Skip to main content
IntelliFlow Communications logo — AI-powered systems for service businesses
IntelliFlowCommunications
Our product · DeskOps

The AI business advisor for your service business.

DeskOps lives inside your sales, your ads, your taxes, your team — and tells you exactly what’s working, what’s not, and what to fix today.

  • Live revenue, ad spend, taxes, and team — one screen
  • Ask anything; answers grounded in your real numbers
  • Sits on top of Stripe, QuickBooks, and your ad accounts
Try DeskOps free Explore DeskOps
Legal

Privacy Policy

Last updated: April 16, 2026 · Version 2026-04-16.2

1. Introduction

IntelliFlow Communications LLC ("Company," "we," "us," or "our") operates DeskOps, a business intelligence platform for service businesses. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service at ops.intelliflowcommunications.com.

2. Information We Collect

2.1 Information You Provide Directly

  • Account information: email address, business name, industry, city, state, entity type
  • Business configuration: team member names, roles, commission rules
  • Manual data entries: expenses, revenue entries, notes
  • Communications: messages sent to our support team
  • AI conversations: questions and instructions you provide to the AI business advisor

2.2 Information Collected from Connected Integrations

When you connect third-party platforms, we receive and store:

  • From Stripe: transaction amounts, dates, customer names, subscription details, MRR data
  • From Square: transaction amounts, dates, customer names, location data
  • From PayPal: transaction amounts, dates, fees, payer information
  • From Clover: transaction amounts, dates, tender types, item-level sale detail, customer names where provided by the merchant
  • From Google Ads: campaign names, spend, impressions, clicks, conversions
  • From Meta Ads: campaign names, spend, impressions, reach, leads, cost per lead
  • From Google Business Profile: call volume, impressions, direction requests, review count, rating
  • From Google Places API: business names, addresses, ratings, and place IDs used for competitor research and location enrichment features
  • From QuickBooks: expense categories, amounts, dates, vendor names, profit and loss summaries
  • From FreshBooks: invoice records, expense categories, amounts, dates, client names, and payment status
  • From Xero: chart-of-accounts entries, expense transactions, invoice records, contact names, and tax amounts

Connected integrations are synced automatically on a background schedule (typically daily or multiple times per day) using your authorized tokens. You can pause, disconnect, or revoke any integration at any time from Settings, and we will immediately stop pulling data.

2.2a Data About Your End Customers

When you use the Invoices feature, manually enter customers, or sync transactions from a payment processor, DeskOps may store information about your own end customers, including: customer name and, where provided, company name; billing or contact email address; billing or service postal address; transaction history associated with that customer. You are the data controller for this end-customer information. IntelliFlow Communications LLC acts as a limited data processor on your behalf, storing and displaying the information only to operate the Service for you. You are responsible for ensuring you have the legal right to collect and provide this information to DeskOps, and for complying with applicable privacy laws (including GDPR, UK GDPR, CPRA/CCPA, and other state privacy laws) with respect to your customers. If you need a Data Processing Addendum (DPA) or Standard Contractual Clauses for cross-border transfers, contact contact@intelliflowcommunications.com.

2.3 API Keys and Integration Credentials

When you connect payment processors (Stripe, Square, PayPal) to DeskOps, you provide a read-only API key or access token from that platform. Here is exactly how we handle these credentials:

  • Storage: Your API keys are encrypted using AES-256 encryption before being stored in our database. They are never stored in plain text.
  • Access: Your encrypted keys are only accessed by our server-side sync processes to retrieve your payment data. They are never exposed to the browser, never included in API responses, never logged, and never visible to any DeskOps employee.
  • Permissions: The keys you provide grant read-only access to your payment data (transactions, customers, subscriptions). They cannot be used to create charges, issue refunds, transfer funds, or modify your account in any way.
  • Revocation: You can revoke your API key at any time directly from your payment processor's dashboard. Once revoked, DeskOps immediately loses access to your data. You can also disconnect any integration from DeskOps Settings, which deletes the stored key from our database.
  • Third-party access: We never share your API keys or integration credentials with any third party. Your keys are used exclusively to sync data between your payment processor and your DeskOps dashboard.

