PRIVACY POLICY
Effective Date: June 1, 2026 | Railstor LLC
Railstor LLC ("Railstor," "we," "us," or "our") operates the Railstor rail car storage management platform at railstor.com. This Privacy Policy describes how we collect, use, and protect information in connection with our services, including our integration with Intuit QuickBooks Online.
1. INFORMATION WE COLLECT
We collect the following categories of information:
- Account information: Usernames and email addresses for platform access, managed through AWS Cognito.
- Business data: Rail car storage contract details, car inventory records, facility information, carrier (car owner) contact information, and invoice data entered by authorized users.
- QuickBooks data: When you connect your QuickBooks Online account, we store QuickBooks Customer IDs (per invoicing entity) and QuickBooks OAuth access and refresh tokens required to authenticate API requests. We also store invoice amounts and line item details that are pushed to QuickBooks.
- Usage data: Standard server logs including IP addresses and request timestamps, retained by AWS infrastructure.
2. HOW WE USE YOUR INFORMATION
We use collected information solely to:
- Provide and operate the Railstor platform for rail car storage management
- Create and push invoices to QuickBooks Online on behalf of authorized users
- Look up and create QuickBooks customer records as directed by users
- Authenticate users and maintain session security
- Improve platform reliability and performance
We do not sell, rent, or share your data or QuickBooks data with any third parties except as necessary to operate the service (AWS infrastructure) or as required by law.
3. QUICKBOOKS DATA HANDLING
Railstor integrates with Intuit QuickBooks Online to enable invoice creation and customer management. Specifically:
- We request only the
com.intuit.quickbooks.accountingOAuth scope, which allows creating and managing invoices and customers. - QuickBooks OAuth tokens are stored securely in AWS DynamoDB and are used exclusively to make API calls on behalf of the authenticated user.
- We store QuickBooks Customer IDs to associate Railstor carrier records with QuickBooks customer records, avoiding duplicate customer creation.
- We do not read, export, or analyze your broader QuickBooks financial data beyond what is necessary to create invoices.
- You may revoke Railstor's access to your QuickBooks account at any time through your Intuit account settings.
4. DATA RETENTION
Business records including contracts, car data, and invoices are retained indefinitely unless you request deletion. QuickBooks OAuth tokens are retained until the connection is revoked or the account is deleted. We will accommodate data deletion requests within 30 days of receipt.
5. DATA SECURITY
All data is stored in AWS (us-east-2 region) using DynamoDB and S3. Access to the platform requires authentication through AWS Cognito. All data in transit is encrypted via HTTPS/TLS. API endpoints validate authentication tokens on every request.
6. ACCESS CONTROLS
Railstor is a private platform. Access is restricted to authorized users created manually by Railstor administrators. User accounts are managed through AWS Cognito with enforced password policies.
7. YOUR RIGHTS
You may request access to, correction of, or deletion of your personal data by contacting us. To disconnect Railstor from your QuickBooks account, visit your Intuit account settings and revoke access.
8. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Changes will be posted at this URL with an updated effective date.
9. CONTACT
For privacy inquiries, contact us at:
tpoland@takrail.com
Railstor LLC
3604 Frontage Rd, Bentonville, AR 72712