Privacy Policy
Last System Revision Matrix: July 2026
1. Information Collection Vectors & Tenant Isolation
Our core system architecture captures distinct interaction sets to process service handshakes, maintain cryptographic tenant boundaries, and seamlessly synchronize business ledger components across distributed client environments:
- Administrative Credentials & Organization Identifiers: Full corporate names, designated email points, verified business/tenant names, phone configurations, and security profile details provided during account creation or via our Google OAuth single sign-on system.
- Operational Log Tracks & Analytical Metrics: Client-side context records including active IP routing positions, geographical matching parameters for localized configurations, user agent characteristics, form telemetry, and system interaction logs.
- Localized Persistence Matrices: Temporary storage objects such as `user_token` values in LocalStorage, cryptographic session tokens, alongside local IndexedDB tables to facilitate uninterrupted system access, background worker syncs, and offline ERP operational stability.
2. Third-Party Identity Federation (Google OAuth)
When choosing to bypass traditional forms via third-party social buttons, our platform intercepts an authorized access token to fetch your core directory details (specifically name, profile link, and validated email address) to bind your authenticated identity to your specific business tenant container.
To maintain explicit control over your corporate data footprints, our components leverage strict security configurations that pass parameters through a clean `return_to_url` routine. This architecture ensures that sensitive session tokens, corporate metadata strings, and transient error flags are immediately removed from your browser's visible address bar once identity verification concludes.
3. How We Utilize Collected Metrics & Ledger Data
Captured user data and organizational metrics are processed strictly to manage live dashboard sessions, track user preferences across specialized enterprise resource layers, route geographical inquiries to appropriate localized currency or regional settings, compile auditing logs, and protect multi-tenant application frameworks from automated bot deployments or malicious cross-tenant injection attacks. We maintain a zero-monetization policy; we do not sell, trade, or expose corporate user metrics or financial balances to third-party bulk advertising brokers or outside analytics aggregators.
4. Client-Controlled Cache Management & Offline Vaults
This PWA-enabled application preserves layout indices, analytical configurations, system metadata, and encrypted temporary summaries directly inside your browser cache. You maintain continuous, uninhibited authority to wipe these data layers at any time by clearing your browser's application cache, purging domain cookies, or resetting internal IndexedDB storage tables for this domain. Note that purging these components will necessitate a new complete initialization handshake with our core database engine.
5. Structural Security Actions & Multi-Tenant Boundaries
All API transactions, user authorization requests, cross-origin requests, and operational data payload dispatches are shielded using industry-standard SSL/TLS layer wrappers. Tenant isolation is verified programmatically at both the gateway router and the database execution layer. While we use robust encryption schemes across all processing pathways, no digital data system can be guaranteed to be absolutely impervious to outside interception. We encourage you to safeguard your administrative account passwords and session keys accordingly.