Privacy Policy
Effective April 29, 2026
This policy explains what data elaichi labs (operated by Elaichi Co. LLC) collects, how we use it, who we share it with, and the choices you have. We've tried to write it in plain English. If anything is unclear, email privacy@elaichico.com.
1. What we collect
Account information
- Name, email address, business name
- Authentication metadata (login timestamps, IP addresses, device/browser identifiers)
Connected service data
When you connect a third-party service via OAuth or API key, we read data from that service in the scopes you authorize. The services we currently integrate with and the categories of data we read are:
- Square — sales transactions, payouts, fees, product catalog, inventory, employees, scheduled shifts.
- Mercury — bank account balances, transactions, statements, recipients, treasury data. Read-only.
- QuickBooks Online — chart of accounts, journal entries, customers, vendors, invoices, bills, reports. Read-only in our current configuration.
- Gusto — employee roster, pay periods, payroll cycle summaries, compensation data. Read-only in our current configuration; PII fields (SSN, DOB, bank routing) are redacted at the logging layer and never persisted in our application logs.
- Shopify Admin — orders, products, customers, inventory, payouts. Read-only.
- TikTok Shop and TikTok for Business (Ads) — orders, product catalog, settlements, campaign-level ad spend, conversions. Read-only.
- Google Workspace (Gmail, Drive) — message metadata and contents that you direct us to read (e.g. vendor invoices in a labeled folder); files in Drive folders you share with the application.
- Slack — public channel messages, messages in channels the application is invited to, and direct messages exchanged with the application bot.
- Homebase — schedules, employees, time clock entries.
Usage data
- Pages visited, features used, errors encountered, performance metrics
- Server logs (request paths, response codes, latencies, user-agent)
Cookies and similar technologies
We use a small number of essential cookies for authentication and session management. We don't use third-party advertising cookies.
2. How we use it
- To provide the Service: forecasting, inventory analytics, invoice processing, accounting reconciliation, financial reporting, payroll preparation, and AI-agent assistance.
- To run AI agents on your behalf: we send relevant context — including connected-service data — to large-language-model providers (currently Anthropic, Inc.) to generate forecasts, drafts, classifications, and other agent outputs. Anthropic processes this data under their Privacy Policy and does not use your data to train their models when called via the Anthropic API in our configuration.
- To secure the Service: detect fraud, abuse, and unauthorized access; investigate incidents.
- To improve the Service: aggregated and anonymized analytics about feature usage and performance. We do not use your individual data to train shared models.
- To communicate with you: service announcements, billing, security alerts, and customer support.
- To comply with legal obligations: tax reporting, financial-record retention, lawful requests from authorities.
3. Who we share it with
We don't sell your data. We share it only with:
- Service providers who run our infrastructure (e.g., Vercel for application hosting; managed Postgres for primary data storage; observability and email-delivery providers). These providers are bound by contract to use your data only to provide their services to us.
- AI / LLM providers (currently Anthropic, Inc.) — see Section 2.
- Connected services you authorize — the third-party services you yourself connected; the data flows read-only from those services to us, not the other way around, unless you specifically enable a write integration.
- Authorities, when legally required — in response to a valid subpoena, court order, or other lawful request. We'll notify you when permitted.
- An acquirer — in the event of a merger, acquisition, or sale of assets. The acquirer must honor this policy.
4. Where data is stored
Application data is stored in managed Postgres databases hosted in the United States. Some agent runs occur on local infrastructure controlled by the account holder (a self-hosted deployment mode), in which case primary storage and processing occur on hardware controlled by the account holder. We use encryption in transit (TLS 1.2+) and at rest for all managed storage we operate.
5. Data retention
- Account data — kept for as long as your account is active.
- Connected-service tokens — kept until you disconnect the integration or delete your account, then revoked and deleted within 30 days.
- Financial records — kept for at least seven (7) years after the related transaction, to comply with U.S. tax-record retention rules.
- Server logs — typically 90 days.
- AI / LLM provider context — Anthropic's stated retention applies to data sent to their API; we do not retain a separate copy of LLM prompts beyond what's needed for our application logs (typically 30 days).
6. Your rights
You have the right to:
- Access the personal data we hold about you;
- Correct data that's inaccurate;
- Delete your data, subject to legal retention requirements (e.g. accounting records);
- Export your data in a portable format;
- Disconnect any third-party integration at any time;
- Object to certain uses, including any processing for direct marketing.
To exercise these rights, email privacy@elaichico.com. We'll respond within 30 days.
California residents have additional rights under the California Consumer Privacy Act (CCPA / CPRA). EU/UK residents have rights under the GDPR / UK GDPR. We honor those rights regardless of where you're located.
7. Security
We use industry-standard practices to protect your data: TLS in transit, encryption at rest for managed storage, strict access controls on engineering systems, multi-factor authentication for administrative accounts, and audit logging on sensitive operations. No system is perfect; if you suspect a security issue, email security@elaichico.com.
8. Children
The Service is not intended for individuals under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
9. International data transfers
We are based in the United States and process data here. If you're accessing the Service from outside the U.S., your data may be transferred to, stored in, and processed in the U.S. We use appropriate safeguards (such as Standard Contractual Clauses) where required.
10. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we'll notify you via email or in-product notice at least seven days before it takes effect. The "Effective" date at the top of this page reflects the latest version.
11. Contact us
Questions, requests, or concerns? Email privacy@elaichico.com or write to:
Elaichi Co. LLC
Privacy Office
San Francisco, CA, USA