Privacy Policy

Last updated August 1, 2026.

Timo Cloud ("Timo," "we," "us") provides an operating layer for produce distributors — order intake, invoicing, and accounting sync — to business customers ("Organizations") and the buyers those Organizations invite to their portal. This policy explains what we collect, why, and how it's protected. It covers the Timo Cloud application at this domain; it does not cover third-party systems you connect (like QuickBooks Online), which have their own privacy policies.

What we collect

Account & organization data: name, email, and role for each user you invite; your organization's name and settings.

Business data you enter or sync: customers, products, orders, invoices, and vendor bills — either typed in directly or synced from an accounting system you connect (currently QuickBooks Online). Access tokens for connected systems are encrypted at rest and never stored in plain text.

Order text you send us: when an order arrives as a text, email, or typed note, that text is processed (including by a third-party AI provider, currently OpenAI) to extract structured order details. We do not use this content to train third-party models, and API-level data retention follows our provider agreement, not a default consumer setting.

Operational & log data: request logs (IP address, timestamp, route) for security and debugging, retained on a rolling basis and never containing your customers' financial line items. Failed login attempts are recorded briefly to prevent brute-force access and are purged automatically.

Error reports: if the application errors, technical details (stack trace, route, a request id) may be sent to our error-tracking provider (Sentry) to help us fix it. We configure this to exclude personal data by default.

What we don't do

We don't sell your data. We don't use your business data — orders, customer lists, pricing — for advertising, and we don't share it across Organizations; every Organization's data is isolated from every other's.

Who can see what

Access within an Organization is role-based: financial data (pricing, margins, payables) is visible only to roles granted that permission. Buyers invited to the portal see only their own orders and invoices, never another buyer's.

How long we keep it

Business records (orders, invoices) persist for as long as your Organization's account is active, so your books stay complete. If you close your account, we retain data only as long as needed for legitimate business, legal, or security purposes, then delete or anonymize it. Login-attempt records are purged after 30 days automatically.

Your choices

You can request a copy of your data, ask us to correct it, or ask us to delete your account by emailing the address below. Disconnecting an integration (like QuickBooks) revokes and deletes the stored credential immediately.

Changes to this policy

If we make a material change, we'll update the date at the top of this page and, where required, notify Organization admins directly.

Contact

Questions about this policy or your data: hello@timo.ag.