Minerva Contractor Advisory LLC
Privacy Policy
Effective: June 9, 2026 (supersedes the version dated June 5, 2026)
Minerva Contractor Advisory LLC ("we," "us," "the Firm") provides bookkeeping and advisory services to construction businesses. Because we handle sensitive financial information, protecting it is core to our work. This policy explains what we collect, how we use and protect it, and your rights.
Information we collect
To deliver our services, we collect and process:
- Financial records: bank and credit-card statements, transactions, invoices, bills, payroll summaries, general-ledger data, financial statements, and job-cost / WIP data.
- Business information: entity name, EIN, address, ownership and officer details, licenses.
- Personal information (incidental): names and contact details of owners, employees, vendors, and customers appearing in your records; and, where required for bookkeeping or 1099 information-return functions, taxpayer identification numbers (e.g., from Forms W-9).
- System access: read-only "accountant" access to your accounting platform (e.g., QuickBooks Online). We do not request, accept, or store your online-banking or other financial-institution login credentials. Where an account is not connected to your accounting platform, we work from read-only statements you provide, or from accountant access provisioned by your financial institution in our own name.
- Information you provide directly (email, documents, uploads through agreed channels).
How we use information
We use your information to: perform the bookkeeping and advisory services (including secure, AI-assisted analysis as described under "How we share it"); communicate with you; maintain our records; comply with legal obligations; and — in de-identified, aggregated form only — improve our services and produce aggregated analyses and benchmarks that do not identify you and cannot reasonably be used to identify you. We do not sell your information, and we do not use it for advertising.
How we protect it
We maintain a written information security program designed to comply with the FTC Safeguards Rule (under the Gramm-Leach-Bliley Act), including: encryption of data in transit (TLS and private, authenticated network tunnels); storage on firm-controlled, hardened infrastructure with key-based access restricted to authorized personnel; encrypted off-site backups; multi-factor authentication on third-party platforms that support it (accounting, email, cloud consoles); least-privilege access; and oversight of our service providers. See Security below.
How we share it
We share information only with:
- Service providers / sub-processors that help us deliver services, each bound by confidentiality and security obligations:
- Hetzner — infrastructure hosting for our production systems; servers located in Hillsboro, Oregon, USA;
- Intuit (QuickBooks Online) — your accounting platform;
- Amazon Web Services, including Bedrock AI processing on a no-retention basis — prompts and outputs are not stored by AWS or used to train models;
- Backblaze — off-site backup storage holding only firm-encrypted data it cannot read;
- Authorities or third parties where required by law, subpoena, or to protect legal rights; and
- A successor in a business transfer, under equivalent protections and with notice to you.
We never sell or rent your data.
Data retention
We retain your financial records for seven (7) years (or longer where required by law or our engagement), then securely delete or return them. You may request return of your data upon termination of services.
Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data: encrypted transmission, access-controlled firm infrastructure, encrypted off-site backups, multi-factor authentication where the platform supports it, and secure storage and disposal. Documents are exchanged only over the channels designated in your engagement letter; we will never ask you to send credentials over email. No system is perfectly secure; in the event of a breach involving your information, we will notify affected parties as required by law — including California Civil Code § 1798.82 and, where applicable, the FTC Safeguards Rule — without unreasonable delay.
Your rights
You may request to access, correct, or delete your information, subject to legal and professional retention requirements. If the California Consumer Privacy Act applies to you, you have additional rights (to know, delete, correct, and to non-discrimination); we do not sell personal information. To exercise a right, contact us below.
Third-party services
Your accounting platform and financial institutions maintain their own privacy policies governing their handling of your data.
Changes
We may update this policy; the "Effective" date reflects the current version, and we will notify clients of material changes.