MonuOS Privacy Policy
Last updated: July 8, 2026
This policy explains what information MonuOS collects, how it is used, and the choices you have. It covers the MonuOS platform (monuos.com, app.monuos.com), hosted shop websites and memorial pages, and optional integrations such as QuickBooks® Online. In most cases MonuOS processes shop-entered business data on behalf of the shop that owns the account.
1. Account and contact data we collect
- Account data: name, email address, password (stored as a secure hash by our authentication provider), shop/business name, and role within the shop.
- Billing data: subscription plan and payment status. Card details are collected and stored by Stripe, our payment processor — MonuOS never stores full card numbers.
- Usage and device data: logs and diagnostics needed to run and secure the Service. On the public marketing site only, we use Google Analytics with page-level data — marketing pages contain no customer records.
2. Shop business data we process
Shops enter business records into MonuOS: customer names and contact details, order and memorial details (which may include names, dates, and photos of deceased persons provided by families), design files, invoices, payment records and balances, appointment and install schedules, employee time-clock entries, and messages. This data belongs to the shop; MonuOS processes it to provide the Service and isolates it per shop with database row-level security that is verified by automated tests on every release. MonuOS does not sell this data.
3. QuickBooks data accessed through OAuth
- If a shop connects QuickBooks Online, MonuOS receives OAuth tokens from Intuit and the QuickBooks company ID. Tokens are encrypted at rest with a key held outside the database, are never exposed to the browser, and are used only server-side.
- With the accounting scope the shop approves, MonuOS reads accounting records — customers, invoices, payments, estimates, and items — to provide import previews, historical imports, and (where available) shop-confirmed exports. MonuOS reads only what these features need.
- MonuOS never changes or deletes QuickBooks data without an explicit, admin-confirmed action, does not use QuickBooks data for advertising, does not use it to train AI models, and does not sell it.
- Disconnecting the integration (Settings → Integrations) revokes MonuOS's access with Intuit and deletes our stored tokens. Data previously imported into MonuOS remains in the shop's account until the shop removes it.
4. How data is used for sync, import, and export
Integration data flows only at the shop's direction: imports bring external records into the shop's MonuOS account as historical data; exports are prepared as drafts, shown in a preview, and sent only after an administrator confirms; external record IDs are stored to prevent duplicates. Nothing is silently overwritten in either system.
5. Third-party processors
MonuOS uses a small set of processors to run the Service:
- Supabase — database, authentication, file storage, and serverless functions (primary application hosting).
- Netlify — web hosting and content delivery.
- Stripe — subscription billing and, where a shop enables online payments, payment processing for that shop's customers.
- Intuit / QuickBooks Online — accounting integration, only when a shop connects it.
- A text-messaging carrier service — business text messaging, when a shop enables texting.
- Resend — transactional email delivery (receipts, reminders, notices).
- AI providers (such as OpenAI, Anthropic, and Replicate) — power optional features like image preparation and writing assistance; content is sent to them only when a shop uses those features.
- Google Analytics — public marketing-site analytics only.
Each processor receives only what its function requires and is bound by its own data protection terms.
6. Data retention
Shop data is retained while the account is active so the shop's records remain intact. Operational logs are kept for a limited period for security and troubleshooting. After a subscription ends, shop data is retained for a reasonable wind-down period (so a returning or exporting shop doesn't lose its records) and then becomes eligible for deletion. Encrypted integration tokens are deleted immediately on disconnect.
7. Deletion and disconnect requests
Shops can disconnect any integration at any time in-app. To request deletion of a shop account and its data — or, for individuals whose information appears in a shop's records (for example on a memorial page), to request removal — email support@monuos.com. Where the data belongs to a shop, we will route or verify the request with that shop as the data owner. We honor applicable legal rights to access, correct, and delete personal information.
8. Security practices
- Encryption in transit (TLS) everywhere; encryption at rest for stored data; additional application-layer encryption for integration tokens.
- Per-shop tenant isolation enforced with database row-level security and verified by an automated isolation test suite on every release.
- Role-based access inside each shop; private customer links (tracking, invoices, proofs) use unguessable tokens, are excluded from search indexing, and are revocable and expiring.
- Secrets and credentials live in managed secret stores, never in client code.
- No security program is perfect; if we learn of a breach affecting your data we will notify affected shops as required by law.
9. Children
The Service is for businesses and is not directed to children under 13. Memorial content about any person is provided and controlled by the shop and the family it serves.
10. Changes and contact
We may update this policy from time to time; material changes will be announced in-app or by email. Questions or requests: support@monuos.com.