TrippMetric

Privacy policy

Richard Tripp operates TrippMetric. This policy describes information handled through our public website, beta application, connected accounting and CRM systems, and support. Contact legal@trippmetric.com about privacy, data access, or deletion, and support@trippmetric.com for technical help.

If an alias is unavailable while email is being configured, contact richard@trippmetric.com.

Information we receive

Account and workspace information includes your name, email address, authentication identifiers, organization, and workspace role. Beta applications can include business contact details and information about your reporting needs and software. Uploaded files and authorized integrations can include customer names and identifiers, transaction dates and amounts, receipts, payments, refunds, credits, linked transaction references, and CRM fields used in reports. We also receive technical information needed to operate the service, such as request timestamps, browser and device information, diagnostic error codes, and integration support identifiers.

How we use information

We use information to authenticate users, manage authorized workspaces, retrieve connected records, prepare revenue and customer reports, respond to support and beta applications, diagnose failures, prevent misuse, and meet legal obligations. We do not sell customer accounting data or use it for advertising. Reports are based on the source records and analysis settings available to the application.

QuickBooks authorization

You authorize access on Intuit's own sign-in and consent pages. TrippMetric does not ask you to give us your QuickBooks password. The application requests QuickBooks Accounting access for reporting; it does not use the QuickBooks Payments API to process card charges. OAuth access tokens are encrypted while cached in server memory, and refresh tokens are encrypted before persistent storage. Token plaintext is used only where needed to communicate with Intuit. Credentials and raw accounting responses are excluded from our diagnostic log exports.

Beta preparation and local copies

During the beta, Richard Tripp or an analyst you authorize may retrieve and process your connected data in a local development environment to prepare your reports. Imported records, reports, and authorized exports may therefore exist on the analyst's computer as well as in the hosted application. A request to delete your data covers these managed copies, subject to the retention and verification provisions below.

Service providers and sharing

We use Vercel for hosting, Clerk for authentication and account management, and Neon PostgreSQL for application storage. Public blog articles are available to all visitors. Account requests and unpublished drafts are restricted to authorized users. Connected platforms process authorization and API requests under their own terms. These providers may process information in countries other than your own. We may disclose information when required by law, to address fraud or security issues, or as part of a business transfer with appropriate notice and protections.

Cookies, analytics, and browser storage

Authentication services use cookies and similar technologies to maintain sign-in and protect accounts. The application uses browser storage for interface preferences and selected report state. You can use browser controls to limit these technologies; doing so may affect sign-in or other features.

Security and diagnostics

We use access controls, HTTPS on the public service, and token encryption to protect connected accounts. No system can guarantee complete security. Diagnostic information is recorded in server logs; workspace-related errors can also be retained in a workspace audit log. Workspace owners can download recent diagnostic events for troubleshooting and choose whether to share them with support. These exports contain safe error descriptions, timestamps, error codes, stack locations, and Intuit transaction identifiers where available, rather than credentials or raw financial records.

Retention, disconnection, and deletion

We retain account information, imported records, reports, and diagnostic events while needed to provide and administer the beta, resolve issues, or comply with legal obligations, until removed through account deletion or service administration. We have not established a fixed automatic deletion period for every category. You can disconnect QuickBooks to stop future access. Disconnection does not automatically delete previously imported records. Email legal@trippmetric.com to request access, correction, export, or deletion of information we control. We will verify your identity and authority, explain any limits, and coordinate removal of managed local copies. Backups or records required for legal and security purposes may remain for a limited period.

Your choices and other people in your data

You choose whether to apply for the beta, upload a file, connect a service, or authorize workspace users. Follow the connected platform's controls to revoke access. Depending on applicable law, you may have additional rights to access, correct, delete, or restrict processing of personal information. If you provide information about customers or colleagues, you are responsible for having authority and providing any notices required for that sharing. The service is intended for business use and is not directed to children under 18.

Changes and contact

We will update this policy as the service evolves and identify the current revision above. Material changes will be communicated through the service or an available account contact. Questions and privacy requests can be sent to Richard Tripp at legal@trippmetric.com.