Access and data handling
Clear safeguards. Specific questions.
Financial data deserves an understandable access model. Review the safeguards below alongside your connection scope and written agreement.
How access is controlled.
01
Practice scope
App requests are checked against a practice identity. User roles and section access determine which parts of the product can be used. Financial analytics are limited to Owner and Admin roles in the current interface.
02
Credentials and connections
Stored integration credentials use AES-256-GCM encryption. New encrypted records bind the credential context to its practice and provider.
03
Sessions and changes
The app checks sessions, authorization, and CSRF protections. Audit logging records supported changes; this is not a claim that every action is logged.
Ownership, disconnection, and retention.
- Who owns practice data?
- The existing terms state that customers retain rights in Customer Data. Source access should be authorized by the customer.
- What happens when a source is disconnected?
- Revocation and reconnection are provider-specific. Disconnecting a source does not promise deletion of previously imported records. Ask about both access revocation and retained data.
- How long is information retained?
- Retention varies by data type, agreement, legal requirements, and operational needs. Request the applicable account policy; no fixed deletion period is promised here.
- How do I request deletion or ask a security question?
- Use the contact page for security questions. Privacy requests can be sent to privacy@revenuerounds.com. We may need to verify your authority before acting.
Next step
Bring your questions. We’ll walk through the numbers.
See the product, discuss your systems, and understand what setup would involve. This request starts a conversation; it does not book a calendar slot.