2.4 DeskOps Tools, Niche Tools, and AI Outputs

When you use DeskOps Tools, the "Image Read" vision analyzer, trade-specific niche tools (HVAC, plumbing, electrical, roofing, cleaning, etc.), or the AI Business Partner chat, the following is collected and stored:

  • Your prompt: the instructions, job description, and context you type into the composer or chat.
  • Uploaded files: PDFs and images you attach (intake forms, photos, roof drone shots, dental charts, inspection reports). These are transmitted to Anthropic's Claude API for the single generation request and stored in your DeskOps file storage so you can re-open the draft.
  • Generated output: the document, estimate, care plan, inspection write-up, or chat response the AI produces, stored against your account so you can review, edit, and download it.
  • Conversation memory: a rolling summary of your chats with the AI Business Partner (name and role references, recent decisions, stated preferences) is cached in Upstash Redis, keyed per organization, so the assistant does not re-ask questions you have already answered. You can wipe this memory from Settings → AI Memory at any time.
  • Consent records: when you accept a clickwrap agreement (DeskOps Tools terms, niche-tool acknowledgement, Terms of Service, Privacy Policy), we store an append-only record of the agreement type, version, timestamp, IP address, and user agent. This is required for legal compliance and is retained for the life of the account plus seven (7) years.

AI inputs are sent to Anthropic's Claude API in real time for the generation request only. Per Anthropic's API data policy, these inputs are not retained by Anthropic for model training. See Section 5 for Anthropic's privacy policy.

2.4a Health-Adjacent Use and Protected Health Information (PHI)

If your practice is regulated as a healthcare provider (medical, chiropractic, dental, veterinary, optometry, physical therapy, massage therapy, or similar), and you upload patient photographs, clinical notes, or other Protected Health Information (PHI) to Image Read, DeskOps Tools, or any other feature of DeskOps, that use may be subject to HIPAA and state health-information privacy laws. DeskOps is not a HIPAA Business Associate by default. If you are a covered entity or business associate and intend to store or process PHI inside DeskOps, you must contact us at contact@intelliflowcommunications.com to execute a Business Associate Agreement (BAA) before uploading any PHI. Without a signed BAA in place, you agree not to upload PHI into the Service.

2.5 Information We NEVER Collect

  • Credit card numbers or debit card numbers
  • Bank account numbers or routing numbers
  • Social Security numbers
  • Login credentials (usernames/passwords) for any third-party platform
  • Protected health information (PHI)
  • Any credentials that could be used to move money

2.6 Automatically Collected Information

  • Browser type and version
  • Device type
  • IP address
  • Pages visited and features used within the Service
  • Crash and error reports (stack traces and component names) captured by our observability tools when the Service encounters an unexpected failure. These reports are filtered server-side to exclude URLs, request bodies, cookies, and authentication tokens.
  • Push notification subscription tokens (if you opt in to browser notifications)

2.7 CPA Partner Program Data

If you apply to or participate in our CPA Partner Program, we collect:

  • Full name, firm name, CPA license number and state, email address, phone number
  • Referral activity and commission earnings
  • Stripe Connect account information for payout processing
  • Terms of service acceptance records

This data is used exclusively to operate the partner program, track referral commissions, and process payouts.

2.8 Billing Information

When you subscribe to DeskOps, billing is handled entirely by Stripe:

  • We store your Stripe customer ID, subscription ID, and plan details
  • We do NOT store your credit card number or payment method details — these are held exclusively by Stripe
  • Stripe processes all payments and stores payment methods under their PCI DSS Level 1 certification

3. How We Use Your Information

We use your information exclusively to:

  • a. Provide and operate the Service
  • b. Display your business data in the dashboard
  • c. Generate AI-powered business insights from your connected data
  • d. Send automated reports (weekly email reports, monthly PDF reports)
  • e. Send service-related communications (billing notices, system alerts, product updates)
  • f. Calculate tax estimates and business health metrics
  • g. Personalize the AI assistant based on your preferences and conversation history
  • h. Improve the Service and fix issues
  • i. Send browser push notifications to you (only if you have opted in)
  • j. Send invoice reminders, receipts, or similar messages to your end customers only when you explicitly trigger that action

3.1 Automated Background Processing

DeskOps runs scheduled sync jobs and cron processes that operate on your behalf without requiring per-action consent after initial authorization. This includes: nightly and intraday syncs of transactions, ads data, and expense data from your connected integrations; periodic recalculation of commissions, tax estimates, goals, and business-health metrics; weekly and monthly report generation; and token refresh for OAuth integrations. By connecting an integration or enabling an automation, you consent to these recurring background processes. You can pause, disconnect, or disable any of them at any time from Settings or the Notifications page.

