Data Privacy Agreement

SteepDesk Data Privacy & Sharing Agreement

This agreement governs how SteepDesk, LLC ("SteepDesk," "we," "us") collects, accesses, uses, stores, and protects the data your business ("Partner," "you") shares with the SteepDesk platform. We never sell your data or use it for anything other than building, operating, and improving SteepDesk.

Effective July 13, 2026. Version 2026-07-13.

How this agreement is accepted

You accept this agreement by clicking to accept it inside the SteepDesk platform. That acceptance is a valid and binding signature for all purposes (Section 10.7). By accepting, you represent that you have the authority to enter into this agreement on behalf of the business you represent, and to grant SteepDesk access to the accounts you connect. This agreement governs data privacy and sharing only; it does not replace the Terms of Service or Privacy Policy, which apply alongside it.

Article I. Definitions

  • Partner Data, all data SteepDesk accesses from your Connected Accounts or that you enter into the platform, including transactions, sales, revenue, expenses, supplier invoices, and inventory and operational data. Partner Data does not include Aggregated Data.
  • Aggregated Data, data derived from Partner Data that we have de-identified using commercially reasonable methods and combined with other sources so that it cannot readily be attributed to you. We will not publish benchmark outputs from a sample so small that your figures could be reasonably back-derived.
  • Connected Account, any third-party account (such as Square or QuickBooks) you connect to SteepDesk through an authorized API integration.
  • Authorized Personnel. SteepDesk employees, contractors, and co-founders who need access to Partner Data to operate the platform and are bound by confidentiality obligations at least as protective as this agreement.
  • Controller / Processor, you are the Data Controller of your business data. SteepDesk acts as your Data Processor for the operations in Section 3.1, and as an independent controller for its own product-development and Aggregated-Data use under Sections 3.1(b) and 3.3.
  • Data Breach, any unauthorized access, disclosure, alteration, or destruction of Partner Data that compromises its confidentiality, integrity, or availability.

Article II. Data collected and sources

2.1 Categories. By connecting your accounts and using SteepDesk, you authorize us to access and process:

  • Square POS, transaction data (sales by item, payment method, timestamps, refunds, discounts, tips), operational data (order volume, product mix), and catalog/inventory data (item names, pricing, images, and inventory counts if enabled).
  • QuickBooks Online, financial data (revenue, cost of goods sold, margin, expenses, net income), supplier and invoice data (vendor names, bill amounts, payment status, due dates), and account data (chart of accounts, references, balances).
  • SteepDesk platform, usage and interaction data (orders placed, roaster selections, feature usage, session logs) and feedback data (in-app feedback, support communications, surveys).

2.2 Access scope (read and write).

  • Square, read only. We read catalog, order, payment, and (if enabled) inventory data. We do not create, modify, or delete records in your Square account. Our Square authorization may include an inventory-write permission reserved for a future sync feature; that feature is not enabled, and we will not write to your Square account without first enabling it and giving you notice and the ability to opt out.
  • QuickBooks, read and limited write. We read accounting data (chart of accounts, vendors, bills, balances). When you place or receive an order through SteepDesk, we may write order-derived records into your QuickBooks, specifically, create a Bill for the order and create a Vendor record for a supplier that does not already exist by name, so your books stay in sync. The bill-push is idempotent and will not duplicate a Bill for the same order. We do not modify or delete your pre-existing QuickBooks records, and you may disable the write-back or disconnect QuickBooks at any time (Section 5.3).
  • Your control.You retain full control of your Square and QuickBooks accounts and may revoke our access at any time through those platforms' settings or by notifying us.

2.3 Data we do not collect.We do not access your customers' personally identifiable information (names, emails, phone numbers, or card numbers), nor employee payroll or individual compensation data from your Connected Accounts. OAuth tokens and API credentials are stored encrypted at rest, restricted to Authorized Personnel, and never exposed in the interface or logs.

2.4 Third-party API terms.Your use of Square and QuickBooks is governed by their own terms. We access Connected Account data only within the scope of the permissions you grant through each platform's OAuth authorization flow.

Article III. Purpose and permitted use

3.1 Permitted purposes. We access and process Partner Data solely to: (a) operate and provide the platform and its features; (b) analyze usage to improve the product, fix bugs, and prioritize features; (c) generate dashboards and insights for your own use from your own data; (d) diagnose and resolve technical issues you report; and (e) monitor for unauthorized access and security incidents. Uses under (b) and Section 3.3 are our controller purposes.

3.2 Strictly prohibited uses. We will never: sell, license, rent, or transfer Partner Data to any third party for commercial gain; use it to market third-party products; share it with your competitors, suppliers, or roasters without your written consent; use it to make credit, insurance, employment, or eligibility determinations about you; build profiles about you for external sale; or train AI/ML models on identified Partner Data without your written consent. We may use Aggregated, de-identified data for model training.

3.3 Aggregated Data. We may use Aggregated Data to improve the platform, develop industry benchmarks, and produce general insights, acting as a controller for such use. We will not attempt to re-identify it and will apply the small-sample limitation above.

Plain-language summary: We use your data to build and run the platform for you. We read from Square and QuickBooks, and we write order-based bills and vendors into your QuickBooks so your books stay in sync, you can turn that off. Your data is never sold, shared with competitors, or used for advertising. We may use fully de-identified industry data to improve the product for everyone.

