This Privacy Policy explains how BoostSync for Xero and Airtable ("we," "us," or "our") handles information when you use the Service to connect Airtable and Xero.
Information We Handle
The Service may handle Airtable account, workspace, base, table, view, record, field, and user information needed to authenticate users, configure table mappings, and write synced values. It may also handle Xero organization, sales invoice, quote, contact, status, amount, due or expiry date, payment, and related document information needed for the workflows you initiate.
OAuth and Credentials
Airtable and Xero connections use OAuth authorization. You enter your Airtable or Xero username and password directly with the relevant provider during OAuth authorization; the Service does not receive or store those passwords. The Service may store encrypted OAuth tokens so it can perform the sync actions you authorize.
How We Use Information
We use information to authenticate users, connect Airtable and Xero accounts, store table and field-mapping configuration, import or link Xero invoices and quotes, write mapped Xero values into Airtable records, troubleshoot sync behavior, maintain security, and provide support.
Authorization and Permissions
A Creator or Owner must authorize the Airtable base before the Service can read its schema or write synced records and fields. Xero access is read-only for sales invoices and quotes. The data and actions available to each user also depend on the permissions configured in Airtable and Xero.
Sharing and Subprocessors
We do not sell personal information. Information may be processed by Airtable, Xero, hosting, database, logging, security, analytics, and support providers as needed to operate and support the Service.
Retention and Deletion
We retain configuration, token, sync, and support information for as long as needed to provide the Service, meet legal obligations, resolve disputes, maintain security, and support customers. You can disconnect Airtable, remove a Xero organization, or contact support to request deletion of Service-controlled records where applicable. Disconnecting or removing a connection does not delete values already written into Airtable.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect Service data, including encrypted storage of OAuth tokens. No system can be guaranteed to be completely secure, and you are responsible for managing access and permissions in Airtable and Xero.
Contact
Questions about this Privacy Policy can be sent to [email protected].