Trust

Where your data lives, and who can reach it.

Written for a treasurer rather than an engineer. If something here is not specific enough for your board, write to hello@waterline.app and I will answer it properly.

Storage

Postgres, row-level

Every row is scoped to a company and enforced by the database, not by the application. A request for another company's data returns nothing.

Access

You decide, per person

Owner, admin, editor, viewer. Advisors hold no seat and cannot edit anything. Removing somebody ends their access immediately.

Export

Your model, any time

One JSON file, re-importable, from Company settings. No request, no waiting period, no lock-in that depends on our goodwill.

QuickBooks

Read only

Tokens are held in a server-side vault and never reach the browser. Nothing is ever written back to your books.

Payments

Handled by Stripe

Card details never touch Waterline. Checkout and the billing portal are Stripe's.

Subprocessors

A short list, named

Supabase (database and auth), Vercel (hosting), Stripe (payments), Intuit (QuickBooks, only if you connect it).

Backups and retention are being finalised and are deliberately not described here yet. A security page that describes a policy which is not yet configured is worse than one that admits the gap. This paragraph will be replaced with the real retention window when it is in place — if you need it before then, ask.

What we do not do

Sell or share your data Never, to anyone, for any purpose.
Train models on your figures Your model is yours. It is not training data.
Write to your accounting system The QuickBooks connection is read-only by design, not by policy.
Read your model in support Not without you asking. If a support question needs it, you will be asked first.