Revenue Autopilot

Privacy Policy

This Privacy Policy describes how Clear Garment Group (“Company,” “we,” or “us”) collects, uses, and protects information when you use Revenue Autopilot (“Service”). We are committed to transparency about our data practices and to giving you meaningful control over your information. Last updated: April 2026.

This Privacy Policy is provided for informational purposes and to satisfy third-party integration requirements, including Intuit’s QuickBooks API production access criteria. It should be reviewed by qualified legal counsel before reliance for any specific legal or compliance purpose.

1. Information we collect

Account information

When you create a workspace we collect your name, business email address, company name, and subscription details. We also collect authentication credentials (managed via Supabase Auth) and, where enabled, multi-factor authentication configuration.

Accounting data via OAuth

When you connect an accounting provider (QuickBooks, Xero, FreshBooks) via OAuth 2.0, we receive an access token and, where applicable, a refresh token scoped to the permissions you approve. We use these tokens to read and sync invoices, customers, and payment records as required by the features you enable.

Payment information

Subscription payments are processed by Stripe. We store only non-sensitive payment references (Stripe customer ID, subscription ID, last-four card digits, and billing status). We do not store full card numbers, CVV codes, or bank account details.

2. How we use your information

We use information collected through the Service exclusively to:

  • — Operate invoice tracking and accounts receivable workflows
  • — Synchronize data with connected accounting providers you have authorized
  • — Execute payment reconciliation and dunning automation sequences
  • — Manage your subscription and process billing
  • — Send transactional communications (invoice reminders, payment confirmations, account notices)
  • — Provide customer support and respond to your inquiries
  • — Maintain platform security, detect fraud, and comply with legal obligations
  • — Improve the Service through aggregated, de-identified usage analytics

We do not use your accounting data for advertising, profiling, or any purpose beyond delivering the specific features you have activated.

3. Data storage & security

Your data is stored in Supabase, a managed PostgreSQL platform with enterprise-grade security controls. We enforce the following safeguards:

  • — Encryption at rest (AES-256) for all stored data
  • — Encryption in transit (TLS 1.2 or higher) for all data transfers
  • — Row-level security (RLS) policies restricting data access to authorized workspace operators
  • — OAuth tokens stored encrypted and never exposed in plaintext
  • — Multi-factor authentication enforced at the platform level
  • — Access to production data limited to authorized personnel on a need-to-know basis

No security measure is perfect. In the event of a data breach affecting your personal information, we will notify affected users and, where required by GDPR Article 33, the relevant supervisory authority within 72 hours of becoming aware of the breach.

4. Third-party sharing

We share your information only with the following categories of parties:

  • Accounting providers — Data is transmitted to QuickBooks, Xero, FreshBooks, or other connected providers only as authorized by you through the OAuth consent flow. We write back to your accounting system only the data you explicitly direct the Service to sync.
  • Stripe— For subscription billing and payment processing. Stripe’s own privacy policy governs data it processes as the payment processor.
  • Supabase — For database hosting and authentication infrastructure.
  • Resend — For transactional email delivery (invoice reminders, account notices). Email content is transmitted only as needed to deliver messages you trigger.
  • Legal & compliance — We may disclose information where required by law, court order, or to protect our legal rights or the safety of users.

We do not sell, rent, or broker your personal information or your accounting data to any third party for their own marketing or commercial purposes.

5. Data retention

We retain your account and business data for as long as your workspace subscription is active and for a reasonable period thereafter to allow you to export your records. Specifically:

  • — Active account data is retained for the duration of your subscription
  • — After cancellation, data is retained for up to 90 days to enable export
  • — Upon verified deletion request, personal data is purged within 30 days, subject to legal hold obligations
  • — OAuth access and refresh tokens are revoked and deleted upon integration disconnection or account deletion
  • — Invoice and payment records may be retained for up to 7 years to meet applicable financial recordkeeping requirements
  • — Aggregated, de-identified analytics data is retained for up to 24 months

6. Your rights

Access

You may request a copy of the personal information we hold about you by contacting us at info@revenueap.com. We will respond within 30 days.

Correction

You may update your account information directly within the Service settings, or contact us to correct inaccurate data that you cannot edit yourself.

Deletion

Authenticated operators can initiate full account deletion from the workspace settings. If you cannot sign in, use our public account deletion page or email us at info@revenueap.com.

Export

You may export your invoice, client, and payment records in standard formats from the Service dashboard. Integration tokens can be revoked independently without deleting your account.

7. Cookies & tracking

We use cookies and similar technologies to maintain your authenticated session and to support core Service functionality. Specifically:

  • Session cookies — Required for authentication and to keep you signed in during a session. These expire when you close your browser or sign out.
  • Persistent cookies — Used to remember workspace preferences and authentication state across sessions. You may clear these via your browser settings, which will require you to sign in again.
  • Analytics — We may use privacy-respecting analytics to understand feature usage in aggregate. We do not use third-party advertising or behavioral tracking cookies.

8. CCPA & GDPR

California residents (CCPA):You have the right to know what personal information we collect and how we use it, the right to delete personal information, the right to opt out of the sale of personal information (we do not sell personal information), and the right not to be discriminated against for exercising these rights. To submit a request, email info@revenueap.com with subject line “CCPA Request.”

EEA/UK users (GDPR): Where GDPR applies, our lawful basis for processing your personal data is primarily contractual necessity (to deliver the Service you subscribed to) and legitimate interests (security and fraud prevention). You have rights of access, rectification, erasure, restriction, portability, and objection. Contact info@revenueap.com to exercise these rights. You also have the right to lodge a complaint with your local data protection authority (DPA).

9. Children’s privacy

The Service is intended for business use by adults and is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at info@revenueap.com and we will take prompt steps to delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes we will notify you via email or in-app notice at least 14 days before the changes take effect. The “Last updated” date at the top of this page indicates when the policy was last revised.

Continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the changes.

11. Contact us

If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact:

Privacy inquiries

Clear Garment Group — Privacy & Data

info@revenueap.com

CCPA & GDPR requests

Email info@revenueap.com with subject line “Privacy Request” and include your workspace email address and the specific action you are requesting.

Account deletion

Use the in-app deletion flow in Settings, or email info@revenueap.com if you cannot access your account. We aim to process verified deletion requests within 30 days.