Effective 12 August 2026 · Last updated 13 August 2026
Pippin is accounting and billing software for managed service providers. It is operated by CDS Group Inc. This policy explains what it holds, why, who else sees it, and how to get it back or have it deleted.
This distinction runs through everything below, so it comes first.
If you are a client of an MSP that uses Pippin and you want to see, correct or remove your information, ask them — they control it, and we will help them do it.
Your name, email address, the organisation you belong to, and the role that decides what you can do. Sign-in is handled by Supabase Auth, by emailed link or by Microsoft work account. Pippin never receives or stores a password.
The books themselves: your chart of accounts, journal entries, invoices, payments, quotes, expenses, bills, time entries, and the client, vendor and employee records they refer to. Client and end-user records typically include names, email addresses, phone numbers and postal addresses.
Receipts, vendor invoices, scanned cheques, tax certificates and similar documents, stored in a private bucket that is never publicly readable and is served only through short-lived signed links.
Only when you connect them, and only what the feature needs: bank and card transactions through Plaid, invoice and payment records through Stripe, device and licence counts from Addigy or Pax8, and worklogs from Jira.
Pippin keeps an audit log of actions taken in your organisation — who did what, when, and what changed. This is a feature of accounting software rather than analytics: it exists so an owner can answer questions about their own books.
To run the service you asked for: keeping your books, issuing invoices through Stripe, importing bank activity, tracking time, producing reports, and letting you export everything. We also use account information to sign you in, to send notifications you have switched on, and to contact you about the service itself.
Where the law requires a legal basis, ours is the performance of our contract with your organisation, and our legitimate interest in keeping the service secure and working.
If you connect a Google Drive so Pippin can deliver your exports there, Pippin requests
two things and no more: the drive.file scope, and your account's email
address.
drive.file grants access only to files Pippin itself creates.
Pippin cannot see, read or list anything else in your Drive — not one existing document.
The email address is used for a single purpose: showing you which Google account your
exports are being delivered to, on the screen where you connected it. It is not used to
contact you, and it is not shared.
Pippin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, we do not sell or transfer it, and we do not use it to train machine-learning models. No person at CDS Group Inc reads it, except where you have asked us to for support, where it is necessary for security, or where the law requires it.
You can disconnect at any time in Pippin, and revoke access directly at myaccount.google.com/permissions. The same applies to a connected Microsoft OneDrive, where Pippin requests only its own application folder.
Pippin uses a small number of service providers, each for one job. They act on our instructions and may not use your information for their own purposes.
| Provider | What it does | When |
|---|---|---|
| Supabase | Database, sign-in and file storage | Always |
| Stripe | Issues invoices and collects payments | Always |
| Apple | Delivers push notifications to your devices | If you enable them |
| Microsoft Entra ID | Signing in with a Microsoft work account | If you use it |
| Plaid | Bank and card connections | If you connect a bank |
| Addigy · Pax8 | Device and licence counts used for billing | If you connect them |
| Atlassian Jira | Imports worklogs as time entries | If you connect it |
| Google Drive · Microsoft OneDrive | Receives scheduled exports | If you connect one |
We also disclose information if the law requires it, and if CDS Group Inc is ever sold or merged — in which case the buyer is bound by this policy, and you would be told before anything changed.
In the United States, in Amazon Web Services' Oregon region, through Supabase. If you are outside the United States, using Pippin means your information is transferred there.
No system is perfectly secure. If a breach affects your information we will tell you and any regulator that has to be told, without undue delay.
You do not need to ask us. Settings → Export produces everything — the journal, the chart of accounts, every invoice, payment, expense, bill, vendor and time entry, plus every receipt you have uploaded — as CSV files anyone can open, with a trial balance you can check it against.
This is deliberate. Being unable to leave is a reason not to start, so leaving is a button rather than a support request.
Depending on where you live you may have the right to see the information we hold about you, correct it, delete it, receive a copy in a portable form, or object to some uses of it. Email us and we will answer within 30 days. We will not treat you differently for asking.
If your information is in Pippin because an MSP put it there, ask that MSP first — they control it. Pass the request to us and we will point you to them, and help them act on it.
Pippin is business software and is not directed at children. We do not knowingly collect information from anyone under 16.
If this policy changes we will update the date above, and tell account holders in the app before anything material takes effect.
CDS Group Inc
privacy@pippinhq.com