

About users

A user’s email address and a password hash, held by Supabase Auth. Plata keeps an audit trail of significant actions (connecting or disconnecting an account, moving records between workspaces, changes to billing) with the acting user and a timestamp.

What Plata does not collect

No analytics or advertising trackers, no third-party cookies, no location, no contacts, no device fingerprinting. The only cookies are the sign-in session, the chosen workspace, and the light/dark theme.

Why Plata uses this data

  • To show balances, transactions, spending, cash flow, net worth, and profit and loss for each workspace.
  • To categorize transactions, match transfers and card payments, detect recurring charges, and attribute pay to team members.
  • To create, send, and collect invoices, including billable expenses, late fees, and reminders, and to match incoming payments to open invoices.
  • To keep the audit trail that lets the operator see who changed what.

Plata does not sell data, share it with advertisers, or use it to build profiles of anyone.

Who else sees it

  • Supabase hosts the database, authentication, and file storage, in the AWS us-west-2 region (Oregon, United States).
  • Vercel hosts the application and its server functions.
  • Plaid and Ramp provide the financial data described above.
  • Stripe processes client bank-transfer payments.
  • Resend delivers invoice and reminder emails to clients. An email carries the invoice lines and amounts; it never carries bank account or routing numbers, which appear only on the client’s private invoice page.
  • Anthropic receives, only when a user runs the optional AI categorization pass, the merchant name, bank description, amount, date, and current category of the selected transactions, and returns suggested categories. No account numbers, balances, names of people, or client details are sent, and Anthropic does not use API data to train its models.

Each of these providers processes data under its own agreement with Buena Agency, Inc.. Plata shares no data with anyone else, except where the law requires it.

How it is protected

  • Every connection uses HTTPS with HSTS; the app sets a content security policy and refuses to be framed.
  • Plaid access tokens and Ramp API credentials are encrypted at the application layer with AES-256-GCM under a key that lives only in the server environment, then stored in tables that no browser session can read. Supabase also encrypts every disk at rest.
  • Every table is protected by row-level security: a signed-in user reads only the workspaces they belong to, and only finance roles can change financial records. The client portal is served with a scoped server-side client and shows one client their own invoices only.
  • Sign-in is by invitation only. An invited person sees the one workspace they were invited to and nothing else; every other address is refused even with a valid password.
  • Client portal links are long random tokens that the operator can retire and reissue at any time.
  • Webhooks from Plaid and Stripe are verified by signature before anything is processed; the daily billing run needs a secret only the scheduler holds.
  • Secrets never appear in the browser bundle or in logs.

How long it is kept

Transactions and balances are kept for as long as the workspace exists, because books need history. Disconnecting a bank account revokes Plata’s access at Plaid (the token is deleted at Plaid and in Plata) and stops new data; the history already imported stays in the books until the user deletes it. Invoices and payments are kept for as long as the operator must retain financial records. Receipts stay with their transaction. Audit entries are kept with the workspace.

What you can ask for

Whether you are a user or a client, you can ask Buena Agency, Inc. to show you the data Plata holds about you, correct it, or delete it where the law does not require it to be kept. Clients can ask for their portal link to be retired. Users can disconnect any financial account themselves from the Accounts page, which revokes access at the institution through Plaid. Write to hola@buena.org.

Changes

If this policy changes in a way that matters, the effective date at the top moves and users are told at sign-in. Questions go to hola@buena.org.