Privacy Policy

Last updated 16 September 2026

WS Ledger is provided by White Sun (Malé, Republic of Maldives). This page explains what personal data we collect through WS Ledger, why, and what you can do about it. It applies to anyone who signs in to WS Ledger — an owner, an employee of a customer organisation, or someone who was invited.

Two kinds of data, two roles

WS Ledger is accounting software your organisation uses to run its own books. That splits the data behind it into two kinds, and we act differently for each:

  • Data about you as a user — your name, email address, password, and how you use the product. For this, White Sun decides why and how it is processed, and this policy describes that in full.
  • Data your organisation puts into its own books — its customers, suppliers, employees, invoices, and financial records. Your organisation controls this data and decides what to enter, correct, keep or delete; White Sun processes it only on your organisation’s behalf, under its instructions, to provide the service. If you are a customer, supplier or employee of a business using WS Ledger and you have a question about your own data, the business itself — not White Sun — is who to ask.

What we collect

  • Account data — name, email address, and a password (we only ever store it hashed; we cannot read it).
  • Organisation data — the business’s legal name, address, MIRA Taxpayer Identification Number, GST/TGST registration status, and similar profile details it enters under Settings.
  • Financial and business records — invoices, bills, payments, journal entries, inventory, payroll and any other data your organisation enters to run its books. Payroll records include what your organisation enters about its own employees: salary, allowances, and bank details for paying them.
  • Documents you upload — receipts, supplier invoices and similar files attached to a record, stored in a private bucket that only your organisation, through the product, can read.
  • Sign-in and security data — the IP address and browser your session started from, timestamps of sign-ins and actions taken, and, if you turn it on, an encrypted two-factor secret or the public key half of a passkey (never anything that could reconstruct your fingerprint, face, or device PIN — those never leave your device).
  • Support and billing communications — anything you send us directly, such as a help request or a payment reference for a bank transfer.

We do not collect payment card numbers: WS Ledger takes payment by bank transfer, recorded by a platform administrator from what the bank shows — no card data ever passes through the product.

Why we process it

  • To provide the product you or your organisation signed up for, and keep your account secure.
  • To meet our own legal obligations — invoicing you, and keeping the records Maldivian law requires of a business.
  • To respond when you contact support, or when your organisation’s administrator asks us to.
  • To keep the service reliable and secure: rate-limiting sign-in attempts, investigating abuse, and maintaining the audit trail described below.

We do not use your data to serve you advertising, and we do not sell it, rent it, or share it with data brokers.

Who inside WS Ledger can see it

Every piece of data belongs to one organisation, and every query the product makes is scoped to it — one organisation cannot see another’s records. Within an organisation, what a person can see follows their role: a cashier does not see the general ledger, a bookkeeper cannot see payroll unless granted it, and so on. Significant actions — signing in, posting a document, changing a role, adding or removing a file — are written to an append-only audit trail that an administrator can review.

Who else sees it

We share data with:

  • Infrastructure providers who host the servers, database, file storage and email delivery WS Ledger runs on. They process data only to provide that infrastructure and have no independent right to use it.
  • Authorities, if the law requires it of us — for example, a lawful request from MIRA or a Maldivian court.
  • A successor, if White Sun were ever to merge with or be acquired by another company — subject to that successor honouring this policy.

Nobody else. In particular, we do not share data with advertisers or analytics networks — we do not use any.

Where it is kept

WS Ledger’s infrastructure is chosen to keep data in the region, close to the Maldives. If that ever changes to include a provider outside it, we take the same care over the data regardless of where the servers sit.

How long we keep it

Account and business data is kept for as long as the account is active. Accounting records are kept for as long as applicable Maldivian tax and business record-keeping law requires, even after an account is closed, because that obligation falls on the business that made the records — not on us to waive. A closed account’s ability to sign in ends immediately; the underlying records are deleted or anonymised once no legal reason remains to keep them, on request.

Security

Some of the concrete steps WS Ledger takes, so this is not just a promise:

  • Passwords are hashed, never stored in a form we could read back.
  • A two-factor secret is encrypted at rest; a passkey’s private key never leaves your device — we only ever hold its public half.
  • Sign-in cookies are httpOnly and, outside local development, sent only over an encrypted (https) connection.
  • Sign-in attempts are rate-limited, by network and by account, with a lockout after repeated failures.
  • Every action of consequence is written to an audit trail nothing in the product can edit or delete.
  • Uploaded files are checked against their actual content, not just their name, before being accepted, and served only to someone with permission to see the record they are attached to.

No system is unbreakable, and we do not claim otherwise — but these are real, specific measures, not marketing language.

Your rights

You can ask to see, correct, or export the personal account data we hold about you, or ask us to delete your account. If you are asking about data your organisation entered — its customers, its employees, its books — that request goes to your organisation; we act on their instructions for that data, not yours directly, unless the law says otherwise. Where deletion would conflict with a legal duty to keep financial records, we will tell you what we can and cannot delete, and why.

Children

WS Ledger is business software. It is not directed at children, and we do not knowingly collect data from anyone under 18.

Changes to this policy

If this policy changes in a way that matters, we will say so — by email to account holders for a material change, and always by moving the date at the top of this page.

Contact

For anything in this policy, write to [email protected].