White Rabbit Calendar to Invoice

Privacy Policy

Last updated: September 9, 2026

White Rabbit Automation ("White Rabbit", "we") operates a private software connector that turns calendar entries into QuickBooks Online invoices. This policy explains what the connector reads, what it keeps, where it keeps it, and who else can see it.

The connector is not a public product. It is set up for one business at a time, at that business's request, and it is used only by that business.

1. Who to contact

White Rabbit Automation, doing business as White Rabbit105 Hillside Blvd, Lakewood, NJ 08701, United Statesdev@whiterabbit.is

2. What the connector reads

From your Google Calendar, read-only. For each event on the calendar you share with us: its identifier, title, description, start and end times, a link back to the event, and the marker Google uses to say an event has changed.

Event titles contain your customers' names, and event descriptions contain the services and amounts you type for that trip. That is the material the invoice is made from.

The access is read-only. The connector cannot create, change or delete anything in your calendar.

From QuickBooks Online, read and write. It reads your customer list, including the billing email addresses you have on file, your product and service list, invoices dated on the days it is working with, and your company's invoice numbering preference. It creates invoices and asks QuickBooks to email them.

It never edits or deletes anything that already exists in your QuickBooks company. It requests one permission only, accounting. It has no access to payments, payroll or banking.

3. What it keeps, and for how long

Kept on our server:

  • One row per calendar event: identifier, title, start and end, the link back to the event, its status, the invoice identifier once one exists, and timestamps. If a trip could not be invoiced, the reason and the single line of your text that caused it are kept, so the next morning's email can quote it back to you.
  • A marker from Google, so each night's run only asks for what changed.
  • Your QuickBooks connection tokens, encrypted.

The event description itself is not kept. It is read, used to work out what to bill, and discarded, apart from the single line quoted above when a trip could not be invoiced.

Not kept: card numbers, bank details, payroll data, or your QuickBooks and Google passwords. Your customers' email addresses are read from QuickBooks at the moment an invoice is sent and are not copied into our database.

How long:

  • Run history: the last 500 runs.
  • Connection tokens: until you disconnect, at which point they are deleted.
  • Event rows: for as long as the connector is in service, and for ninety days after it stops. The connector uses them to guarantee it never invoices the same trip twice, so deleting them sooner would risk a duplicate invoice. After those ninety days they are deleted.

4. Where it is kept

In the United States, in Ashburn, Virginia, on infrastructure operated by Railway.

5. How it is protected

  • QuickBooks connection tokens are encrypted where they are stored, using Fernet (AES-128-CBC with an HMAC-SHA256 signature). The key is held in the hosting platform's environment configuration and is never in our source code.
  • Traffic to Google and Intuit travels over HTTPS. Email is sent over an encrypted connection.
  • The connector's maintenance endpoints require a secret token. There is no public login page and there are no user accounts.
  • Secrets are never written to logs. Log lines record the path of a request but never its query string, because QuickBooks queries carry customer names.

Other stored fields, such as event titles, are not separately encrypted by the application. They are protected by the access controls of the hosting platform.

6. Who else sees it

Nobody outside your business and White Rabbit.

  • We do not sell it, rent it, or use it for advertising.
  • We do not use it to train anything.
  • The nightly summary email goes to a single address, the one you give us.
  • White Rabbit staff with production access can see this data in the course of supporting you.

We rely on these service providers: Railway (hosting, United States), Intuit (QuickBooks Online), and Google (the Calendar API, and the mailbox the summary email is sent from).

7. Disconnecting, and deletion

You can disconnect the connector at any time from within QuickBooks. That stops it reading or writing anything immediately, and the stored tokens are deleted.

To have the rest deleted, write to dev@whiterabbit.is. We will delete the connector's database and confirm within 30 days. Invoices it already created live in your own QuickBooks company. They are yours, and we do not remove them.

8. Changes to this policy

Any change is posted on this page, with the date at the top updated.