Privacy Policy

Last Updated: March 30, 2026

1. Information We Collect

1.1 Information You Provide

  • Account information: name, email address, password
  • Company information: business name, industry, location
  • Payment information: processed securely through Stripe (we do not store credit card details)

1.2 Information from Connected Services

When you connect QuickBooks, Xero, or FreshBooks via OAuth, we REQUEST permission to access the following data from your accounting platform:

  • Financial transactions and account balances
  • Customer and vendor information
  • Invoice and payment data
  • Profit & loss statements
  • Cash flow information

Current Implementation: While we request these OAuth permissions during connection, the financial data displayed in your dashboard is currently simulated for demonstration purposes. We store your OAuth connection tokens securely in our database (encrypted at rest) to prepare for real-time data integration, which is in active development. Your actual financial data from QuickBooks/Xero/FreshBooks is not yet being retrieved or stored.

We store OAuth connection details in our database, including:

  • Access tokens and refresh tokens (encrypted)
  • Company/organization ID from your accounting platform
  • Company name
  • Connection status and last sync timestamp

1.3 Automatically Collected Information

  • Usage data: pages visited, features used, time spent
  • Device information: browser type, IP address, operating system
  • Cookies and similar technologies for authentication and analytics

2. How We Use Your Information

We use collected information to:

  • Generate financial health scores and AI-powered reports
  • Send monthly email summaries and alerts
  • Process payments and manage subscriptions
  • Improve and personalize the Service
  • Provide customer support
  • Send important service updates (you can opt out of marketing emails)
  • Detect and prevent fraud or security issues

3. How We Share Your Information

We share your information only in these limited circumstances:

3.1 With Your Accountant

If you were referred by an accountant, they can view your health scores and reports through their dashboard to better serve you. They cannot access your raw financial data.

3.2 Service Providers

We share data with trusted third parties who help us operate:

  • Stripe (payment processing)
  • SendGrid (email delivery)
  • Anthropic Claude API (AI report generation)
  • Supabase (database hosting)
  • Vercel (application hosting)

3.3 Legal Requirements

We may disclose information if required by law, court order, or government request, or to protect our rights and safety.

3.4 Business Transfers

If ProfitRunway is acquired or merged, your information may be transferred to the new owner.

4. Data Security

We protect your information using:

  • Encryption in transit (HTTPS/TLS) and at rest
  • Secure OAuth authentication (no password storage for accounting platforms)
  • Regular security audits and monitoring
  • Access controls and employee training
  • Secure cloud infrastructure (Vercel, Supabase)

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain your information for as long as your account is active or as needed to provide services. After account deletion, we may retain certain data for legal compliance, dispute resolution, and fraud prevention for up to 7 years.

6. Your Rights and Choices

You have the right to:

  • Access and download your data
  • Correct inaccurate information
  • Delete your account and data
  • Opt out of marketing emails (account emails still required)
  • Disconnect accounting platform integrations
  • Export your reports and data

To exercise these rights, contact us at privacy@getprofitrunway.com

7. Cookies and Tracking

We use cookies for:

  • Authentication and session management
  • Remembering your preferences
  • Analytics (via PostHog) - you can opt out

You can control cookies through your browser settings, but some features may not work without them.

8. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies.

9. Children's Privacy

ProfitRunway is not intended for users under 18. We do not knowingly collect information from children. If you believe we have collected data from a child, contact us immediately.

10. International Data Transfers

Your data may be transferred to and processed in the United States or other countries where our service providers operate. By using the Service, you consent to these transfers.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights:

  • Right to know what personal information we collect and how we use it
  • Right to delete your personal information
  • Right to opt out of sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your rights

To exercise these rights, email privacy@getprofitrunway.com

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or prominent notice on the Service. Your continued use after changes constitutes acceptance.

13. Contact Us

For questions or concerns about this Privacy Policy or our data practices:

Email: privacy@getprofitrunway.com

Support: support@getprofitrunway.com

Website: https://getprofitrunway.com