Privacy Policy
Last updated: August 29, 2026
This Privacy Policy explains how DataFloat Solutions Inc. (“DataFloat”, “we”, “us”, or “our”) handles information across everything we run: datafloat.app (the “Site”), our waitlist and pilot application forms, and the DataFloat platform itself (the “Platform”). Together we call these the “Services”, with the same meaning they have in our Terms of Service.
Two very different kinds of information move through the Services, and they are not governed the same way. Section 1 explains which one applies to you before anything else does.
1. What This Policy Covers
Information reaching us falls into three categories, and the third is the one worth reading closely.
- Site visitors and applicants. If you browse datafloat.app, join our waitlist, or apply to the pilot program, we decide what happens with the information you give us. This policy governs it in full.
- Platform account holders. If we admit you to the pilot and you create an account, the same is true of your account details and how you use the product. This policy governs that in full too.
- The client books you connect. This is different. When you connect a client's accounting data to the Platform, the information inside belongs to your client and the people in their records, not to you and not to us. You decide what happens to it. We act on your instructions and on the agreement we signed with you, and nothing else. In the vocabulary of privacy law, you are the controller of that data and we are your processor, or service provider.
Section 3 describes what we do with connected client data. But this policy is not the document that governs it — your pilot agreement and Terms §7 are. Everywhere else below, “you” and “your information” mean the person reading this and their own information, not their clients'.
By using the Services, you agree to the practices described here.
2. Information We Collect
We collect the following:
- Information you provide directly. When you join our waitlist, we collect your first name, last name, and email address. When you apply to our pilot program, we also collect your role or title, company name, firm size, information about how you currently produce reports, who those reports are for, and any details or questions you choose to share with us.
- Account information. If you are admitted to the pilot, we collect what an account needs: your name, email address, and a password. Passwords are stored only as salted hashes, so nobody at DataFloat can read yours.
- Information about how you use the Platform. Once you have access, we keep operational records such as sign-in events, which integrations you have connected, when syncs run, and errors the product hits. We use these to run the service, support you, and investigate problems.
- Information collected automatically. When you use the Site or the Platform, we and our service providers collect limited technical information such as your IP address and basic device or browser details. Your IP address is also used to rate limit our forms and our login, signup, and password-reset endpoints, which is how we blunt spam and credential-stuffing attempts. Our forms use Cloudflare Turnstile to check that submissions come from real people.
- Data from systems you connect. If you connect QuickBooks Online, or optionally HubSpot, we sync data from those accounts into your workspace. Section 3 covers this.
We do not intentionally collect sensitive personal information about you, and we ask that you do not include it in free-text fields.
3. Client Data You Connect to the Platform
Most of our users are accountants and fractional CFOs who connect books belonging to someone else. The financial records we sync can contain personal information about people who never visited our website: client contacts, employees named in payroll, vendors, and anyone else appearing in the ledger. We treat that data as yours to direct.
- We use it only to provide the Services to you. We do not use connected client data for our own purposes, we do not sell it, we do not share it with advertisers or data brokers, and we do not use it to train artificial intelligence models. The providers in Section 5 are the only third parties that touch it.
- The connection reads, it does not write. No journal entry, invoice, account, or transaction in your client's books is ever created, edited, or deleted by DataFloat. Data moves one way, out of QuickBooks and into your workspace. Intuit's consent screen will show a broader permission than we use, because their accounting scope covers reading and writing together and they offer no read-only version of it. Our Trust & Security page explains this in detail.
- We do not store your QuickBooks credentials. Your access and refresh tokens are held by Fivetran, our sync provider, and never land in our database. We store only the connection metadata needed to identify your workspace.
- You are responsible for the right to connect it. Under Terms §7 you confirm you have the authorizations and consents required for every account you connect, including your client's permission and any professional or regulatory duty you owe them. We are not in a position to verify that, and we rely on your confirmation.
- Requests from your clients come to you. If someone whose personal information sits in data you connected asks us for access, correction, or deletion, we will not act on it unilaterally. We will refer them to you and help you respond, because you hold the relationship and the obligation.
4. How We Use Your Information
We use the information described in Section 2 to:
- respond to your waitlist or pilot application and communicate with you about DataFloat;
- evaluate pilot applications and determine fit;
- create and secure your account, verify your email address, and send account emails such as verification and password resets;
- provide, operate, maintain, and improve the Site and the Platform, and support you when something goes wrong;
- understand the needs of finance and accounting professionals so we can build a better product;
- protect against fraud, spam, abuse, and other security risks; and
- comply with our legal obligations.
