Pippin

Privacy Policy

Effective 12 August 2026 · Last updated 13 August 2026

Pippin is accounting and billing software for managed service providers. It is operated by CDS Group Inc. This policy explains what it holds, why, who else sees it, and how to get it back or have it deleted.

Two kinds of people, two different roles

This distinction runs through everything below, so it comes first.

If you are a client of an MSP that uses Pippin and you want to see, correct or remove your information, ask them — they control it, and we will help them do it.

What Pippin holds

Account information

Your name, email address, the organisation you belong to, and the role that decides what you can do. Sign-in is handled by Supabase Auth, by emailed link or by Microsoft work account. Pippin never receives or stores a password.

The records you enter

The books themselves: your chart of accounts, journal entries, invoices, payments, quotes, expenses, bills, time entries, and the client, vendor and employee records they refer to. Client and end-user records typically include names, email addresses, phone numbers and postal addresses.

Files you upload

Receipts, vendor invoices, scanned cheques, tax certificates and similar documents, stored in a private bucket that is never publicly readable and is served only through short-lived signed links.

Information from services you connect

Only when you connect them, and only what the feature needs: bank and card transactions through Plaid, invoice and payment records through Stripe, device and licence counts from Addigy or Pax8, and worklogs from Jira.

A record of what was done

Pippin keeps an audit log of actions taken in your organisation — who did what, when, and what changed. This is a feature of accounting software rather than analytics: it exists so an owner can answer questions about their own books.

What Pippin does not do

Why we hold it

To run the service you asked for: keeping your books, issuing invoices through Stripe, importing bank activity, tracking time, producing reports, and letting you export everything. We also use account information to sign you in, to send notifications you have switched on, and to contact you about the service itself.

Where the law requires a legal basis, ours is the performance of our contract with your organisation, and our legitimate interest in keeping the service secure and working.

Google user data

If you connect a Google Drive so Pippin can deliver your exports there, Pippin requests two things and no more: the drive.file scope, and your account's email address.

drive.file grants access only to files Pippin itself creates. Pippin cannot see, read or list anything else in your Drive — not one existing document. The email address is used for a single purpose: showing you which Google account your exports are being delivered to, on the screen where you connected it. It is not used to contact you, and it is not shared.

Pippin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data for advertising, we do not sell or transfer it, and we do not use it to train machine-learning models. No person at CDS Group Inc reads it, except where you have asked us to for support, where it is necessary for security, or where the law requires it.

You can disconnect at any time in Pippin, and revoke access directly at myaccount.google.com/permissions. The same applies to a connected Microsoft OneDrive, where Pippin requests only its own application folder.

Who else sees it

Pippin uses a small number of service providers, each for one job. They act on our instructions and may not use your information for their own purposes.

ProviderWhat it doesWhen
SupabaseDatabase, sign-in and file storageAlways
StripeIssues invoices and collects paymentsAlways
AppleDelivers push notifications to your devicesIf you enable them
Microsoft Entra IDSigning in with a Microsoft work accountIf you use it
PlaidBank and card connectionsIf you connect a bank
Addigy · Pax8Device and licence counts used for billingIf you connect them
Atlassian JiraImports worklogs as time entriesIf you connect it
Google Drive · Microsoft OneDriveReceives scheduled exportsIf you connect one

We also disclose information if the law requires it, and if CDS Group Inc is ever sold or merged — in which case the buyer is bound by this policy, and you would be told before anything changed.

Where it is stored

In the United States, in Amazon Web Services' Oregon region, through Supabase. If you are outside the United States, using Pippin means your information is transferred there.

Keeping it safe

No system is perfectly secure. If a breach affects your information we will tell you and any regulator that has to be told, without undue delay.

How long it is kept

Getting your data out

You do not need to ask us. Settings → Export produces everything — the journal, the chart of accounts, every invoice, payment, expense, bill, vendor and time entry, plus every receipt you have uploaded — as CSV files anyone can open, with a trial balance you can check it against.

This is deliberate. Being unable to leave is a reason not to start, so leaving is a button rather than a support request.

Your rights

Depending on where you live you may have the right to see the information we hold about you, correct it, delete it, receive a copy in a portable form, or object to some uses of it. Email us and we will answer within 30 days. We will not treat you differently for asking.

If your information is in Pippin because an MSP put it there, ask that MSP first — they control it. Pass the request to us and we will point you to them, and help them act on it.

Children

Pippin is business software and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes

If this policy changes we will update the date above, and tell account holders in the app before anything material takes effect.

Contact

CDS Group Inc
privacy@pippinhq.com