Midwood Money — Privacy, Data Retention & Security Policy
Operator: NJH Supply LLC (d/b/a Midwood Soles), 23 Longview Ave, Madison, NJ 07940 · Effective 9/5/2026 · Reviewed annually
1. What Midwood Money is
Midwood Money is an internal bookkeeping application operated by NJH Supply LLC for its own business. It connects the company's own business bank and credit card accounts, through Plaid, to reconcile bank deposits against marketplace payouts and to categorize business expenses. It is not offered to the public. The only users are the owner and authorized staff of NJH Supply LLC. The application is read-only: it never initiates payments, transfers, or any other money movement.
2. Data we collect
- Account and transaction data for NJH Supply LLC's own financial accounts, obtained through Plaid with the account holder's consent given in Plaid Link: account names, masked account numbers, balances, transaction dates, amounts, merchant descriptors, and categories.
- Plaid access tokens that allow the application to refresh transaction data.
- Bookkeeping annotations entered by our staff (classifications, notes, purchase-order links).
We never receive or store bank login credentials. Authentication with the financial institution is performed by Plaid and, for OAuth institutions, by the institution itself.
3. How we use it
Solely for NJH Supply LLC's internal accounting: reconciling payouts, categorizing expenses, tracking purchase orders and loans, and producing reports for our accountant. We do not sell, rent, share, or use financial data for advertising, and we do not share it with any third party other than our infrastructure providers (Plaid, and our hosting provider Railway) as needed to run the application, and our accountant as needed to prepare our books and taxes.
4. Consent
Every account connection is authorized by an owner of NJH Supply LLC through Plaid Link, which presents Plaid's End User Privacy Policy and the institution's own consent screens. Consent can be withdrawn at any time by disconnecting the account in the application, or through the Plaid Portal at my.plaid.com.
5. Data retention and deletion
- Transaction and account data is retained for seven years from the transaction date, matching IRS business-record retention guidance, then deleted.
- When an account is disconnected, its Plaid access token is revoked with Plaid (
/item/remove) and deleted from our systems immediately. Previously synced transactions remain in the ledger only as accounting records subject to the seven-year schedule.
- Data may be deleted sooner on request of the account holder by emailing the contact below. Requests are honored within 30 days.
- This policy is reviewed at least annually and whenever the application's data handling changes.
6. Security
- Encryption in transit: all traffic uses HTTPS with TLS 1.2 or higher.
- Encryption at rest: Plaid access tokens are encrypted at the application layer with AES-256-GCM before storage. The database runs on Railway, whose persistent storage is encrypted at rest.
- Access control: access requires authentication through Midwood's single sign-on with role-based permissions. Only the owner and explicitly authorized staff hold the bookkeeping role. Access is granted and revoked by the owner in the ops-portal user management screen.
- Least privilege: the application requests only Plaid's Transactions product, and has no ability to move money.
- Secrets: API credentials live only in the hosting provider's encrypted environment configuration, never in source code.
- Patching: dependencies are updated with each deployment; the hosting platform maintains the underlying operating system and runtime images.
- Incident response: if a compromise of financial data is suspected, we will rotate all credentials, revoke Plaid access tokens, notify Plaid, and notify the account holder within 72 hours.
7. Contact
Information security and privacy contact: Tyler Cobb, Owner, NJH Supply LLC — info@njhsupplyllc.com.