Privacy Policy
Last updated: August 2026
Plain-language summary
What data we collect
Account info (email, name, company, QuickBooks version, designer count), conversion data (XML files you upload, SKU mappings you create, conversion history), usage data (logins, page views).
What we do with it
Provide the service. Improve the product. Communicate with you. Never sold, never shared with third parties (except as required by law).
Who we share it with
Supabase and Fly.io (infrastructure), Intuit (your QuickBooks connection, at your direction), Resend (transactional email), Stripe (payments — when applicable). No advertising networks, no analytics resellers, no data brokers.
Your rights
Access, correct, delete your data anytime. Export your data anytime. Cancel anytime.
Full legal text
Collection of Information
We collect: (a) Account information you provide — name, email, company, QuickBooks version, team size; (b) Customer Data you upload or create — design export files (XML/CSV), SKU mappings, conversion history and results; (c) QuickBooks connection data — when you authorize the connection through Intuit's sign-in, we receive access tokens (never your Intuit password) and, during conversions, the specific QuickBooks records needed to complete them (such as customer names, item names, and document numbers); (d) Usage and log data — sign-ins, feature usage, and technical logs including an audit trail of every use of your QuickBooks connection; and (e) Communications you send us.
Use of Information
We use information to: provide, operate, and secure the Service; run the conversions you request; prevent duplicate postings and errors; provide support; send transactional and service communications; improve the product; and comply with law. We do not sell personal information, and we do not use your Customer Data for advertising or to train third-party models.
Your QuickBooks Data
The Service accesses your QuickBooks only through Intuit's authorized connection (OAuth), scoped to accounting data. We perform targeted lookups needed for a conversion and create the documents you request (estimates and invoices); we do not bulk-export or warehouse your accounting records. Connection tokens are encrypted with per-credential keys and every use of your connection is recorded in an audit log. You can revoke the connection at any time from QuickBooks or your KitchenAPI settings, which immediately disables our access.
Sharing of Information
We share information only with: (a) Service providers that host and operate the Service under contractual confidentiality — currently Supabase and Fly.io (cloud infrastructure, United States), Resend (transactional email), Google Workspace (business email), and, when online payments are offered, Stripe (payment processing); (b) Intuit, to operate the QuickBooks connection you authorize; (c) Professional advisors and authorities where required by law, to protect rights and safety, or to enforce our terms; and (d) A successor in a merger, acquisition, or asset sale, subject to this policy. We do not share data with advertising networks, analytics resellers, or data brokers.
Cookies
We use only the cookies and similar technologies necessary to operate the Service — session authentication and security. We do not use third-party advertising or cross-site tracking cookies. Your browser can block cookies, but signed-in features require them.
Data Retention and Your Rights
We retain account and Customer Data while your account is active. You may access, correct, export, or delete your data at any time from within the Service or by contacting privacy@kitchenapi.com; account deletion removes Customer Data within 30 days, except audit and security logs and records we must keep for legal or accounting purposes, which are retained for a limited period and then deleted. If you are in a jurisdiction with statutory privacy rights (such as the EEA, UK, or California), you may exercise those rights — including access, correction, deletion, and portability — through the same contact, and we will not discriminate against you for doing so.
Children's Privacy
The Service is a business tool not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact privacy@kitchenapi.com and we will delete it.
International Data Transfers
The Service is hosted in the United States. If you use it from outside the U.S., you understand that your information is processed and stored in the U.S., where privacy laws may differ from those of your jurisdiction.
Security
We protect information with industry-standard measures, including encryption in transit (TLS) and at rest, per-credential envelope encryption for QuickBooks connection tokens, tenant isolation, least-privilege access controls, and audit logging. No method of transmission or storage is completely secure; we will notify affected customers of any breach as required by law. Details for technical audiences are on our Security page.
Changes to This Policy
We may update this policy from time to time. Material changes will be announced by email or in-product notice before taking effect, and the "Last updated" date will change.
Contact Us
Privacy questions or data requests: privacy@kitchenapi.com
Privacy concerns or data subject requests: privacy@kitchenapi.com