Privacy Policy
Last updated: 2026-05-10
Stickman Sound, Inc. ("we", "us", "Provider") operates the Stickman HQ software application (the "Software"). This Privacy Policy describes what information the Software collects, how it is used, and how it is protected. The Software is an internal-use tool — it is not offered for public sign-up.
1. Information We Collect
From the operator
- Account credentials — email and a salted, PBKDF2-hashed password for sign-in.
- Estimate / invoice / crew records entered by the operator: company names, contact names, phone numbers, email addresses, line-item descriptions, rates, and dates.
- QuickBooks Online OAuth tokens — refresh and access tokens issued by Intuit. Stored server-side at file-system permission 600. Never sent to the browser.
From QuickBooks Online (with operator authorization)
- Customer records, vendor records, service items, invoices, and estimates from the operator's QBO realm. Used to reconcile against local records and to push approved estimates back as invoices.
Automatic / device data
- Standard request metadata (IP address, user-agent) recorded in operational logs for debugging and rate-limiting. Not retained beyond 30 days.
The Software does not collect biometric data, location data, or browsing history. The Software does not track users across other websites.
2. How We Use Information
- To provide the Software's core functionality (estimating, invoicing, crew scheduling, call-sheet generation).
- To synchronize approved records with the operator's QuickBooks Online realm.
- To send transactional emails (password resets, user invitations) via Resend.
- To debug and operate the Software.
We do not sell, rent, or share User data with third parties for marketing purposes. We do not show advertising.
Text Messaging (SMS) — Consent & Mobile Information
Stickman Sound, Inc. sends scheduling & logistics text messages (job availability
checks, booking confirmations, call times, day-of schedule changes) only to its own crew members and
contractors who gave express written consent via the unchecked-by-default checkbox on their private
crew-portal account page — see how crew opt in and the full
Messaging Policy. Message frequency varies; message & data rates may
apply. Reply STOP to opt out at any time, HELP for help.
No mobile information will be shared with third parties or affiliates for marketing or
promotional purposes. Text messaging originator opt-in data and consent (mobile phone
numbers and SMS consent records) are never sold, rented, or shared with any third party. Mobile
numbers are used solely to deliver the scheduling messages described above, via our SMS provider
(Twilio) acting strictly as a service provider on our behalf.
3. Third-Party Services
The Software integrates with the following third parties. Each receives only the data necessary to perform its function. Their privacy practices are governed by their own policies:
- Intuit (QuickBooks Online) — receives operator-initiated invoice/customer pushes when the operator clicks "Send to QBO." Intuit privacy
- Resend — sends operator-initiated transactional emails (password resets and invitations). Resend privacy
- Twilio — delivers our scheduling/logistics text messages to consented crew members; receives only the recipient's mobile number and the message content, strictly as a service provider. Twilio privacy
- Anthropic — receives natural-language prompts the operator types into the in-app AI assistant. No User data is sent unless the operator explicitly types it. Anthropic privacy
- Open-Meteo — receives a city name to retrieve weather forecasts for shoot locations. No User identifiers are sent.
- Fly.io — hosts the public-facing portion of the Software. Fly.io privacy
4. Data Storage and Security
- In transit: HTTPS / TLS 1.2+ for all public endpoints. The Stickman HQ server enforces HSTS via Fly.io's automatic certificates.
- At rest: server-side state files (OAuth tokens, post-production board, password-reset tokens, snapshot backups) live on a Fly.io persistent volume with restrictive POSIX permissions (chmod 600).
- In the browser: operator's working state lives in the browser's
localStorage on the operator's own device.
- Authentication: passwords are hashed with PBKDF2-SHA-256 (200,000 iterations + per-install salt). The plain password is never persisted.
- OAuth: QuickBooks Online tokens follow Intuit's authorization-code flow. Refresh tokens never leave the server. CSRF state is verified on every callback.
5. Data Retention and Deletion
The operator controls all data stored by the Software:
- Disconnecting QuickBooks Online via the in-app toolbar deletes the OAuth tokens immediately.
- Clearing browser
localStorage removes the operator's working state.
- Operational logs are retained no longer than 30 days.
- Snapshot backups created by the operator can be downloaded and deleted at the operator's discretion.
The Software does not retain data after the operator initiates deletion; data is purged on the next storage-cleanup cycle (typically immediate, never longer than 24 hours).
6. Children's Privacy
The Software is not directed at, and is not intended for use by, children under the age of 13. We do not knowingly collect information from children.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by a new "Last updated" date at the top of this page.
8. Contact
Questions, requests, or concerns about this Privacy Policy or your data:
stickmansound@gmail.com