Back to DocuBridge AI
Data Privacy & Security
Effective Date: January 1, 2026

Privacy Policy

DocuBridge AI Inc. ("DocuBridge", "we", "our") is committed to safeguarding the privacy and integrity of your commercial data. This Privacy Policy details how we collect, store, process, and protect information when you utilize our platform and accounting integrations.

1. Information We Collect

To provide automated wholesale document extraction and synchronization, we process the following categories of data:

  • Wholesale Purchase Orders: PDF files, scanned images, buyer billing/shipping addresses, purchase order numbers, line item descriptions, SKUs, quantities, and price amounts.
  • Accounting Ledger Metadata: Customer lists (display names, contact IDs) and item catalogs (SKUs, item IDs, unit prices) synchronized from QuickBooks Online or Xero.
  • OAuth Credentials: Encrypted access tokens and refresh tokens generated via OAuth 2.0 authorization code flows with Intuit and Xero.
  • User Account Data: Email address, workspace subdomain, and billing identifiers managed securely through Stripe.

2. How We Use Your Data

We use your information strictly to:

  • Perform multimodal optical parsing and structured extraction of purchase order documents.
  • Execute 4-tier fuzzy SKU and customer reconciliation against your accounting catalog.
  • Generate draft Sales Orders in QuickBooks Online or draft Invoices in Xero via authorized REST APIs.
  • Manage your subscription tier, billing quotas, and system audit logs.

3. AI Model Data Privacy (Zero Training Guarantee)

Zero AI Training Commitment: Your purchase order documents, proprietary pricing, customer names, and accounting data are never used to train public foundation models. API interactions with our vision extraction infrastructure operate under enterprise data-handling agreements where inputs are processed ephemerally and discarded from model training sets.

4. Security Standards & Encryption

We implement strict defense-in-depth security measures:

  • Encryption in Transit: All HTTP traffic is enforced over TLS 1.3.
  • Encryption at Rest: All stored documents, extracted line items, and OAuth tokens are encrypted using AES-256.
  • Tenant Isolation: Every database query is bounded by strict tenant identifiers (`tenant_id`), preventing multi-tenant data leakage.

5. Third-Party Disclosures & Integrations

We never sell, rent, or trade your commercial data. Data is shared exclusively with:

  • Intuit Inc.: When you connect QuickBooks Online to push draft sales orders.
  • Xero Limited: When you connect Xero to push draft invoices and sync contacts.
  • Stripe: For PCI-compliant credit card processing and subscription management.

6. Data Retention & Deletion Rights (GDPR & CCPA)

You may request complete deletion of your documents, extracted line items, and accounting connection tokens at any time. Upon workspace termination or explicit written request to privacy@docubridge.ai, all associated records in our PostgreSQL cluster and document storage are permanently purged within 30 days.

7. Privacy Inquiries

If you have any questions or require our Data Processing Addendum (DPA), contact:
privacy@docubridge.ai