With your business and operational data inside the Service (transactions, customers, expenses, ad metrics, and AI conversations), we do NOT:

  • Sell it to third parties
  • Use it for advertising purposes
  • Share it with other DeskOps customers
  • Use it to train AI models (your data is sent to Anthropic's Claude API for real-time responses only and is not retained by Anthropic for training per their data usage policy)
  • Share it with data brokers

Our public marketing website (the pages you browse before signing up) is treated separately: it uses analytics and advertising tools to measure our ad campaigns. See Section 8 (Cookies and Tracking) for what those tools collect and how to opt out.

4. Data Storage and Security

4.1 Where Your Data is Stored

  • Primary database: Supabase (PostgreSQL), hosted in the United States, with AES-256 encryption at rest
  • AI memory: Upstash Redis, hosted in the United States
  • File storage: Supabase Storage (for logos, PDF reports), hosted in the United States
  • Application hosting: Vercel, United States

4.2 Security Measures

  • All data encrypted at rest using AES-256
  • All data encrypted in transit using TLS 1.2 or higher
  • OAuth tokens stored encrypted and accessible only by server-side code (never exposed to the browser)
  • Row Level Security (RLS) on every database table ensures complete data isolation between customers
  • No customer can access another customer's data under any circumstances

4.3 OAuth Token Security

  • Integration tokens (for Stripe, Google, Meta, QuickBooks, etc.) are stored encrypted
  • Tokens are scoped to read-only access
  • Tokens are never logged, never included in error messages, and never returned in API responses
  • You can revoke any integration token at any time by disconnecting the integration from Settings

5. Third-Party Services

We use the following third-party services to operate DeskOps. Each has its own privacy policy:

  • Supabase (database, authentication, and file storage): supabase.com/privacy
  • Anthropic (AI assistant, DeskOps Tools generation, Image Read, and niche-tool outputs): anthropic.com/privacy
  • Stripe (subscription billing, Stripe Connect payouts for the CPA Partner Program, and payment processor integration for revenue sync): stripe.com/privacy
  • Upstash (AI conversation memory, OAuth state storage, and rate-limit counters): upstash.com/privacy
  • Resend (email delivery for invoices, reports, and notifications): resend.com/legal/privacy-policy
  • Vercel (application hosting and serverless function execution): vercel.com/legal/privacy-policy
  • Sentry (crash and error observability): sentry.io/privacy
  • Intuit / QuickBooks (accounting data integration): intuit.com/privacy
  • FreshBooks (accounting data integration): freshbooks.com/policies/privacy
  • Xero (accounting data integration): xero.com/legal/privacy
  • Square (payment processor integration): squareup.com/us/en/legal/general/privacy
  • PayPal (payment processor integration): paypal.com/us/legalhub/privacy-full
  • Clover (payment processor integration): clover.com/privacy-policy
  • Google (Ads, Business Profile, and Places APIs): policies.google.com/privacy
  • Meta (Ads API): facebook.com/privacy
  • Pipedream (ad integration sync automation): pipedream.com/privacy

If we add a new third-party service that receives your data, we will update this list and, for material additions, notify existing customers by email before the new service begins receiving data.

6. Data Retention

  • Active account data: retained for as long as your account is active.
  • After account deletion: all primary account data is permanently deleted from our production database within 30 days. Cloud provider backups containing your data are rotated on their provider-set schedule (typically 30 days for Supabase point-in-time recovery, up to 30 days for Upstash Redis snapshots).
  • AI conversation memory: cached in Upstash Redis per organization. Cleared immediately when you click "Wipe Memory" in Settings, or when you request account deletion.
  • Activity and audit logs: retained while your account is active, and for 90 days after account deletion to support security investigations, fraud prevention, and legal discovery obligations.
  • Billing and tax records: subscription payment records, invoices, and tax-relevant transaction history are retained for up to 7 years, or as required by applicable federal and state tax laws in the jurisdiction where IntelliFlow Communications LLC is registered (Indiana, United States), whichever is longer.
  • Server logs: retained for 90 days for security and debugging purposes. Logs are filtered to exclude request bodies, cookies, and authentication tokens.
  • CPA partner records: retained for the duration of the partnership plus 7 years for tax and commission-audit compliance. Commission payout records cannot be deleted while an active Stripe Connect account remains linked.
  • Consent records: retained for the life of the account plus 7 years (append-only, cannot be modified).

