Privacy Policy

Effective June 2026

This page describes how WebTechPro handles personal and accounting data when used together with Xero, QuickBooks Online and Stripe. We recommend having a privacy lawyer in your jurisdiction review it before relying on it as your sole notice.

1. Who we are

WebTechPro ("WebTechPro", "we", "us", "our") provides a revenue automation platform ("Win!") that lets merchants ("you", "Merchant") automate invoice collection — including hosted payment links, autopay, automated reminders, and accounting reconciliation — via the Merchant's own Stripe account, using invoice data pulled from Xero or QuickBooks Online (collectively the "Accounting Platforms").

For the purposes of GDPR and similar laws: with respect to data about you (the Merchant) we act as data controller; with respect to data about your invoiced customers we act as a data processor on your behalf.

2. Data we collect

  • Account data — your name, email, business name and country, collected via your sign-in.
  • Accounting data — invoices, contacts, balances, currencies, invoice numbers, customer email addresses, payment status and invoice URLs read from Xero or QuickBooks Online under the OAuth scopes you grant. We do not request payroll, journal, chart-of-accounts write access, bank-feed credentials, or any scope we do not need to operate the payment workflow.
  • Payment data — your Stripe Connect account ID, charge/payout capability flags, payment intent IDs, refund IDs and amounts. Card numbers, CVCs and bank account numbers are entered directly into Stripe Elements and Stripe Checkout and never touch our servers.
  • Operational logs — request and response metadata (timestamps, IP, user agent, endpoint, status code) used for debugging, security monitoring and fraud prevention.

3. OAuth scopes we request

When you connect an Accounting Platform we request only the minimum scopes needed to import invoices and reconcile payments:

  • Xeroaccounting.transactions, accounting.contacts, accounting.settings.read, offline_access, openid profile email.
  • QuickBooks Onlinecom.intuit.quickbooks.accounting, openid profile email.
  • Stripe — Standard Connect account link (you authorise charges and refunds on your own Stripe account; we never receive your Stripe password).

You can revoke our access at any time on the Connections page, or directly inside Xero (My Xero → Connected Apps), QuickBooks Online (Settings → Apps → My Apps) or Stripe (Settings → Connected Apps).

4. How we use it

  • To import and display your invoices, contacts and balances.
  • To create hosted payment links, PaymentIntents and SetupIntents on your connected Stripe account.
  • To reconcile successful payments back to the original invoice in Xero or QuickBooks Online by recording a payment against that invoice.
  • To send transactional notifications — invoice email, payment receipt, reminder — to you and to your invoiced customers via a third-party email delivery provider.
  • To prevent fraud, debug failures and meet our legal obligations.

5. How we DO NOT use it

  • We do not sell, rent or license data obtained from Xero, QuickBooks Online or Stripe to any third party.
  • We do not use Accounting Platform data for advertising, profiling unrelated to the service, or training third-party AI models.
  • We do not access invoice data for any purpose other than operating the service for you.

6. Sharing

We share data only with the sub-processors needed to operate the service:

  • Xero — accounting data source / destination
  • Intuit (QuickBooks Online) — accounting data source / destination
  • Stripe — payment processing and card / bank tokenisation
  • Transactional email provider — delivery of invoice emails, receipts and reminders
  • Supabase — authentication and PostgreSQL database hosting
  • Railway / Replit — application hosting and logging

Each sub-processor is bound by its own privacy policy and data processing agreement. We disclose data to law enforcement only when compelled by valid legal process.

7. Retention

WebTechPro is a revenue automation platform, not your system of record. We do not undertake to retain invoice, payment or accounting metadata for any defined period. The authoritative, long-term record of your invoices, payments and customer ledger lives in your own Xero or QuickBooks Online organisation, which you control and back up under your accounting platform's own retention policies.

Operational copies of invoice and payment metadata that pass through our service exist only for as long as is reasonably necessary to deliver the service (for example, to route a webhook, mark an invoice paid in your books, or display recent activity in the dashboard) and may be deleted at any time. OAuth refresh tokens are deleted immediately when you disconnect a platform on the Connections page or close your account.

To delete your WebTechPro account and the personal data we hold about you, open a support ticket; we will process the request within 30 days.

8. Security

OAuth access and refresh tokens are encrypted at rest. All traffic to and from the service runs over TLS 1.2+. Card and bank details are tokenised inside Stripe Elements and Stripe Checkout; we are never in possession of raw card numbers or CVCs. Production database access is restricted to named engineers and is audit-logged. We will notify affected merchants and (where required) regulators within 72 hours of confirming a security breach that compromises personal data.

9. International transfers

Data may be processed in the United States, the European Union and other countries where our sub-processors operate. We rely on the Standard Contractual Clauses and our sub-processors' own transfer mechanisms (e.g. EU-US Data Privacy Framework) to lawfully move data across borders.

10. Your rights

Depending on where you live (EU/UK GDPR, California CPRA, Australia Privacy Act, etc.) you may have rights to access, correct, port, delete or restrict processing of your personal data, and to object to processing or withdraw consent. Open a support ticket to exercise any of these rights. We will respond within 30 days. You may also lodge a complaint with your local supervisory authority.

11. Children

The service is intended for businesses. We do not knowingly collect personal data from anyone under 18.

12. Changes

We may update this policy. Material changes will be announced in-app or by email at least 14 days before they take effect.

13. Contact

Privacy questions, rights requests and security disclosures: please open a support ticket and mark the subject line accordingly (e.g. "Privacy request" or "Security disclosure"). It routes directly to the right team.