Privacy Policy

Last Updated: October 14, 2025 | Effective Date: October 14, 2025

1. Introduction

OLA Group Technology LLC ("we," "our," or "us") operates StoneOS, a stone fabrication management platform for the stone industry. This Privacy Policy explains how we collect, use, store, and protect your information when you use our services, including our QuickBooks integration.

By using StoneOS, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create a StoneOS account, we collect:

  • Business name and contact information
  • Email address and phone number
  • Billing and payment information
  • Physical business address

2.2 QuickBooks Integration Data

StoneOS integrates with QuickBooks Online through a dual-tier system:

Tier 1: Your QuickBooks Account

When you connect YOUR QuickBooks Online account to StoneOS, we collect and process:

  • QuickBooks Company ID (Realm ID) - to identify your specific QuickBooks account
  • OAuth Access Tokens - to securely access your QuickBooks data on your behalf
  • OAuth Refresh Tokens - to maintain the connection without requiring you to re-authorize
  • Customer Information - names, email addresses, phone numbers, billing addresses
  • Invoice Data - invoice numbers, amounts, line items, dates, payment status
  • Payment Notifications - webhook notifications when your customers pay invoices through QuickBooks

Purpose: To automatically create customer invoices in YOUR QuickBooks account when orders are placed through StoneOS.

Tier 2: Our QuickBooks Account (Admin Tier - Wholesale Billing)

We (OLA Group Technology LLC) maintain our own QuickBooks Online account for business-to-business invoicing:

  • We create wholesale invoices in OUR QuickBooks account to bill you (the account) for stone materials
  • Your account information is stored as a "customer" in our QuickBooks account
  • This includes: account name, email, phone, address, and account ID
  • This is standard supplier-to-customer invoicing practice

Purpose: To bill your account for wholesale stone materials provided through the StoneOS platform.

2.3 Usage Data

We automatically collect certain information when you use StoneOS:

  • Log Data: IP addresses, browser type, operating system, pages visited, time spent
  • Feature Usage: Which features you use and how often
  • Error Logs: Technical diagnostics for troubleshooting

3. How We Use Your Information

3.1 QuickBooks Integration Usage

Your QuickBooks Account:

  • Create customer invoices automatically when orders are placed
  • Sync invoice status and payment information
  • Update order statuses based on payment notifications
  • Generate financial reports for your business

Admin QuickBooks (Our Account):

  • Create wholesale invoices to bill your account for materials
  • Track accounts receivable
  • Generate financial reports for our wholesale operations
  • Maintain accurate business records

3.2 Customer Data Usage (Non-QuickBooks)

In addition to QuickBooks integration, we collect and use customer information directly within StoneOS for order management and communication purposes:

  • Customer Information: Names, email addresses, phone numbers, billing/shipping addresses stored in our database
  • Order History: Stone selections, measurements, quotes, purchase history, project details
  • Communication Records: Email correspondence, support tickets, consultation notes
  • Usage Purpose: Order processing, customer support, quote generation, project tracking, communication

This data is stored separately from QuickBooks and is used solely for platform operations. Your customers' information is never shared between accounts and is only accessible to your team members.

3.3 File Uploads and Media

StoneOS allows you to upload various files for business operations:

Stone Images:

Photos of stone slabs, samples, and materials for your catalog. These images are displayed to your customers and stored securely in our cloud storage.

Account Logos:

Your business logo for branding on quotes, invoices, and customer-facing materials. Stored and displayed within your account only.

Reseller Permits:

Tax exemption certificates and business licenses for verification purposes. These documents are stored securely and only accessed by authorized admin personnel for verification.

Payment Receipts:

Electronic payment confirmations and wire transfer receipts for order processing. Stored for accounting and order fulfillment purposes.

File Storage & Security:

  • All files stored in secure cloud storage (Supabase Storage on AWS S3)
  • Access controlled via authentication and authorization
  • Files encrypted at rest and in transit
  • Automatic virus scanning for uploaded files
  • You can delete uploaded files at any time through your dashboard

4. How We Store and Protect Your Information

4.1 Data Storage

  • Database: Supabase (hosted on AWS infrastructure)
  • Location: United States (US-based data centers)
  • Backups: Daily automated backups with 30-day retention
  • Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256)

4.2 QuickBooks Token Security

  • Access Tokens: Stored encrypted in our database
  • Token Expiration: Access tokens automatically expire after 1 hour
  • Refresh Tokens: Used to obtain new access tokens without re-authorization
  • Token Logging: Tokens are NEVER logged in plain text (only redacted presence indicators)
  • Access Control: Tokens accessible only to authorized API functions

5. Data Sharing and Disclosure

5.1 Third-Party Services

We share data with the following third-party services necessary for platform operation:

Intuit/QuickBooks Online:

We share OAuth tokens with QuickBooks to access your account on your behalf. QuickBooks receives customer and invoice data you create through StoneOS.

