Legal

Privacy notice

This notice explains what Tally collects, why, and what you can ask us to do with it. Last reviewed 2 August 2026.

Draft pending legal review. The operating entity, registered address and governing jurisdiction for Tally have not been finalised, so they are deliberately left blank rather than invented. This notice will be republished with those details and a named data-protection contact before Tally accepts paying customers.

What we collect

Two categories, kept separate.

Marketing enquiries. If you submit the early-access or sales form we store the name, email address, band or company name, plan interest, approximate shows per year, any message you write, the page you submitted from, your browser user-agent string, and a one-way hash of your IP address used solely for rate limiting. The raw IP address is not stored.

Account and financial records. If you go on to use Tally, we store what you enter: gigs, income, expenses, receipts you upload, people you add, the amounts owed and paid, and the roles you assign. We also store your email address, a hashed password, and — if you turn it on — a two-factor authentication secret.

Tally does not store payment-card details. Card data is handled by Stripe and never reaches Tally's servers.

How we use it

To operate the product, to reply to you, to keep your account secure, and to bill you if you are on a paid plan. We do not sell your data, we do not share it with advertisers, and we do not use band financial records to train machine-learning models.

Who can see it

Inside your band, visibility follows the role you assign. An owner or finance manager sees everything; a performer sees their own pay and receipts; an accountant granted reports-only access sees reports and nothing else.

Outside your band, records are handled by the service providers that run Tally — hosting, database, email delivery, and Stripe for payments. Each processes data only to provide its service.

TODO (owner): publish the named list of sub-processors and their locations before general availability.

Security

Every connection to Tally is encrypted in transit using TLS. Passwords are stored hashed, never in plain text. Two-factor sign-in is available on every account. Access inside the product is enforced by role on the server, not only in the interface.

TODO (owner): Tally makes no claim of encryption at rest, and holds no SOC 2, ISO 27001, PCI or GDPR certification. Do not add such claims to this site until they are independently verified.

Retention and deletion

If you cancel a paid plan, your account reverts to Free limits at the end of the billing period. Your existing records are not deleted, and CSV export remains available on every plan so you can take your books with you.

Marketing enquiries are kept until you ask us to remove them. To delete an account and its records, write to us and we will confirm before anything is removed.

Your choices

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Every report and ledger in Tally can also be exported to CSV at any time without asking.

Contact

Privacy questions: privacy@tally.band. Anything else: hello@tally.band.