We collect information you provide directly, including:
We do not sell your personal information. We share data only with:
RoxyPM integrates with third-party services that you may choose to connect. When you connect a third-party service, you authorize the exchange of data between RoxyPM and that service as described below. You are not required to connect any third-party service — all integrations are optional.
When you connect QuickBooks Online, RoxyPM may send and receive: customer names and contact information, invoices and invoice line items, vendor records, and payment records. This data is used solely to synchronize your accounting records between RoxyPM and your QuickBooks account. Your QuickBooks OAuth credentials (access tokens) are stored securely in our database and are never shared with other tenants or third parties. You may disconnect QuickBooks at any time from Settings, which immediately revokes RoxyPM's access to your QuickBooks data. Intuit's privacy policy governs QuickBooks' handling of your data: intuit.com/privacy/statement.
When you connect Stripe or Square, payment details are handled directly by those processors using their PCI-compliant systems. RoxyPM stores only transaction references (amount, date, status, last 4 digits of card) — never full card numbers. Your processor API keys are stored securely in our database and are never shared.
When you connect Twilio, RoxyPM sends and receives text messages on your behalf using your Twilio account. Message content, phone numbers, and delivery status are logged within your tenant for communication tracking. Your Twilio credentials are stored securely and are never shared with other tenants.
Each tenant configures their own email server (SMTP). Email credentials are stored in your tenant record and used exclusively to send email on your behalf. We do not read, scan, or analyze email content beyond delivery status logging.
We retain your data as long as your account is active or as needed to provide services. Demo accounts are automatically deleted after 4 hours. Upon account termination, we retain data for 30 days for recovery purposes, then permanently delete it. Backup copies may persist for up to 90 days.
We employ industry-standard security measures including: TLS encryption in transit, encrypted database connections, bcrypt password hashing, JWT session tokens, rate limiting, CSRF protection, and regular security audits. No system is 100% secure, and we cannot guarantee absolute security.
Depending on your location, you may have the right to:
To exercise any right, email support@roxypm.com. We respond within 30 days.
California residents have the right to know what personal information is collected, request deletion, opt out of sale/sharing (we do not sell), and not be discriminated against for exercising rights. Categories collected: identifiers, commercial information, internet activity, professional information, and inferences. We do not use sensitive personal information for purposes beyond providing our services.
Residents of states with comprehensive privacy laws have equivalent rights to access, correct, delete, and port their data. To exercise rights or appeal a decision, contact support@roxypm.com.
We use essential cookies for authentication (session tokens stored in localStorage). We do not use third-party advertising cookies. Analytics are server-side only. We do not participate in cross-site tracking or targeted advertising.
RoxyPM is a business-to-business platform not directed at individuals under 16. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it promptly.
We comply with CAN-SPAM (federal), TCPA (telephone), and applicable state marketing laws. Marketing emails include an unsubscribe link in every message. We obtain affirmative consent before sending marketing communications. You may opt out at any time by clicking unsubscribe or emailing support@roxypm.com. Transactional emails (password resets, invoice notifications, security alerts) are not marketing and cannot be unsubscribed.
RoxyPM is operated from the United States. If you access the platform from outside the US, you consent to the transfer and processing of your data in the United States.
We may update this policy periodically. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
Joint Venture Labs LLC
2550 Sandy Plains Rd, Ste 225-407
Marietta, GA 30066
Email: support@roxypm.com
Phone: (470) 641-7953