Privacy policy

Last updated: 30 September 2026

This policy explains what personal data we handle, whose, what for, who we share it with, how long we keep it, and how to exercise your rights. It describes the same service as our Mexican and Colombian notices, which are written to the law of those countries; where the versions differ, the Spanish one governs for customers contracting there. If anything here is unclear, ask us before you accept it.

Who we are

The controller of your personal data is DiVincenzo Development LLC, a company organised in the United States of America, which operates YaCuadra.

For anything to do with this policy — requests about your data, questions, complaints — write to privacy@yacuadra.com. We reply by the same means unless you ask for another.

Who this covers

It covers two groups of people, and our relationship with each is different.

The people who use the service: accountants and staff at the firm that subscribes, and sellers who subscribe directly. For them we are the controller.

The people whose data appears in the information being reconciled: the firm's seller clients and, where those sellers are individuals, the sellers themselves. For that data the firm is the controller and we act on its behalf, on its instructions.

What personal data we collect

From whoever uses the service: name, email address, password — stored using a slow key-derivation function, never in the clear and never recoverable — and the firm or company they belong to.

About the firm's seller clients: name or business name, tax ID, tax status, the identifier of their marketplace account, read-only credentials for reading it, the period's financial transactions — sales, commissions, shipping, advertising, refunds, chargebacks and withholdings — and the tax invoices behind them.

Technical data: IP address, browser type, date and time of access, and the actions taken inside the account. We use these to run the service, investigate incidents and show who did what, which is a reasonable requirement in a tool that touches accounting records.

What we do not collect, and it is worth saying plainly: we do not ask for or store electronic signing certificates, tax authority credentials, bank credentials or card details. We handle no sensitive data. We never move money and never have access to anyone's funds.

How we obtain it

Directly from you, when you create the account, configure a client, or write to us.

From the marketplace and the payment gateway, through a read-only authorisation that you or your client grant and can revoke at any time from the platform itself.

From the files you upload, when you would rather hand us the reports than connect the account.

What we use it for

Necessary purposes, without which we cannot provide the service: reconciling the payout against its components; identifying, quantifying and documenting differences; producing the period's journal entry and its working papers; keeping the history so a closed period can be restated when a late refund arrives; support; billing and collecting the subscription; and meeting legal obligations.

Additional purposes, optional, which you may decline without affecting the service or its price: improving the product from aggregated data that identifies no person and no client, and telling you about changes and new features.

To decline the additional ones, say so at the address above. We do not use your data, or your clients', to train third-party models.

Who we share it with

We do not sell personal data, do not hand it to anyone for their own commercial use, and do not publish it.

We share it only with the providers who help us operate, limited to what their function requires: the infrastructure the service runs on, transactional email, the host of this public site, and the payment processor that charges the subscription.

Each handles the data on our behalf, under contract, with a duty of confidentiality and an obligation to return or delete it when the relationship ends. We do not permit them to use it for their own purposes.

We may also disclose it when a competent authority requires it in writing and lawfully. Where the law permits, we will tell you first.

International transfers

The controller is organised in the United States, so any handling of data originating in Mexico or Colombia is an international transfer. By accepting this policy you consent to it.

Some of the providers who help us operate are also outside Mexico and Colombia.

We and each provider are bound to handle the data only for the purposes described here, keep it confidential, apply security measures equivalent to those your country's law requires, and return or delete it when the relationship ends.

Mexican and Colombian data protection law continues to apply to this handling, and we submit to it despite being organised abroad.

Where the data lives

The service runs on our own infrastructure, which we administer, not on a third-party cloud. The servers are outside Mexico and outside Colombia.

If the servers move, we will update this section and tell you before they do.

How long we keep it

While the account is active we keep the period's reconciled information and its working papers, because a closed period may have to be restated when a late refund or chargeback arrives.

When the relationship ends you can export your data for 30 days. After that we delete the reconciled information.

We keep longer only what the law requires us to — our own accounting and tax records, subscription receipts — and the access logs needed to investigate security incidents, which we delete once they no longer serve that purpose.

How we protect it

Traffic is encrypted in transit. Passwords are stored derived and never in the clear. Access to production systems is limited to those who need it for their role and is logged.

The session is held in a signed cookie; if the signature does not match, the session is discarded.

No system is invulnerable. If a breach occurred that significantly affected your rights, we would tell you without undue delay, along with what we know, what we are doing, and what we recommend you do.

Automated decisions

The service compares figures and flags differences automatically. Those flags are exactly that: a line marked for a person to check.

We make no automated decisions that produce legal effects for you or for your clients. No output of the system determines a tax liability, approves or rejects anything, or replaces the judgement of the accountant who signs.

Your rights and how to use them

You can ask for a copy of your data, have it corrected when it is wrong or incomplete, ask us to delete it, object to specific uses, and ask us to restrict how it is used or disclosed.

Write to privacy@yacuadra.com with your name, a way to reply to you, proof of your identity or of your authority to act, a clear description of the data your request concerns, and anything that helps us locate it.

We answer within the period the applicable law requires — in Mexico, 20 working days, acted on within a further 15; in Colombia, ten working days for a query and fifteen for a complaint, extendable as the law provides. Exercising these rights is free.

If the request concerns a client of the firm, we pass it to the firm as controller and tell you we have done so, because in that case the decision is theirs.

Withdrawing consent

You can withdraw consent at any time by writing to the same address. You can also remove the read-only access from the marketplace platform itself, with immediate effect.

Withdrawing it may stop us being able to provide the service, and in some cases the law requires us to keep certain records regardless.

How to complain

If you believe we have not handled your request properly, you can take it to the supervisory authority for your country — in Mexico the INAI, in Colombia the Superintendencia de Industria y Comercio.

We would be grateful if you raised it with us first: it is usually faster, and we want to know.

Cookies and tracking

Cookies are small files the site stores in your browser. This site uses first-party cookies only. We use no third-party cookies, no advertising cookies and no cross-site tracking technologies, and we embed no social-network pixels or tags. Nor are fonts or any other resource loaded from third-party servers: every resource the site uses is served from our own domain.

Necessary cookies. These enable the site to function and to provide the service you have requested: keeping you signed in, retaining preferences such as which edition of the site you were reading, recording your decision in respect of this notice, and preserving the security of access to your account. They are not subject to consent, and disabling them prevents the site from working correctly.

Measurement cookies. These allow us to understand, in aggregate, how the site is used, for the purpose of improving it. They are set only with express consent given through the cookie notice. Where they are used, this section will identify the tool employed, the information it collects and its retention period.

The cookie notice presents the options to accept and to reject on equal terms. Rejection does not limit access to any functionality of the site. You may withdraw or change your decision at any time from “Cookie preferences”, available at the foot of any page, and you may also block or delete cookies through your browser settings.

Necessary cookies are retained for no longer than is required to fulfil their purpose. The cookie recording your decision in respect of this notice is retained for six months, after which you will be asked again.

Children

The service is for professionals and businesses. It is not directed at children and we do not knowingly collect their data. If we find we have received a child's data without the required authorisation, we will delete it.

Changes to this policy

Any change is published on this page, with the update date shown above.

If a change materially affects how we handle your data, we will tell you by email at least 30 days in advance, so you can object or cancel before it takes effect.