Privacy Policy
Effective Date: March 19, 2026
Happy Medium ("we," "us," or "our") operates the Happy Medium platform (the "Service"), a multi-tenant software-as-a-service platform for experience-based businesses. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our Service.
1. Information We Collect
We collect the following categories of information:
Account data: name, email address, phone number, and authentication credentials when you create an account.
Payment data: payment processing is handled by Stripe. We do not store credit card numbers. Stripe provides us with a token reference, last four digits, and card brand for display purposes.
Reservation and booking data: party size, date/time preferences, special requests, and booking history.
QuickBooks Online data (business owners only): when a business owner connects their QuickBooks Online account, we access chart of accounts, journal entries, bills, vendors, and related financial data solely for accounting synchronization. This access occurs only at the business owner's explicit request.
Usage data: pages visited, features used, device type, browser type, and IP address.
2. How We Use Your Data
We use your information for the following purposes:
Service delivery: processing reservations, managing tabs, and providing the core booking and point-of-sale experience.
Payment processing: collecting deposits and processing payments through Stripe, including Stripe Terminal for in-person transactions.
Accounting synchronization: syncing financial data with QuickBooks Online when a business owner has connected their account.
Error tracking: monitoring application errors via Sentry using anonymized and aggregated data to improve reliability.
Communications: sending reservation confirmations, reminders, and account notifications via Resend (email) and Twilio (SMS).
3. Data Storage and Security
Application data is stored in PostgreSQL on Railway, encrypted at rest.
QuickBooks Online OAuth tokens are encrypted using AES-256-GCM before storage.
All data in transit is protected by TLS 1.2 or higher, with HTTP Strict Transport Security (HSTS) enforced.
Session cookies are configured with httpOnly, secure (in production), sameSite: lax, and a 7-day sliding expiration.
4. Data Retention
Account and booking data is retained while your account is active and for a reasonable period thereafter for legal and business purposes.
QuickBooks Online OAuth tokens are revoked immediately upon disconnect.
Session data has a 7-day time-to-live and is automatically purged.
5. Data Deletion
You may request deletion of your account and personal data by contacting us. Business owners can disconnect their QuickBooks Online integration at any time through their dashboard, which revokes OAuth tokens and clears reference data. Business owners may also choose to purge all QBO-imported entries upon disconnection.
6. Third-Party Services
We share data with the following third-party services as necessary:
Stripe: payment processing and point-of-sale terminal services.
Intuit / QuickBooks Online: accounting synchronization (only when a business owner connects their account).
Sentry: error tracking and application monitoring.
Resend: transactional email delivery.
Twilio: SMS notifications.
Railway: infrastructure and database hosting.
Cloudinary: image hosting and optimization.
Mapbox: location and mapping services.
7. Your Rights
You have the right to:
Access the personal data we hold about you.
Request correction of inaccurate data.
Request deletion of your data.
Request a portable copy of your data.
Withdraw QuickBooks Online consent at any time via the dashboard disconnect feature.
8. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at privacy@practical-magic.co.