Legal
Privacy Policy
Allodial Predict — Allodial Supply Co
Last updated: August 2026
Overview
Allodial Predict is operated by Allodial Supply Co LLC, a subsidiary of Allodial Holdings LLC ("Allodial," "we," "us," "our"). This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices you have. It applies to allodialsupply.com, app.allodialsupply.com, and all Allodial Predict services (together, the "Service").
Allodial Predict is a business-to-business (B2B) platform. Our users are distributor admins and account managers at supply distribution businesses (including jan-san, paper, chemical, and facility supply). We are not a consumer service, and we do not knowingly collect personal information from consumers or anyone under 18.
1. The Short Version
- We collect your business's order history and product data to work out each of your accounts' normal ordering rhythm and tell you which ones have broken it. That's the point of the product.
- We never sell your data to anyone, ever.
- Our sync only reads from your connected accounting/ERP systems (QuickBooks Online, Epicor Prophet 21, Epicor Eclipse). The one exception: we create a QuickBooks estimate or invoice only when you explicitly push a specific order — never on a schedule and never automatically. Details in section 5.
- Your data is isolated from every other customer's data.
- When you close your account, we delete your data within 30 days of your request.
2. Data We Collect
Account information. Name, business email address, company name, and role — provided when your account is created.
Business operational data. Purchase order history, product and catalog data, and customer reorder patterns that you import directly or that we read from your connected systems. This is business data about commercial transactions between businesses.
ERP connection data. When you connect QuickBooks Online, Prophet 21, or Eclipse, we receive an access token or the credentials that let us read your data. These are encrypted at rest and are used only to retrieve the data needed for the Service. We never see or store your ERP passwords.
IP address and device information. When you accept our Terms of Service or Alpha Terms, we log your IP address and browser user-agent at the time of acceptance as part of the legal acceptance record. We also log IP addresses, user-agents, and request metadata from automated scanners and crawlers that access decoy security endpoints — this data is used for security monitoring only and contains no personal account data.
Replay files (not collected). Our public Replay tool reads the order export you choose entirely inside your own browser. The file is never uploaded, never reaches our servers, and nothing from it is stored. There is no account to create and nothing to opt out of.
Usage data. Feature usage, session activity, and the prediction and alert records the Service generates for your account.
Marketing-site activity (only if you accept cookies). If you press Accept on the cookie banner on our public site, Klaviyo records which pages you read there and links that to your email address once you give it to us. Decline and none of it is collected — the script is never loaded. This applies to the public marketing site only; the authenticated app carries no such tracking regardless of your choice.
Billing data. Subscription status and payment method details. Payments are processed by Stripe; we never store your card numbers.
3. Data We Do NOT Collect
- No consumer personal information (our users and the data they process are business operators and business records)
- No protected health information (PHI)
- No payment card data (handled entirely by Stripe)
- No data from your connected ERP beyond what is needed to measure each account's ordering rhythm — we do not read payroll, banking, employee, or tax records
4. How We Use Your Data
We use your data for exactly three things:
- Drift detection — measuring how often each of your accounts orders, and how long it has been since the last one, to tell you which accounts have gone quiet.
- Trend analysis — surfacing patterns in your own order data (seasonality, velocity changes, churn risk).
- Suggested purchase order generation — drafting suggested POs for your review. Suggestions are advisory only; nothing is ever placed or written back to your systems automatically.
We also use account and usage data to operate the Service: authentication, transactional email (alerts, billing notices), support, and improving detection accuracy. Drift detection is deterministic arithmetic on your own order dates and amounts, computed inside your account's own database. No external model participates in it, and no model decides which of your accounts are flagged, at what level, or in what order. The three features that do send data to an external AI provider are named in the paragraph below.
Three in-app features send data to OpenAI in order to function: the Allobot assistant (your chat messages and the operational context they refer to, such as customer names and account summaries), import column mapping (the headers and a sample of rows from a file you upload), and supplier-invoice extraction (a supplier invoice document you upload, which is a financial record and typically contains your supplier's name, line items, prices, and freight charges). All three run only on data you put in front of them. Supplier-invoice extraction happens only when you upload an invoice, and what it reads is staged for your review — nothing it extracts updates your pricing until you approve it.
That data is processed under OpenAI's API terms, is not used to train AI models, and is never used to train models for other customers. Your order history is not sent to any external AI provider for detection, and we do not send payment or card data to any AI provider.
Our public Operational Signal Network (OSN) — a public supply-chain stress indicator shown on our marketing site — uses an AI classification model (via Vercel AI Gateway) to analyze publicly available data sources such as freight indexes, weather alerts, and economic indicators. No customer or distributor data is ever included in OSN processing.