Subject to Intuit's Privacy Policy: https://www.intuit.com/privacy/

Supabase (Database Provider):

Stores all platform data including encrypted QuickBooks tokens.

Subject to Supabase Privacy Policy: https://supabase.com/privacy

We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6. Your Rights and Choices

6.1 Access and Correction

You have the right to:

  • Access your personal information stored in StoneOS
  • Update or correct inaccurate information
  • Export your data in a portable format

How: Contact us at info@olagrouptech.com

6.2 QuickBooks Connection Control

You can:

  • Disconnect QuickBooks at any time from your StoneOS dashboard
  • Revoke Access through your QuickBooks account settings
  • Delete Tokens: Tokens are automatically deleted upon disconnection

Effect of Disconnection:

  • We can no longer access your QuickBooks account
  • Automatic invoice creation will stop
  • Previously created invoices remain in QuickBooks
  • No data is deleted from your QuickBooks account

7. Data Breach Notification Procedures

7.1 Our Commitment to Security

We take data security seriously and have implemented multiple layers of protection to safeguard your information. However, no system is 100% secure. In the unlikely event of a data breach, we are committed to transparency and prompt notification.

7.2 What Constitutes a Breach

We define a data breach as any of the following:

  • Unauthorized access to encrypted QuickBooks OAuth tokens
  • Exposure of customer personal information (names, emails, addresses, phone numbers)
  • Unauthorized access to business financial data
  • Exposure of uploaded files (stone images, reseller permits, payment receipts)
  • Any security incident that may compromise user data confidentiality or integrity

7.3 Our Response Procedures

Immediate Actions (Within 24 Hours):

  • Contain the breach and secure affected systems
  • Assess the scope and impact of the breach
  • Initiate internal incident response procedures
  • Begin forensic investigation to determine cause and extent
  • Notify our hosting providers (Supabase, Vercel) if infrastructure-related

User Notification (Within 72 Hours):

If your data is affected, we will notify you via:

  • Email: To your registered email address
  • Dashboard Alert: Prominent notification upon login
  • Website Notice: Public disclosure if breach affects multiple users

Our notification will include:

  • Description of what happened
  • What data was affected
  • What we've done to address the breach
  • What actions you should take to protect yourself
  • Contact information for questions and support

7.4 Your Recommended Actions

In the event of a data breach involving your account, we recommend:

  • QuickBooks Connection: Disconnect and reconnect your QuickBooks account to refresh OAuth tokens
  • Password Reset: Change your StoneOS password immediately
  • Monitor Accounts: Watch for suspicious activity in your QuickBooks and bank accounts
  • Enable MFA: Activate multi-factor authentication if not already enabled
  • Customer Notification: Consider notifying your customers if their data was affected

7.5 Regulatory Compliance

We will comply with all applicable data breach notification laws, including:

  • GDPR: Notification to EU data protection authorities within 72 hours
  • CCPA: Notification to California Attorney General if breach affects California residents
  • State Laws: Compliance with state-specific breach notification requirements
  • Industry Standards: Following best practices from NIST, ISO 27001

7.6 Prevention Measures

To minimize breach risk, we maintain:

  • 24/7 security monitoring and intrusion detection
  • Regular security audits and penetration testing
  • Encrypted data storage (AES-256) and transmission (TLS 1.2+)
  • Access controls and least-privilege principles
  • Regular security training for our team
  • Incident response plan tested quarterly

8. QuickBooks-Specific Disclosures

8.1 OAuth 2.0 Authentication

We use OAuth 2.0 to connect to your QuickBooks account:

  • You authorize access through QuickBooks' secure login page
  • We never see or store your QuickBooks password
  • You can revoke access at any time

8.2 Token Refresh

  • Access tokens expire after 1 hour
  • We automatically refresh tokens using refresh tokens
  • Refresh tokens expire after 100 days (requires re-authorization)

8.3 Dual QuickBooks System Explanation

Why We Use Two QuickBooks Accounts:

  1. Your QuickBooks (Showroom Tier): YOU invoice YOUR customers. We create invoices in YOUR account on your behalf. You receive payments from your customers.
  2. Our QuickBooks (Admin Tier): WE invoice YOU (the account). We create wholesale invoices in OUR account. You pay us for stone materials.

This is a standard supplier-distributor relationship. Just as any supplier would invoice you through their accounting system, we use QuickBooks for our wholesale invoicing.

9. Contact Us

For questions about this Privacy Policy or your personal information:

OLA Group Technology LLC

Email: info@olagrouptech.com

Support: orders@olagrouptech.com

Website: www.olagrouptech.com

Address: 16501 Ventura Blvd., Suite 610, Encino, CA 91436

Intuit, QuickBooks, and QuickBooks Online are registered trademarks of Intuit Inc.

StoneOS is a trademark of OLA Group Technology LLC.

Last Updated: October 14, 2025 | Effective Date: October 14, 2025

Version 2.1 (Expanded with customer data, file uploads, and breach procedures)

© 2025 OLA Group Technology LLC. All rights reserved.