Where your business records actually live

Your invoicing app can look like a folder on your laptop while every client name, invoice amount and product record actually lives on computers operated by another company.

That is not automatically bad.

Cloud software solved real problems. It made data available on multiple devices, simplified collaboration and removed a lot of manual syncing.

But “cloud” is a vague word. It can hide the most important question: who actually controls the copy of your business records that the software depends on?

For invoices, quotes and client information, that is worth understanding before you need to recover something.

This article is general information, not legal, privacy, security or tax advice. Data protection and record location requirements can depend on your business and jurisdiction.

What does “in the cloud” actually mean?

It means the data is stored on remote computing infrastructure rather than existing only on the device in front of you.

The infrastructure might be operated directly by the software company or by a large hosting provider on its behalf.

When you sign in to a web invoicing service, your browser is usually requesting data from that remote system. The laptop is the window. The provider’s system is the source of truth.

That arrangement has advantages. You can sign in from another computer and see the same records. The provider can manage server backups, database maintenance and updates.

The tradeoff is dependency.

Your access now depends on the provider’s account system, infrastructure, policies and continued operation.

Can the software company technically access your records?

It depends on the architecture, encryption and provider policies.

In many conventional software-as-a-service systems, the provider operates the application and database infrastructure. That means authorised systems and, in some circumstances, authorised personnel may have technical means to process or access customer data for purposes such as support, security, fraud prevention, legal compliance or service operation.

That does not mean employees are casually reading invoices.

It means “the data is encrypted” and “the provider cannot access the data” are not the same claim.

Encryption in transit protects data as it moves across networks. Encryption at rest protects stored data from certain kinds of unauthorised access. If the service also holds the keys required for normal operation, the service may still be able to decrypt the data when needed.

If provider access matters to you, ask specifically about it.

What should you read in a privacy policy or terms of service?

You do not need to become a lawyer, but look for a few practical answers.

Who is the legal provider?

What categories of data are collected?

Where may the data be processed?

Which service providers or subprocessors are involved?

Why can the provider use the data?

What happens when you close the account?

How long can backups or deleted data remain?

Can you export your records in a useful format?

What happens if the terms change?

How does the provider respond to legal requests?

Do not stop at the marketing page saying “bank-level security.” That phrase does not answer any of those questions.

What happens if a software company is acquired?

Usually, the service does not vanish overnight.

But ownership can change the incentives around a product. Pricing can change. Features can be consolidated. Privacy terms can be updated. A product can be merged into another platform or eventually discontinued.

Business data is valuable partly because it is difficult to move when it has years of history attached.

The safest response is not to predict which companies will be acquired. It is to make sure you can leave.

Can you export invoices? Clients? Products? Reports? Attachments? Are the exports standard formats such as PDF, CSV or Excel, or a proprietary backup that only the original service can read?

Portability is a security feature in the broad sense. It protects you from being trapped by circumstances that have nothing to do with hackers.

What happens to your records if a cloud service shuts down?

The answer depends on the provider and the shutdown.

A responsible service may provide notice and an export period. But your record keeping obligations remain yours.

The CRA explicitly says businesses are responsible for protecting records even when a third party holds them. It also says information held by third parties should be retained by you because those third parties may not keep it for the legally required period.

That is an important point.

Outsourcing storage does not outsource responsibility.

If you need invoices for six years, “the service closed” does not recreate them.

Export important records periodically.

Is local accounting or invoicing data safer than cloud data?

Not automatically.

A local file on one Mac can be extremely private and extremely fragile at the same time.

If the drive fails and there is no backup, local storage has not protected you.

If the Mac is stolen and the disk is not properly secured, local storage may create another problem.

Cloud systems can offer strong redundancy and professional security operations. Local systems can reduce the number of organisations involved in storing your data and give you more direct control.

The useful comparison is not “cloud good” versus “local good.”

It is:

  • Who controls the data?
  • Who can technically access it?
  • How is it protected?
  • How is it backed up?
  • Can you export it?
  • What happens when you stop using the product?
  • What happens when your own hardware fails?

What is the difference between a provider cloud and your own cloud account?

Architecture matters.

One model stores customer records in the software company’s own service.

Another can use a cloud account that belongs to the customer, with the application syncing through that platform rather than creating a separate vendor account and database.

Ledger uses the customer’s own iCloud account for sync. Sync can also be switched off entirely, in which case the records stay on one Mac. There is no separate account and no company server holding the invoicing database.

That does not make backups optional. It changes who sits in the middle of the data path.

If you choose local-only storage, you are taking more direct responsibility for protecting the Mac and its backups.

Does iCloud mean the app company can see the data?

Not simply because an app uses iCloud.

Apple provides developer technologies that let apps store and sync data through iCloud. The privacy and access properties depend on the particular technology and implementation.

The important distinction for a buyer is whether creating an account with the app provider creates another central copy of the business database on that provider’s infrastructure.

Ask the provider what it stores itself, not merely whether the word “iCloud” appears on the feature page.

What questions should you ask any invoicing provider?

You can learn a lot from ten questions:

  1. Where is my primary business data stored?
  2. Do I need an account with you?
  3. Can your staff technically access invoice and client contents?
  4. What third parties store or process the data?
  5. Can I turn cloud sync off?
  6. Can I export invoices as ordinary PDFs?
  7. Can I export structured data such as CSV?
  8. What happens to my data if I cancel?
  9. How long is deleted data retained?
  10. What should I back up myself?

A provider should be able to answer these without hiding behind general security language.

Is a PDF export enough as a backup?

It is a useful archive, but not always a complete backup.

A PDF preserves the human-readable invoice. It may not preserve every relationship in the underlying database, such as product records, client history, payment metadata or editable line items.

Structured exports such as CSV preserve different information but may not reproduce the original document exactly.

A native database backup may preserve the most, but it can be useless if only discontinued software can open it.

That is why layered backups are useful.

Keep human-readable exports for important records. Keep structured exports where available. Keep a system backup. Make sure at least one copy is separate from the computer you use every day.

What does the CRA require if records are electronic?

The CRA says electronic records must remain electronically readable for the required retention period. Businesses are responsible for making records available when requested and for maintaining proper backups.

It also says records generally must be kept at the business or residence in Canada unless permission is given to keep them elsewhere, and notes that records stored outside Canada and merely accessed electronically from Canada are not considered to be kept in Canada.

If your business has a complicated cross-border storage arrangement, get advice specific to your situation.

See what records the CRA expects you to keep for the retention and record-location rules in full.

Privacy architecture and tax record location are related questions, but they are not the same question.

Convenience and control are both real features

Cloud software can be convenient. Local storage can provide control. Your own cloud account can sit somewhere between those models.

There is no reason to turn the choice into a philosophy.

Decide what matters for your business.

If you need a five-person finance team editing the same books, your requirements are different from a freelancer sending 20 invoices a month from a Mac and iPhone.

If you handle sensitive client names, rates or project details, you may care more about reducing the number of systems that hold a copy.

If you travel constantly, access from multiple devices may matter more.

The important thing is knowing the arrangement you are choosing.

Your records should still be yours when the app is gone

The strongest test of a business app is not how easy it is to enter data.

It is whether you can still understand and retain your records if you stop using it.

Know where the data lives. Know who controls access. Export ordinary files. Keep backups. Read enough of the provider’s terms to understand what happens when the relationship ends.

Your invoice history can outlive the software that created it. Plan for that from the beginning.

Sources: Canada Revenue Agency on your responsibilities and the requirements associated with records the law requires you to keep, where to keep your records, for how long, and how to request permission to destroy them early, and electronic record keeping (IC05-1).

← All posts