OpenProfit

Privacy Policy

Last updated: October 6, 2026

This policy explains what personal information OpenProfit collects, why, and what you can do about it. OpenProfit is operated by Lobbystack Inc., Montreal, Quebec, Canada ("we", "us"). It covers the hosted service at openprofit.dev. If you run the open-source software on your own server, we receive nothing from it unless you switch on the usage ping described in section 5.

1. What we collect

Account information. Your email address, and if you sign in with Google or GitHub, the name, email and avatar they share with us. We never see your password for those services.

Workspace information. The workspace name, base currency, products you create, and the settings you choose.

Provider credentials. The API keys and tokens you give us to connect a provider. They are encrypted at rest with a key that is not stored with the data, and decrypted only to call that provider.

Financial data from providers. Transactions, fees, refunds, subscriptions, customer counts and usage charges that the providers you connect report to us. This can include your customers' transaction amounts and dates. It does not include your customers' names, emails or card details; we do not request those fields.

Billing. If you pay for a plan, Polar Software Inc. collects your name, email, billing address and payment details as merchant of record. We receive your email, the plan, and the subscription status. We do not receive card numbers.

Usage and technical data. Server logs with IP address, browser and request details, kept for 30 days for security and debugging. We do not run third-party analytics or advertising trackers on the Service.

Cookies. One session cookie to keep you signed in, and one local setting for the theme. No advertising or cross-site cookies.

Emails you send us. Support messages and their content.

2. How we use it

Under the GDPR, our legal bases are performance of our contract with you, our legitimate interest in running and securing the Service, and consent where we ask for it.

3. Who we share it with

We do not sell personal information and we do not share it with advertisers. We share it only with the services that run OpenProfit:

Service Purpose Location
Railway Hosting and database United States
Polar Software Inc. Payments, invoices, tax, as merchant of record United States and EU
Resend Sending sign-in links, alerts and the weekly email United States
Google, GitHub Sign-in, if you choose them United States
Frankfurter (European Central Bank data) Exchange rates; receives no personal data EU

Each provider you connect receives API calls from us using your credential. Those calls contain nothing about you beyond the credential itself.

We may also disclose information when the law requires it, to enforce our terms, or to protect the rights and safety of users or the public. If we sell or transfer the business, your information may transfer with it under this policy.

4. Where data lives

The Service runs on servers in the United States. If you are in Canada, the European Economic Area, the United Kingdom or Switzerland, your information is transferred there. For transfers from the EEA, UK and Switzerland we rely on standard contractual clauses with our subprocessors.

5. Telemetry from self-hosted copies

A self-hosted copy of the open-source software sends us nothing by default. If its owner switches on the usage ping, it sends once a day: a hashed instance id that cannot be reversed, the software version, and counts of workspaces, products and connections per provider. No names, emails, amounts or keys. We use it to know which connectors matter and which versions are in use.

6. How long we keep it

7. Security

Credentials are encrypted with AES-256-GCM. Traffic is encrypted in transit. Access to production systems is limited to the people who run the Service. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the authorities as the law requires.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict some processing, to withdraw consent, and to complain to a supervisory authority. In Canada this includes rights under PIPEDA and Quebec's Act respecting the protection of personal information in the private sector; in the EEA and UK, rights under the GDPR; in California, rights under the CCPA.

You can do most of this yourself: edit the workspace in Settings, remove connections and products, and delete the workspace. For anything else, email hello@openprofit.dev. We respond within 30 days and may ask you to confirm your identity first.

Quebec residents: the person in charge of the protection of personal information is the operator named above, reachable at the same address.

9. Children

The Service is not directed at anyone under 18, and we do not knowingly collect their information.

10. Changes

We may update this policy. We will post the new version at openprofit.dev/privacy with a new date, and for material changes we will email you or show a notice in the Service before they take effect.

11. Contact

hello@openprofit.dev