Privacy Policy
Effective August 11, 2026
Raincheck helps weather-exposed businesses measure what rain costs them. This policy explains what Ego Labs, Inc. collects, why, who else touches it, and how to get rid of it. It is written to be read, not to be survived.
What we collect
When you join the waitlist
Your email address, plus anything else you choose to enter: your name, business name, business type, location, which weather conditions affect you, a revenue band, how severely weather hits your business, whether lost revenue comes back later, and a free-text description. Every field except the email address is optional. If you used the interactive playground first, the figure you set there — what a rainy day costs you — is submitted with the form along with the estimates it produced, so we can see what prompted you to sign up.
When you connect QuickBooks
With your authorization, we read exactly two things from your QuickBooks company:
- your Profit and Loss report, summarized by day, on a cash basis — the daily revenue totals we compare against local rainfall
- your company name, so the page can show you which company is connected
We request Intuit’s accounting scope — the narrowest scope that includes the Profit and Loss report. Intuit does not offer a read-only version of it, so the permission you approve would technically allow writing to your books. Raincheck only ever reads, and only the two things above. We never request payroll or payments access, and we never read customer or vendor lists, employee records, or bank details. We never see your QuickBooks username or password — Intuit handles sign-in and we only ever receive a token.
Automatically
Our hosting and infrastructure providers record ordinary request data — IP address, timestamp, and browser user agent — as part of serving and securing the site. We do not use advertising or cross-site tracking cookies.
Your connection, and what we keep
Connecting QuickBooks gives us two tokens from Intuit: an access token, which lets us read the report described above, and a refresh token, which lets us obtain a new access token when that one expires. We hold both, encrypted with AES-256-GCM under a key held only by the application, so a copy of our database on its own does not yield working credentials. We never receive or store your QuickBooks password — Intuit handles sign-in.
Your browser holds a cookie, but it is only a pointer: it records which QuickBooks company this browser is connected to and carries no credential of any kind. It is encrypted, marked HttpOnly and Secure, and lasts 30 days.
We keep the connection until you end it. Disconnecting — from this site, or from inside QuickBooks — revokes our access with Intuit and deletes what we hold.
We save the daily revenue totals we read — only those, never the figures our model derives from them.
We keep them for product research: understanding how rain actually affects real businesses is how we work out whether this product should exist and how coverage should be priced. It also means you can return to your results without reconnecting, but research is the reason, and we would rather say so than describe it as a convenience feature. We do it by default rather than asking, and you can turn it off at any time.
You can delete it at any time. There is a Delete my data control on your results. It erases what we hold and stops us saving anything further, and we keep it that way until you tell us otherwise. Disconnecting deletes it too.
One honest caveat: our databases keep rolling backups for disaster recovery, so deleted figures can persist in those backups for a short period before they age out. We do not restore them, and nothing reads from a backup in normal operation — but it would be wrong to tell you deletion is instantaneous everywhere.
How we use it
- to calculate and show you how rainfall has affected your revenue
- for product research — measuring how weather affects real businesses, so we can judge whether this product is worth building and how coverage should be priced
- to contact you about early access, if you joined the waitlist
- to keep the service running, secure, and free of abuse
What we don’t do
- We do not sell your personal or business information.
- We do not share it with advertisers or data brokers.
- We do not use your accounting data to train machine-learning models.
- We do not disclose it to anyone outside the providers listed below, except where the law requires it.
Who else processes it
We rely on a small number of providers, all of whom are bound to protect it:
- Intuit — supplies the QuickBooks data you authorize us to read
- Amazon Web Services — application servers and databases, hosted in the United States
- Vercel — website hosting and delivery
How long we keep it
- Session cookie — 30 days, then it expires on its own
- Your QuickBooks tokens — until you disconnect or ask us to remove them
- Waitlist details — until you ask us to remove them
- Your daily revenue totals — until you delete them, disconnect QuickBooks, or ask us to remove them
- Server logs — 30 days, then deleted automatically
- Database backups — a short rolling window for disaster recovery, which may briefly outlive a deletion
Security
Traffic is encrypted in transit. Stored data is encrypted at rest. Your Intuit tokens are additionally sealed with authenticated AES-256-GCM encryption before they are written, so they are unreadable to anyone holding only a copy of the database. The session cookie is sealed the same way, so a tampered cookie is detected and rejected rather than trusted. Access to production systems is limited to least-privilege credentials scoped to the specific resources they need. No system is perfectly secure, and we do not claim otherwise.
Your choices
- Disconnect QuickBooks at any time. Use the disconnect control on the site, or revoke access from your Intuit account. Disconnecting revokes our access with Intuit and clears your session immediately.
- Delete your saved data. Use the Delete my data control on your results — it erases what we hold and stops further saving. Or email us and we will do it.
- Access, correct, or delete personal information. Email us. Depending on where you live you may have additional rights — including under the GDPR or the CCPA — and we honour those requests regardless of where you are.
- Leave the waitlist. Email us, or use the unsubscribe link in any message we send.
Children
Raincheck is a tool for businesses. It is not directed at children, and we do not knowingly collect information from anyone under 18.
Changes
If we change this policy we will update the effective date above, and for material changes we will tell waitlist members by email.
Contact
Privacy questions, access requests, deletion requests, or complaints: legal@ego.tech.
Something wrong with the product itself — a connection that won’t complete, figures that look off: help@ego.tech.