Privacy notice · Effective October 5, 2026
Careful boundaries.
Clear expectations.
This notice explains the public Opermetry website and the intended use of data in an approved internal analytics workflow.
1. This public website
The public website provides service information, terms, and setup guidance. It has no account registration, sign-in, credential fields, analytics dashboard, or business-data upload. It does not set cookies, load advertising or visitor analytics scripts, or embed third-party fonts or tracking resources.
2. Requests and hosting
When you visit, your browser sends normal request information, such as an IP address, requested URL, and browser headers, to the hosting infrastructure. The application does not create request logs or persist visitor records. The public website is hosted on Railway. Railway and network infrastructure may process or log technical information for delivery, security, and operations under their own configuration and policies. No specific infrastructure log-retention period is asserted here.
3. OAuth return information
A provider redirect may include authorization parameters in its URL. The application does not exchange authorization codes, accept tokens as credentials, display query parameters, or persist them. It does not create application request logs containing these values. The URL can still be present in browser history or infrastructure logs; do not share it, and use the approved local redirect configuration. This public callback page is not a credential collection endpoint.
4. Internal analytics data
An approved internal integration may read accounting, sales, supplier, transaction, and related business records from authorized QuickBooks, Clover, and BILL accounts. Depending on the source records and approved scope, those records may include information about customers, employees, suppliers, and business contacts. The current internal workflow processes approved data locally and in the existing Google BigQuery business analytics environment. This public website does not retrieve or expose those records.
5. Purpose and access
The intended purpose is internal business analysis, reconciliation, and operational review for Smokers Abbey. Access must be limited to authorized staff and specifically approved service providers with a business need. Data must not be sold, used for advertising, or published publicly through this service. The internal application owner is responsible for confirming actual provider permissions, access controls, and approved recipients.
6. Credentials and safeguards
Provider authorization and secret storage belong in the approved local integration environment. Current local tokens are encrypted using Windows DPAPI, bound to the local user, and stored outside the source repository. Do not send passwords, authorization codes, tokens, or client secrets through the public site or routine support messages. Owners should apply appropriate access controls, secure storage, and incident procedures to the internal environment. This notice does not claim an independent security audit or certification.
7. Retention and deletion
This public application does not store business records or visitor submissions. Internal imported records, backups, and credentials follow the business's applicable retention requirements and the approved integration's configuration. No fixed internal retention period is published here. Revoking a provider connection stops authorized future access but does not itself delete existing records. Ask the internal owner about retention, deletion, and legal accounting obligations.
8. Providers and disclosure
Source providers and hosting infrastructure process information under their own terms and privacy policies. This website does not assert that a particular internal integration is active or that any provider has approved it. Business information may be disclosed only through approved business processes or when legally required.
9. Questions and requests
For a privacy question, correction, access, or deletion request, contact the internal application owner. They must verify the requester's authority, identify the relevant records and responsible business, and consider applicable legal retention requirements. support@opermetry.com
10. Changes
Changes to this notice will appear here with an updated effective date. Material changes to internal data processing should be communicated by the application owner before implementation.