Last updated: May 27, 2026
This Privacy Policy describes how Sekra Living LLC ("Sekra," "we," "us," or "our") collects, uses, and protects information in connection with the Sekra Employee Hub application ("Application"). The Application is an internal business tool used exclusively by authorized Sekra employees and contractors.
Authentication data. When you sign in, we collect your name and email address from your Google account via Google OAuth. We do not receive or store your Google password.
Usage data. We log actions performed within the Application, including invoice submissions, approvals, rejections, and system configuration changes. These logs are used for audit, compliance, and operational purposes.
Financial data. The Application connects to Intuit QuickBooks Online on your behalf to read and write accounting data (budget information, journal entries, vendor records). It connects to Mercury Bank to stage payment requests. We access only the data necessary to perform these functions.
Device and session data. We may collect standard log data including IP address, browser type, and session timestamps for security and troubleshooting purposes.
We use the information collected to operate and maintain the Application, authenticate users and enforce access controls, process invoice approval workflows, create accounting entries in QuickBooks, stage payment requests in Mercury, maintain audit logs for compliance, and troubleshoot issues and improve the Application.
We do not sell, rent, or share your personal information with third parties for marketing purposes. We share data only as follows:
Intuit Inc. — QuickBooks data is transmitted to and from Intuit's servers as part of the accounting integration. Intuit's privacy policy governs their handling of this data.
Mercury Financial LLC — Payment staging data is transmitted to Mercury's API. Mercury's privacy policy governs their handling of this data.
Service providers — We may use hosting and infrastructure providers (including Base44, a Wix company) who process data on our behalf under appropriate data processing terms.
Legal compliance — We may disclose information if required by law or to protect the rights, property, or safety of Sekra or others.
Audit logs and invoice records are retained for a minimum of seven years in accordance with standard accounting and recordkeeping requirements. User account data is retained for the duration of your engagement with Sekra and deleted upon request following termination.
We implement reasonable technical and organizational measures to protect data against unauthorized access, alteration, or disclosure. Access to the Application is restricted to authorized @sekra.com accounts and enforced via Google OAuth. Sensitive credentials (API tokens) are stored in encrypted form and accessible only to system administrators.
As a Sekra employee or contractor, you may request access to your personal data held in this Application, correction of inaccurate data, or deletion of your account data by contacting the system administrator at todd.butler@sekra.com.
The Application uses the following third-party services, each governed by their own privacy policies:
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the Application after changes constitutes acceptance of the updated policy.
For privacy-related inquiries: legal@sekra.com System administrator: todd.butler@sekra.com