Privacy Policy
What Midbench is
Midbench keeps a company's accounting records: it connects to the financial services a customer authorizes (banks, payment processors, billing and payroll platforms), reads their activity, and maintains governed, auditable books from it.
What we store
- Financial records. Transactions, balances, invoices, bills, and payroll summaries read from the providers a customer connects, plus the accounting records derived from them. These are the product — they are retained as ledger records for as long as the customer keeps an account, and audit history is retained as required for financial record-keeping.
- Provider credentials. When a customer connects a provider, the credential (an API key or OAuth token) is captured on a dedicated page over TLS, encrypted immediately, and stored only in ciphertext. Credentials are never shown back to anyone — including us — and are used solely to read the data the customer authorized. Read-only scopes are used wherever the provider offers them.
- Contact details. The name and email used to communicate with us.
What we don't do
- We do not sell personal or financial data, and we do not share it with third parties for their own purposes.
- We do not run advertising or third-party tracking on this site.
Service providers
Midbench runs on infrastructure from Amazon Web Services and ClickHouse Cloud, which process data on our behalf under their own security and confidentiality commitments. Data is encrypted in transit and at rest.
Deletion
Customers can disconnect a provider at any time, which stops all further reads; stored credentials for it are revoked. To close an account or request deletion of data not subject to financial record-keeping obligations, email us.
Changes
If this policy changes materially, we will post the updated version here with a new effective date.
Contact
info@midbench.com · Midbench Inc., 60 Broad Street, New York, NY 10004