Legal & Policies
These documents govern your use of the HailesOnline Sync Dashboard.
Privacy Policy #
HailesOnline ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
Plain English summary: We collect your email address to identify your account. We never sell it, never share it with advertisers, and never store your password in plain text. That's it.
1.1 What we collect
- Email address — collected when your account is created. Used solely to identify you and allow you to sign in.
- Password hash — your password is irreversibly hashed using bcrypt before being stored. The original plain-text password is never written to disk or any log.
- Session data — a signed session token (containing only your user ID) stored in an HttpOnly cookie. This expires when you log out or the token reaches its maximum age.
- Sync activity logs — order IDs, customer names, amounts, and sync status from your WooCommerce store. This data belongs to you and is used solely to power the dashboard you see.
- IP address and request logs — standard web server access logs retained for up to 30 days for security and debugging purposes.
1.2 Security & Identity Verification
To protect your account from unauthorized access, we collect and store a hashed (anonymized) version of your IP address. This data is used solely to verify your identity during login attempts from unrecognized devices. Hashing ensures your actual IP address is not stored in a readable format in our primary activity logs.
1.3 What we do not collect
- We do not collect payment card details, bank account numbers, or any financial credentials.
- We do not collect your name, phone number, or any demographic information.
- We do not use third-party analytics or advertising trackers.
- We do not collect data about your behaviour outside of this application.
1.4 How we use your data
- To authenticate you and maintain your signed-in session.
- To display your WooCommerce-to-QuickBooks sync activity on the dashboard.
- To send transactional emails if you contact us at [email protected] (no marketing emails are sent).
- To investigate security incidents using access logs.
1.5 Data sharing
We do not sell, rent, trade, or otherwise share your personal data with any third party for commercial purposes. We do not share your email address with advertisers. Your data may be disclosed only:
- If required by applicable law or a valid legal order.
- To our hosting infrastructure provider (for server operation only — they do not process your data independently).
1.6 Third-Party Data Intermediation
By using this service, you authorize HailesOnline to act as a data intermediary. The service will periodically fetch order data from your WooCommerce store and transmit it to QuickBooks Online. We do not own your data; however, we process and store metadata (such as Order IDs, Customer Names, and Totals) required to maintain your sync logs and provide the Service.
1.7 Data retention
Your account data is retained for as long as your account is active. Sync logs are retained indefinitely by default; you may request deletion by contacting us. If you request account deletion, all personal data will be removed within 30 days.
1.8 Your rights (UK GDPR)
If you are based in the United Kingdom, you have the following rights under UK GDPR:
- Right of access — you may request a copy of the data we hold about you.
- Right to rectification — you may ask us to correct inaccurate data.
- Right to erasure — you may ask us to delete your data.
- Right to restrict processing.
- Right to data portability.
- Right to object to processing.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
Terms of Service #
By accessing or using the HailesOnline Sync Dashboard ("the Service"), you agree to be bound by these Terms of Service. If you do not agree, do not use the Service.
2.1 Permitted use
The Service is provided exclusively for the purpose of synchronising WooCommerce orders with QuickBooks Online for the account holder's own business. You may not:
- Use the Service for any unlawful purpose or in violation of any applicable law.
- Attempt to gain unauthorised access to any part of the Service or its infrastructure.
- Reverse engineer, decompile, or disassemble any part of the Service.
- Use automated tools to scrape, crawl, or bulk-download data from the Service.
- Resell, sublicence, or otherwise transfer access to the Service to any third party.
2.2 Account responsibility
You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account. You must notify us immediately at [email protected] if you become aware of any unauthorised use.
2.3 Third-party services
The Service integrates with WooCommerce and Intuit QuickBooks Online via their respective APIs. Your use of those platforms is governed by their own terms of service. We are not responsible for the availability, accuracy, or conduct of those third-party services.
2.4 Service availability
We aim to maintain high availability but do not guarantee uninterrupted access to the Service. Planned or emergency maintenance may result in temporary downtime. We will endeavour to communicate scheduled maintenance in advance.
2.5 Technical Configuration & User Responsibility
The Service allows users to manually input sensitive API credentials, including but not limited to WooCommerce Consumer Keys and QuickBooks Realm IDs. You acknowledge that incorrect configuration of these settings can result in application failure, data loss, or sync errors. HailesOnline is not responsible for any financial discrepancies or operational downtime caused by user-configured settings.
