Legal
Privacy Policy
Novogn LLC ("Novogn," "we," "us") builds and operates order-operations software for business clients under written service agreements. This policy explains what data we handle, why, and how we protect it. It covers two things: this website, and the platforms we run on behalf of clients.
1. This website
novogn.llc is a static informational site. It sets no cookies, has no user accounts, and runs no analytics or advertising scripts of its own. Cloudflare serves the site and keeps standard request logs (IP address, browser type, pages requested) for security and abuse prevention, subject to Cloudflare's own retention schedule. Cloudflare may also insert its cookieless performance beacon, which reports page-load timing to Cloudflare in aggregate and does not identify visitors. If you email us, we keep the correspondence for as long as it is useful to the conversation.
2. Platforms we operate for clients
Each client engagement is governed by a service agreement that names Novogn as the client's service provider. The client decides what data enters the platform and how it is used. We process that data only to deliver the agreed service, and we do not use it for any purpose of our own.
The categories of data a platform typically holds:
- Business contact details of the client's customers, distributors, and sales representatives: names, company names, work email addresses, phone numbers, and shipping or billing addresses.
- Commercial records the client receives or issues: purchase orders, order confirmations, invoices, price lists, contract terms, commission calculations, and distributor sales reports.
- Accounts for the client's own staff: name, work email address, role, and a salted password hash. We never store plaintext passwords.
- An audit trail recording who changed what and when, kept so every financial state in the system can be explained.
We do not process payment card numbers, bank account numbers, Social Security numbers, or health records.
3. Accounting integrations, including QuickBooks Online
When a client connects its accounting system, the client's own administrator authorizes the connection through the provider's standard consent screen. For QuickBooks Online, the platform requests the accounting scope only and uses it to:
- read the connected company's name to confirm the connection;
- look up and, when missing, create customer and item records that mirror records already in the platform;
- create, update, and void invoices that originate in the platform, so the client's books stay current;
- read the client's income account list to categorize those items.
The platform does not record payments, read the general ledger, run reports, or bulk-export accounting data. Connection tokens are stored encrypted and are deleted when the client disconnects, which also revokes the authorization with the provider. Accounting data is never sold, shared with third parties, or used for anything beyond the client's own bookkeeping. The provider's privacy statement governs the data held on its side.
4. Service providers we rely on
We use a small number of infrastructure providers, each under its own data-processing terms. All are located in the United States.
| Provider | Purpose |
|---|---|
| Railway | Application hosting and databases |
| Cloudflare | Document storage, backups, and this website |
| Anthropic | Reading purchase-order documents into structured data. Used under commercial API terms that exclude training on customer data. |
| Resend | Delivering transactional email a client chooses to send |
| Microsoft 365 | Reading a client's own order-intake mailbox, inside the client's tenant, with the client's authorization |
| Intuit | QuickBooks Online, when a client connects it |
| Sentry | Error monitoring. Error reports carry record identifiers, not names, addresses, or document contents. |
We do not sell data. We do not share it with advertisers or data brokers. We disclose data only to these providers, to the client that owns it, or when the law requires.
5. Security
- Every connection is encrypted in transit with TLS.
- Credentials and integration tokens are encrypted at rest with AES-256-GCM, using a key that exists only in the hosting provider's secret manager and is unique to each environment.
- Access is role-based. Connecting integrations, editing credentials, and deleting records are limited to a client's administrators, and every such action is written to the audit trail.
- Databases are backed up nightly to encrypted object storage. Secrets inside backups remain ciphertext.
- Source code is scanned for leaked secrets on every change, and dependencies are checked for known vulnerabilities weekly.
- If a security incident affects a client's data, we notify that client without undue delay and support its notifications to the people affected.
6. Retention and deletion
Client data is kept for the life of the service agreement and for the period the client's own legal and accounting obligations require afterward. Issued invoices and their audit history are retained rather than deleted, because the client's books depend on them. Backups roll off on a fixed schedule: daily copies after 28 days, weekly copies after about six months, with monthly copies held for the term the client agreement specifies. When a client instructs us to delete data or ends the engagement, we delete or return it and confirm in writing.
7. Your choices
If your information is in a platform we operate, it is there because you do business with one of our clients. Requests to access, correct, or delete it should go to that client, who controls the data. We support every such request the client passes to us. You can also write to us directly and we will route it.
8. Children
Our website and platforms are for businesses. They are not directed at anyone under 18 and we do not knowingly collect data from minors.
9. Changes to this policy
When this policy changes, the new version is posted here with an updated effective date. Material changes affecting a client's data are communicated to that client directly.
10. Contact
Novogn LLC
garrett@novogn.llc