Article IV. Data protection and security

4.1 Security standards. We implement and maintain reasonable and appropriate technical and organizational measures, including at minimum: encryption of Partner Data in transit via TLS 1.2 or higher; encryption of integration OAuth tokens and API credentials at rest at the application layer using AES-256-GCM; encryption at rest at the infrastructure layer via our SOC 2-compliant database and hosting providers; role-based access controls enforced through application permissions and database row-level security; storage of credentials in encrypted form, never exposed in the interface or logs; and regular security reviews of our infrastructure and data-access logs.

4.2 Access controls and logging. Access to Partner Data is limited to Authorized Personnel who need it. We maintain automated audit logs of changes to Partner Data through the platform and of programmatic (API and connector) calls. On written request, no more than once per calendar year, we will provide a summary derived from these logs.

4.3 Subprocessors. We may engage subprocessors to help process Partner Data, each bound by obligations at least as protective as this agreement, and we remain responsible for their acts and omissions. Current subprocessors include Supabase (database and hosting), Vercel (application hosting), Resend (email), Stripe (billing), and Sentry (error monitoring); Anthropic when you use the Claude connector; and Square and Intuit (QuickBooks) if you connect them. We will notify you of material subprocessor changes affecting Partner Data within thirty (30) days.

4.4 Data breach notification. On a confirmed or reasonably suspected Data Breach involving Partner Data, we will notify you in writing within seventy-two (72) hours of becoming aware, to the extent practicable, describing the nature of the breach, the data affected, likely consequences, and our remediation; cooperate in investigating it; and take prompt action to contain and prevent recurrence.

4.5 No sale of data. We will never sell, rent, license, or transfer Partner Data to any third party for consideration. This prohibition is absolute and survives termination.

Article V. Your rights

  • Access & portability. Request a copy of your Partner Data, or an export on termination, in a machine-readable format (CSV or JSON) within thirty (30) days, at no charge.
  • Correction. Request correction of inaccurate data; we will correct or delete it within thirty (30) days where technically feasible.
  • Revoke access. Revoke our access to any Connected Account at any time through Square/QuickBooks settings or by notifying us. On a disconnect request we will, on a best-efforts basis, revoke our access token with the provider and confirm within two (2) business days. Revoking access does not by itself delete data already collected (see deletion).
  • Deletion. On written request we will delete all Partner Data from active systems within thirty (30) days and revoke any tokens we still hold, except data we must retain by law, Aggregated Data that cannot be traced to you, and backups (deleted within ninety (90) days in the ordinary backup-rotation cycle). We confirm deletion in writing.
  • Audit. No more than once per calendar year, request a written summary of the categories of Partner Data we hold, the subprocessors with access, and the security measures in place; we respond within thirty (30) days.

Article VI. Retention and deletion

During the term we retain Partner Data as long as necessary to provide the platform and fulfill the permitted purposes. After termination we retain Partner Data for ninety (90) days so you can export it, then permanently delete it from active systems and revoke any tokens we still hold (unless you requested deletion earlier). Backups are deleted within ninety (90) days of termination in the ordinary rotation cycle. We may retain Aggregated Data indefinitely, as it cannot identify you. We confirm deletion in writing on completion.

Article VII. Confidentiality

Each party holds the other's confidential information in confidence and will not disclose it without consent, except as required by law. Your Partner Data is our confidential information; our platform technology, roadmap, and business information are yours to keep confidential. If we are legally compelled to disclose Partner Data, we will notify you in advance where permitted, cooperate in seeking protective relief, and disclose only the minimum required. These obligations survive termination for three (3) years, and indefinitely for trade secrets.

Article VIII. Representations and warranties

SteepDesk represents that it has authority to enter this agreement; will access and process Partner Data only as described here; will maintain the Article IV security measures; will never sell Partner Data; and that its access to your Square and QuickBooks accounts is within the OAuth permissions you grant (read access to both, plus the limited QuickBooks write in Section 2.2).

You represent that you have authority to enter this agreement and connect the accounts; that you have the right to share the Partner Data for these purposes without violating law or third-party agreements; and that you will promptly notify us of any unauthorized access to your Connected Accounts.

Article IX. Term and termination

This agreement starts on your acceptance and continues until terminated. Either party may terminate on thirty (30) days' written notice, or immediately for an uncured material breach after fifteen (15) days' notice. On termination, your license to use the platform ends, our right to access your Connected Accounts ends immediately, and retention and deletion proceed under Article VI. Articles IV, V, VI, VII, VIII, and X survive termination.

Article X. General provisions

  • 10.1 Limitation of liability. To the maximum extent permitted by law, our total liability arising out of this agreement will not exceed the fees you paid us in the twelve (12) months before the claim. This cap does not apply to unauthorized sale of Partner Data, gross negligence, or willful misconduct.
  • 10.2 Governing law. Texas law governs, without regard to conflict-of-law principles. Disputes are resolved by binding arbitration in Austin, Texas under AAA rules, except that either party may seek injunctive relief in court for a breach of confidentiality or data-protection obligations.
  • 10.3 Amendments.We may update these terms on thirty (30) days' notice of material changes. For click-to-accept agreements, your continued use after notice, or your acceptance of the updated version when prompted, constitutes acceptance.
  • 10.4 Entire agreement. This is the entire agreement on data privacy and sharing and supersedes prior understandings on that subject. It does not supersede separate subscription or platform terms.
  • 10.5 Severability & 10.8 No waiver. If any provision is unenforceable, the rest remain in effect, and a failure to enforce any provision is not a waiver of it.
  • 10.7 Electronic acceptance. Click-to-accept acceptance through the SteepDesk platform is a valid and binding signature for all purposes.

Contact

Questions about this agreement or your data? Email privacy@steepdesk.com. For security reports, use security@steepdesk.com.