2.6 Automated Syncing
The Service includes automated background processes that may attempt to sync data without manual intervention. It is your responsibility to regularly review your "Activity Logs" to ensure that automated syncs are performing accurately.
2.7 Limitation of liability
To the fullest extent permitted by applicable law, HailesOnline shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of or inability to use the Service, including but not limited to lost profits, lost data, or business interruption.
2.8 Modifications to these terms
We reserve the right to update these Terms at any time. Continued use of the Service after any change constitutes your acceptance of the revised Terms. The "last updated" date at the top of this page will always reflect the most recent revision.
2.9 Governing law
These Terms are governed by and construed in accordance with the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
End User Licence Agreement #
This End User Licence Agreement ("EULA") is a legal agreement between you ("the User") and HailesOnline ("the Licensor") for the use of the HailesOnline Sync Dashboard software and service.
By accessing the Service, you confirm that you have read, understood, and agreed to this EULA. If you are accepting on behalf of a business, you confirm that you have the authority to bind that business to these terms.
3.1 Grant of licence
Subject to the terms of this EULA, HailesOnline grants you a limited, non-exclusive, non-transferable, revocable licence to access and use the Service solely for your internal business purposes.
3.2 Restrictions
You must not:
- Copy, modify, adapt, translate, or create derivative works of the Service or any part thereof.
- Sell, sublicence, rent, lease, or otherwise transfer your rights under this EULA to any third party.
- Remove, obscure, or alter any proprietary notices, labels, or marks on the Service.
- Use the Service in any way that violates any applicable local, national, or international law or regulation.
- Attempt to circumvent any technical measures used to protect the Service.
3.3 Intellectual property
The Service, including all software, design, text, graphics, and documentation, is owned by HailesOnline and is protected by copyright and other intellectual property laws. This EULA does not transfer any ownership rights to you.
3.4 Updates and changes
HailesOnline may, at its sole discretion, release updates, patches, or new versions of the Service. This EULA applies to all such updates unless a separate licence accompanies them.
3.5 Termination
This EULA is effective until terminated. Your rights under this EULA will terminate automatically without notice if you fail to comply with any of its terms. Upon termination, you must cease all use of the Service. HailesOnline reserves the right to suspend or terminate your access at any time for any violation of these terms.
3.6 Disclaimer of warranties
The Service is provided "as is" and "as available" without warranties of any kind, either express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, or non-infringement. HailesOnline does not warrant that the Service will be error-free or uninterrupted.
3.7 Indemnification
You agree to indemnify, defend, and hold harmless HailesOnline and its affiliates from any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in any way connected with your use of the Service or your breach of this EULA.
Data We Store #
This section provides a transparent, complete reference of every category of data stored by the Service.
| Data | Why we store it | Plain text? | Shared? |
|---|---|---|---|
| Email address | Account identity and login. Used to look up your account when you sign in. | Yes — stored as entered | Never sold or shared with third parties |
| Password | Authentication | No — bcrypt hashed only. The plain-text password is never written anywhere. | Never |
| QuickBooks tokens | OAuth 2.0 access and refresh tokens for your QuickBooks account, used to push invoices. | Stored encrypted at rest | Sent to Intuit QuickBooks API only |
| WooCommerce API keys | Consumer key and secret used to fetch orders from your store. | Stored encrypted in system config | Sent to your WooCommerce store only |
| Order sync logs | Records of each sync attempt: WooCommerce order ID, customer name, amount, status, and any error. | Yes | Never — visible only to you in the dashboard |
| Tax mappings | Your configured mappings between WooCommerce tax classes and QuickBooks tax IDs. | Yes | Never |
| App settings | Sync frequency, currency preference, auto-retry toggle. | Yes | Never |
Passwords: We use bcrypt with a cost factor of 12 or higher. This means even if our database were compromised, your password could not be recovered from the stored hash.
5.1 Where data is stored
All data is stored in an SQLite database on the server hosting the application. No data is stored in third-party cloud databases, data brokers, or analytics platforms.
5.2 Data deletion
You may request deletion of your account and all associated data at any time by emailing [email protected]. Deletion will be completed within 30 days of the request.
Contact Us #
If you have any questions about these policies, wish to exercise your data rights, or need to report a security concern, please contact us:
We aim to respond to all enquiries within 2 working days.