1. Information We Collect
1.1 Information you provide
- Account profile (name, email, organization, role).
- Authentication identifiers from our identity provider (Clerk).
- Configuration choices you make in the dashboard.
1.2 Information from connected services
When you connect a supported accounting or point-of-sale system, you explicitly authorize DebTera to read data from that system on your behalf. From your point-of-sale system (such as Flowhub) we access sales, order, and end-of-day summary data used for reconciliation and reporting. From QuickBooks Online we may access:
- Company profile — legal name, company name, country, currency.
- Chart of accounts — bank, credit-card, asset, liability, income, and expense accounts; types, subtypes, and current balances.
- Transactions — purchases, deposits, payments, bill payments, transfers, and journal entries, including amount, date, account, vendor, customer, and memo data.
- Reports— the standard Profit & Loss, Balance Sheet, and Cash Flow reports for analytical purposes.
1.3 Automatically collected information
- Standard server logs (IP address, user agent, request path, timestamps).
- Service health and performance telemetry.
2. How We Use Information
We use the information we collect to:
- Provide reconciliation, analytics, reporting, and business-insight features.
- Compute revenue, expense, cash-flow, and financial-health metrics.
- Detect duplicate or unusual entries and surface reconciliation issues.
- Authenticate users, secure the service, and prevent abuse.
- Communicate with you about service changes and support.
3. How We Store and Protect Information
- Data is stored in our managed database hosted by Supabase, with row-level security enforcing tenant isolation by organization.
- OAuth access and refresh tokens for connected services are encrypted at rest with AES-256 authenticated encryption, using a key held only on our application servers.
- All data in transit uses TLS.
- Access to production systems is restricted to authorized personnel.
5. Data Retention
We retain connection data and synced QuickBooks data for as long as your DebTera account is active or as needed to provide the service. When you disconnect QuickBooks, we revoke our refresh token with Intuit and delete the encrypted access and refresh tokens from our database. Upon written request to privacy@debtera.com, we will delete synced QuickBooks data associated with your account within 30 days, except where we are required to retain it by law.
6. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal information. To exercise these rights, email privacy@debtera.com. We will respond within a reasonable time and at no cost, except where allowed by applicable law.
DebTera is a business tool for licensed retail operators, is not directed at children, and does not knowingly collect information from anyone under 18.
7. International Transfers
We process data in the United States. If you access DebTera from outside the U.S., you consent to the transfer and processing of your data in the U.S.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by email or by a prominent notice in the dashboard before they take effect.