5. Third-Party Integrations (QuickBooks Online, Prophet 21, Eclipse)
When you connect an accounting or ERP system:
- Authorization is yours. You connect via OAuth from within the Service. We only access data after you explicitly authorize the connection through the provider's own consent screen.
- Syncing is read-only. Our automatic sync only reads. We retrieve purchase orders, invoices/sales history, items/products, and customer records relevant to reorder prediction. Our sync never creates, modifies, or deletes anything in your connected system.
- Writing happens only when you ask for it. QuickBooks Online is the one exception to the above, and only on your explicit instruction: when you choose to push a specific order to QuickBooks, we create an Estimate or an Invoice for that order in your company file. We never write on a schedule, in the background, or without a direct action from you, and we never modify or delete existing records. If you never use that action, our QuickBooks access stays read-only.
- Token security. OAuth tokens are encrypted at rest and in transit. Tokens are never shared with any third party and are never exposed in logs or to other users.
- Disconnect any time. You can disconnect an integration from your Allodial Predict settings, or revoke access from within the provider (for QuickBooks, via the Intuit "My Apps" page). When you disconnect, we stop syncing immediately and delete the stored tokens. Previously synced data remains in your account until you delete it or close your account.
- Provider policies. Your use of QuickBooks Online is also governed by Intuit's terms and privacy policy; the same applies to Epicor for Prophet 21 and Eclipse.
6. Data Sharing
We never sell your data. We never share your data with advertisers, data brokers, or other customers. We share data only with the service providers (subprocessors) needed to run the platform:
We may also disclose data if required by law (e.g., a valid subpoena), and we will notify you of such requests unless legally prohibited.
7. Tenant Isolation
Each distributor account ("tenant") is fully separated. Database row-level security ensures no tenant can ever access another tenant's data. We never aggregate one customer's data into another customer's predictions, and no individual distributor's data is surfaced publicly without permission.
8. Data Retention and Deletion
- Active accounts: your data is retained for as long as your account is active.
- Account closure: upon your request after closing your account, all tenant data — including synced ERP data and encrypted tokens — is deleted within 30 days.
- Disconnected integrations: OAuth tokens are deleted immediately on disconnect.
- Billing records: retained as required by law and tax regulations.
To request deletion, email legal@allodialsupply.com or use your account settings.
9. Security
- All data is encrypted in transit (TLS 1.2+) and at rest.
- OAuth tokens and credentials are encrypted with access restricted to the systems that need them.
- Row-level security enforces tenant isolation at the database layer.
- Access to production systems is restricted and logged.
- If we discover a security incident affecting your data, we will notify you without undue delay and notify affected integration partners (such as Intuit or Epicor) as required by their developer programs.
We log IP addresses, user-agents, and HTTP request metadata from automated scanners that probe decoy security endpoints (honeypot routes). These logs are used solely for security monitoring and threat detection and contain no personal account data. They are retained for up to 90 days.
See our Security page for more detail. To report a vulnerability: security@allodialsupply.com.
10. Where Data Is Stored
All data is hosted in the United States (Vercel and Supabase US regions). If you use the Service from outside the USA, you consent to your data being processed in the USA.
11. Your Rights and Choices
You may, at any time:
- Access and export your business data from the Service
- Correct your account information
- Disconnect any ERP integration
- Request deletion of your account and data (completed within 30 days)
- Ask us what data we hold about your account
- Leave the marketing list — via the unsubscribe link in any marketing email, or the marketing toggle in your account settings. Operational email continues either way.
- Withdraw cookie consent on our marketing site at any time, from the Cookie Policy page
Email legal@allodialsupply.com for any of the above. We respond to verified requests within 30 days.
12. Marketing Email
Sales and marketing email — the newsletter and the sequence that greets a new account — is sent through Klaviyo. Everything else we send you comes through Resend and is not marketing: drift alerts, your daily list of accounts, order handoffs, billing notices, and security notifications. Those are part of the Service and continue regardless of your marketing choices.
You get on the marketing list one of two ways: by subscribing on our public site, or by creating an account. Either way you can leave at any time — the unsubscribe link at the foot of every marketing email, or the marketing toggle in your account settings, which removes you from the list itself and not merely from a flag in our database.
We do not sell, rent, or share the list. We do not send you other companies' offers. The address you give us is used to send you our own writing and nothing else.
13. Cookies
Signing in and using the Service need only strictly necessary cookies, which are always on. Our public marketing site additionally offers one marketing cookie, set by Klaviyo, which runs the newsletter signup form and tells us which analyses get read. It is off until you accept it, and declining means the script that would set it is never loaded at all.
We use no advertising cookies, no retargeting, and no cross-site tracking. Full detail, including how to change your mind: our Cookie Policy.
14. Changes to This Policy
If we make material changes, we will notify account admins by email and update the date at the top of this page before changes take effect.
15. Contact
Allodial Supply Co LLC
legal@allodialsupply.com