Privacy Policy

Last updated: June 30, 2026

What BleuOS is

BleuOS is a private, internal financial dashboard operated by a single business owner (Bleu La La / Hush Baby). It connects the owner's own business accounts to show true profit and cash position. It is not a consumer-facing product; there are no third-party end users.

What data we access

  • Plaid (read-only): account balances, transactions, and liabilities (loan/credit balances and APRs) for the owner's linked bank and card accounts. We request only the Transactions and Liabilities products. We cannot move money — no payment, transfer, or auth products are enabled. We never see or store bank login credentials; those are entered directly into Plaid's secure flow.
  • Shopify: order/sales and unit counts per sales channel, via the Admin API (read-only).
  • SellerBoard: Amazon profit, stock, and cost-of-goods reports, via report links.

How we use it

Solely to display the owner's own financial metrics (profit, cash, debt, inventory, fulfillment cost) inside this dashboard. We do not sell, rent, share, or use the data for advertising, and we do not share it with any third party beyond the service providers below that operate the app.

How we protect it

  • All data is transmitted over HTTPS/TLS 1.2+.
  • Data and access tokens are stored in Supabase (PostgreSQL), encrypted at rest, with row-level security; API keys and tokens are kept as encrypted environment variables, never in source code.
  • Access requires email + password sign-in and is limited to the owner; MFA is enabled.
  • Sub-processors: Vercel (hosting), Supabase (database/auth), Plaid (bank data), Shopify, and SellerBoard — each under their own security and privacy terms.

Data retention & deletion

Data is retained only while it is useful to the dashboard and is refreshed regularly. The owner can delete stored data or revoke connected accounts at any time — by disconnecting an institution in Plaid (or the bank's connected-apps settings), removing the relevant rows in the database, or revoking the Shopify/SellerBoard links. Revoking a connection stops further data access and removes the stored access token.

Consent

The owner consents to the collection and processing of this data by explicitly linking their own accounts through each provider's authorization flow (e.g. Plaid Link).

Contact

Questions about this policy or your data: Mordechai Strasser, Owner — strasser.mordechai@gmail.com.