Privacy Policy
Effective August 28, 2026
This policy describes how Sherpa Data LLC ("Sherpa Data," "we," "us") handles information in connection with our analytics platform for property managers (the "Service"). It covers visitors to sherpadata.io and customers of the Service.
1. Information we collect
Account information — name, email, company, and billing details when you create an account or subscribe.
Data from services you connect — when you authorize a connection to a third-party platform (a property-management system, a payment processor, or an accounting platform such as QuickBooks Online), we retrieve the data needed to produce your reports: bookings, transactions, accounts, classes, and related records. We access only what the integration requires.
Usage data — standard logs (IP address, browser, pages viewed) and limited analytics used to operate and improve the Service.
2. How we use information
We use your information solely to provide, secure, support, and improve the Service — rendering your dashboards and reports, syncing your connected accounts, billing, and customer support. We do not sell your data. We do not use your business data for advertising, and we do not share it with third parties except the service providers below or as required by law.
3. QuickBooks Online and other connected accounts
Connections to QuickBooks Online use Intuit's OAuth authorization — you sign in with Intuit and grant access; we never see or store your QuickBooks password. The resulting access credentials (OAuth tokens) are encrypted at rest. Retrieved accounting data is stored with per-customer isolation enforced by database row-level security, so each customer's data is readable only within their own tenancy.
You can disconnect QuickBooks (or any connected service) at any time from within Sherpa Data or from the provider's own app-access settings. Disconnecting revokes our access and stops all further retrieval. On written request after disconnection, we will delete the previously retrieved data for that connection.
4. Service providers
We use a small set of subprocessors to run the Service: cloud hosting and managed PostgreSQL (Render, United States), content delivery (Cloudflare), payment processing (Stripe), email delivery, and CRM/support tooling. Each processes data only as needed to provide their service to us.
5. Data retention
We retain Customer Data for as long as your account is active. After termination, we provide a data export on request within 30 days, after which data may be deleted from active systems; residual copies in encrypted backups expire on the backup rotation schedule.
6. Security
Safeguards include TLS encryption in transit, encryption of integration credentials at rest, per-tenant row-level security at the database layer, least-privilege access controls, and audit logging. No method of transmission or storage is 100% secure; we will notify affected customers of a breach as required by law.
7. Your rights
You may access, correct, export, or delete your personal information by contacting us. Depending on your jurisdiction, you may have additional statutory rights; we honor verified requests consistent with applicable law.
8. Cookies
The Service uses cookies for authentication and session management. The marketing site uses limited analytics cookies. We do not use cross-site advertising trackers.
9. Children
The Service is for business use and not directed to children under 16; we do not knowingly collect their information.
10. Changes
We may update this policy; material changes will be announced via the Service or email before taking effect, with the effective date updated above.
Contact
Sherpa Data LLC · [email protected]