This Privacy Policy explains how RavenDash, operated by Michael Reynolds LLC (“RavenDash,” “we,” “us”), collects, uses, stores, and protects information when you use the Service. RavenDash is used by accounting professionals to create live financial dashboards for their clients from QuickBooks Online data.
1. Information we collect
Account information
When you create an account, we collect your email address and a password (stored only as a secure hash, never in plain text). You may optionally provide your firm name, a logo, and a brand color.
Client information
For each client dashboard you create, we store the client business name you enter and a unique share token used to generate the dashboard’s private link.
QuickBooks connection data
When you connect a client’s QuickBooks Online company, we store that company’s Intuit company identifier (“realm ID”) and the OAuth access and refresh tokens Intuit issues. These tokens are encrypted at rest using symmetric encryption; the encryption key is held separately from the database.
Financial data
Financial figures shown in dashboards (revenue, expenses, cash flow, and similar reports) are fetched live from QuickBooks Online each time a dashboard is viewed. RavenDash does not store your clients’ financial records in its own database.
2. How we use information
- To authenticate you and operate your account;
- To connect to QuickBooks Online on your behalf and display dashboards;
- To apply your firm’s branding to the dashboards your clients see;
- To maintain the security and reliability of the Service;
- To communicate with you about the Service.
We do not sell your information or your clients’ information, and we do not use it for advertising.
3. How we store and protect information
Data is stored using Supabase (database, authentication, and file storage) and the Service is hosted on Vercel. QuickBooks access and refresh tokens are encrypted before they are written to the database. Access to client data is restricted by row-level security so that each account can only reach its own records. We use industry-standard measures to protect information, though no method of transmission or storage is completely secure.
4. Third-party services
We rely on the following service providers to operate RavenDash:
- Intuit — provides QuickBooks Online data via its API. Your use of QuickBooks data is also governed by Intuit’s privacy policy and terms.
- Supabase — database, authentication, and storage of your account data, client records, and encrypted tokens.
- Vercel — application hosting and delivery.
5. QuickBooks data handling
We access QuickBooks Online data only with your authorization, only for the purpose of displaying dashboards within the Service, and only for the QuickBooks companies you explicitly connect. We do not write to or modify QuickBooks records. You may revoke RavenDash’s access to any connected company at any time, either from within RavenDash (Disconnect) or from within QuickBooks Online. When access is revoked, the associated tokens are deleted from our database.
6. Sharing and share links
A client dashboard is reachable by anyone who has its unique share link. You control who receives that link. You can pause sharing or regenerate the link at any time, which immediately invalidates the previous URL. We do not share dashboard links or their contents with anyone other than as directed by you.
7. Data retention
We retain your account information, client records, and connection data for as long as your account is active. When you delete a client, disconnect a QuickBooks company, or close your account, the associated records and tokens are deleted from our systems. Backups, if any, are purged on a rolling basis.
8. Your rights and choices
You can access and update your account information and branding at any time from the Settings page. You can delete individual client records and QuickBooks connections from within the Service. To request deletion of your entire account, contact us at the address below. Depending on your location, you may have additional rights regarding your personal data; we will honor applicable requests.
9. Children’s privacy
The Service is intended for accounting professionals and is not directed to anyone under 18. We do not knowingly collect information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date and, where appropriate, communicated to you directly.
11. Contact
For privacy questions or requests, contact us at support@ravendash.app.