Effective Date: 26 September 2026

Privacy Policy

OrderKeeper is operated by Rapidops Apps LLC ("Rapidops", "we", "us"). This policy explains what we collect when you use OrderKeeper, what we do with it, who else receives it, and how long we keep it.

1. Our Role

For your account details, we decide how the data is used. For the purchase orders you send us and the data we read from your accounting ledger, we process that data on your behalf, only to provide the service to you. Purchase orders often contain information about your customers, such as names and delivery addresses; you remain responsible for having the right to share it with us.

2. What We Collect

  • Account details: your name, email address, organization name and role. Your password is stored only as a salted hash, never in readable form.
  • Purchase orders: the files you upload or email to your OrderKeeper address, the details read from them (such as order numbers, dates, buyer names, delivery addresses, products, quantities and prices), your corrections, and the sender address of emailed orders.
  • Accounting ledger data: when you connect QuickBooks Online or Xero, your customer names, your products (names, SKUs, descriptions and prices) and your company's name, plus the access tokens for the connection. The ledger settings needed to enter an order correctly (such as tax codes and rates, numbering, payment terms and currency) are read when an order is checked or entered, and are not stored.
  • Billing details: your subscription status and the identifiers Stripe gives us. Card details are entered on Stripe's pages and never reach us.
  • Technical data: IP addresses, used briefly to limit repeated sign-in and sign-up attempts, and server logs.

3. How We Use It

  • To read your purchase orders, match their lines to your products, and create the orders you approve in your ledger.
  • To send account emails, such as address confirmation and password reset links.
  • To manage your subscription and its monthly allowance.
  • To keep the service secure and working, and to investigate errors.

We do not sell your data, use it for advertising, or use your purchase orders for any purpose other than providing the service to you.

4. AI Processing

Each purchase order you send is passed to Google's Gemini API, which reads it and returns its details to us. We use Gemini as a paid service. Under Google's terms for the paid service, Google does not use the content we send to improve its products; it may keep it for a limited time to detect abuse. The details it returns are stored only in OrderKeeper.

5. Who Else Receives Your Data

We share data only with the providers that run parts of the service:

  • Google LLC (Gemini API): reads each purchase order, as described above.
  • Intuit Inc. (QuickBooks Online) and Xero Limited: only if you connect them; they receive the orders you approve and, in QuickBooks Online, the purchase order file attached to each and any customer you ask OrderKeeper to add.
  • Stripe, Inc.: subscription billing and card payments.
  • Contabo GmbH: hosts the servers that run OrderKeeper and store your data.
  • Backblaze, Inc.: stores our nightly backups.
  • Spaceship, Inc. (Spacemail): our email provider; purchase orders emailed to your OrderKeeper address and our account emails pass through it.

We may also disclose data where the law requires it.

6. Security

  • Connections to OrderKeeper are encrypted (HTTPS).
  • The access tokens for your QuickBooks Online or Xero connection are stored encrypted (AES-256).
  • Every record belongs to one organization, and each request is checked against the signed-in user's organization before any data is returned.
  • The database and your files are backed up every night to separate storage.

7. How Long We Keep It

  • We keep your data while your account is open.
  • You can delete any order that has not been pushed to your ledger at any time; its file and details are deleted with it. Orders that were pushed are kept as the record of what was sent.
  • Disconnecting a ledger deletes its access tokens.
  • Orders emailed to your OrderKeeper address also stay in our mailbox, where they are deleted when you close your account.
  • To close your account, email privacy@rapidops.io. We delete your organization's data within 30 days. Copies in our backups are deleted as the backups expire, within a further 30 days.
  • Server logs are overwritten regularly.

8. Your Rights

You can ask us for a copy of your data, to correct it, or to delete it, by emailing privacy@rapidops.io. We answer within 30 days. Depending on where you live, you may have further rights under local data protection law, including the right to complain to a supervisory authority.

9. Cookies

We use one cookie to keep you signed in, and a short-lived one while you connect an accounting ledger. We use no advertising or analytics cookies.

10. Changes to This Policy

When we change this policy, we update the date at the top. For significant changes, we tell account owners by email before they take effect.

11. Contact

Privacy questions and requests: privacy@rapidops.io
Everything else: support@rapidops.io