7. Your Rights

You have the right to:

  • a. Access your data at any time through the Service
  • b. Export your data in CSV format from the Settings page
  • c. Correct inaccurate data by editing it within the Service or contacting us
  • d. Delete your account and all associated data from the Settings page
  • e. Disconnect any third-party integration at any time
  • f. Opt out of non-essential communications
  • g. Opt out of browser push notifications
  • h. Clear AI conversation memory

7.1 State Privacy Laws (United States)

If you are a resident of a U.S. state with a consumer privacy law in effect — including California (CPRA/CCPA), Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), or any other state whose law applies — you may have additional rights, which may include: the right to know what categories of personal information we collect and how it is used; the right to access a portable copy of your personal information; the right to correct inaccurate personal information; the right to request deletion of your personal information; the right to opt out of the "sale" or "sharing" of your personal information for targeted advertising (see Section 8 — our marketing website shares limited identifiers with Meta for ad measurement, which these laws may treat as "sharing"; you can opt out below); and the right to non-discrimination for exercising these rights. To exercise any of these rights, contact us at contact@intelliflowcommunications.com from the email address on file with your account, or submit the request from inside the Service. We will respond within the timeframe required by your state's law, typically 30 to 45 days.

7.2 Authorized Agent Requests

You may designate an authorized agent to submit a privacy request on your behalf. We will require the agent to provide proof of their authority (a signed permission from you or a power of attorney) and we may contact you directly to verify the request.

7.3 EU / UK Users

DeskOps is operated from the United States and is primarily offered to U.S.-based service businesses. If you access the Service from the European Economic Area or the United Kingdom, we process your personal information under our legitimate interest in operating the Service and providing it to you as a customer, or under contract. You have the rights of access, rectification, erasure, portability, restriction, and objection under the GDPR and UK GDPR. To exercise these rights or to request a Data Processing Addendum or Standard Contractual Clauses for transfers of your customer data to the United States, contact contact@intelliflowcommunications.com.

8. Cookies and Tracking

8.1 Inside the Service

When you are signed in to DeskOps, the Service uses only essential cookies for authentication and session management. We do not run advertising cookies, ad pixels, or third-party advertising trackers inside the Service.

8.2 On our marketing website

Our public marketing pages (which you can browse without an account) use the following tools to understand and measure our advertising:

  • Google Analytics 4 — measures page views and campaign performance.
  • Meta Pixel and Conversions API — measure the performance of our Facebook and Instagram ads. When you submit one of our lead forms (waitlist, get started, or contact), we share a hashed (irreversible) version of your email and phone number, along with advertising identifiers such as the fbclid click ID and the Meta _fbc/_fbp cookies, with Meta to attribute and optimize those ads.

We also capture campaign parameters (UTM tags and click IDs) from the links you arrive on so we can credit the right ad. Under some U.S. state privacy laws (e.g., California's CPRA), sharing these identifiers with Meta for advertising may be considered "sharing" or "targeted advertising."

8.3 Your choices — Do Not Sell or Share My Personal Information

You can stop this browser from loading the Meta Pixel and sharing identifiers for advertising at any time using the control below. We also honor the Global Privacy Control (GPC) browser signal where it is enabled.

Sharing is on

Opt out to stop this browser from loading the Meta Pixel and sharing identifiers for ad measurement.

This choice is stored only in this browser. We also honor the Global Privacy Control (GPC) signal where supported. Clearing your browser storage resets it.

9. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will delete it promptly.

10. Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and applicable authorities within 72 hours as required by applicable state and federal law, including a description of the breach, the types of information affected, and the steps we are taking to address it.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before the changes take effect. The "Last Updated" date at the top of this policy indicates when it was last revised.

This Privacy Policy is provided as a draft document and is subject to review by qualified legal counsel. It does not constitute legal advice.

Terms of Service →SMS Compliance Standards →
IntelliFlow Communications logo — AI-powered systems for service businesses
IntelliFlowCommunications

The AI business advisor for service businesses. Built for owner-operators who finally want their numbers to make sense.

contact@intelliflowcommunications.com

Product

  • DeskOps
  • Pricing
  • Get Started
  • FAQ

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of service
  • SMS Compliance
  • Accessibility

© 2026 IntelliFlow Communications. All rights reserved.

Privacy PolicyTerms of serviceYour privacy choices