We do not sell your personal information, we do not share it for advertising, and we do not use it to train artificial intelligence models.
5. How We Share Your Information
We share information only in the circumstances below, with the providers named.
- Providers behind the Site and its forms. Vercel hosts the site; Supabase stores waitlist and pilot submissions; Cloudflare provides the bot protection on our forms; Upstash backs the rate limiting; and a Discord webhook notifies our team of a new submission, which means the name, email, and application answers you send us are delivered into a private channel our founders read.
- Providers behind the Platform. Fivetran moves data from QuickBooks and HubSpot into your workspace; Supabase is the database it comes to rest in; Vercel runs the application; Anthropic powers the AI features; Intuit and HubSpot are the sources you connect; Resend sends account emails; Upstash rate limits our login endpoints; and Tavily provides web search for market research features, which never receives your financial data. Our Trust & Security page lists what each one does and where it operates.
- Legal reasons. We may disclose information if required to do so by law or in response to valid legal requests, or to protect the rights, safety, and property of DataFloat, our users, or others.
- Business transfers. If DataFloat is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
Each provider processes information on our behalf and is permitted to use it only to provide services to us. We do not sell your personal information, and we do not share it for advertising purposes.
6. Where Your Data Is Stored
Your data is processed in Canada and stored in the United States.
The pipeline that moves data out of QuickBooks runs in Montreal. The database it comes to rest in is hosted in Northern Virginia. Because the stored copy sits on US infrastructure, it is subject to US legal process, and Canadian firms with public sector clients or Quebec operations should factor that into their own assessments. Data is encrypted in transit using TLS and at rest using AES-256.
7. AI Features
The Platform's AI features are built on Claude, from Anthropic. When you ask a question about your data, the relevant portion of that data is sent to Anthropic's API to produce the answer.
Your data is never used to train artificial intelligence models. Anthropic does not train its models on data submitted through their commercial API, we do not train models on your data, and we will not start without asking you first in plain language.
8. Data Retention and Deletion
We retain waitlist and pilot application information for as long as needed for the purposes in this policy, including to communicate with you about the pilot, unless a longer retention period is required by law. You may ask us to delete it at any time.
For the Platform, you can disconnect a client's accounting company at any time, and you can ask us to delete the data we have already synced. Both are handled manually today, not through a self-serve button. Email security@datafloat.app and we will disconnect the integration, which stops all future syncing, and remove the synced data from our database. Self-serve versions of both are on our list, and this policy will be updated when they ship.
9. Security
We take reasonable measures to protect information from loss, theft, misuse, and unauthorized access. On the account layer specifically: no session is issued until you have verified your email address, our login, signup, and password-reset endpoints are rate limited, completing a password reset revokes every existing session, and changing the email address on an account requires re-entering the current password.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not currently hold a SOC 2 certification. Our Trust & Security page sets out the controls we do have.
10. Your Choices and Rights
You may contact us at any time to access, correct, or delete the personal information we hold about you, or to unsubscribe from our communications. Depending on where you live, you may have additional rights under applicable privacy laws. To exercise any of these rights, use the contact details in Section 14. We aim to respond within 30 days.
These rights cover your own information. They do not extend to the client data you connect to the Platform, which stays under your control and your firm's obligations, as Section 3 explains.
11. Third-Party Services and Links
The Site and the Platform may link to third-party websites or services that we do not control. This Privacy Policy does not apply to them, and we encourage you to review their privacy policies.
Your use of a system you connect, such as QuickBooks Online or HubSpot, remains governed by your own agreement with that provider. Disconnecting it from DataFloat does not change anything about your relationship with them.
12. Children's Privacy
The Services are intended for business users and are not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the date shown at the top of this page. If a change is material, we will make reasonable efforts to tell you, for example by email or a notice on the Site. We encourage you to review this policy periodically.
14. Contact Us
For questions about this Privacy Policy, or to make a request about your personal information, email us at legal@datafloat.app. We aim to respond within 30 days.
To delete data synced into the Platform, or to report a security issue, email security@datafloat.app.
For anything else, reach us at hello@datafloat.app or in our Discord community.