Parcel Health Inc. — Depot Privacy Policy
1. Who We Are
Parcel Health Inc. (“Parcel Health,” “we,” “us,” or “our”) operates Depot, our B2B procurement and order-management platform for sustainable healthcare packaging and related supplies (the “Platform”), at depot.parcelhealth.co and related subdomains.
This Privacy Policy describes how we collect, use, store, share, and delete personal and business information when you:
- use Depot as an authorized user of a customer organization (health system, pharmacy, clinic, or telemedicine partner);
- are a Parcel Health team member operating Depot, including our QuickBooks Online accounting integration;
- visit public, unauthenticated Platform pages (such as login, password reset, shared quote links, or this policy); or
- contact us regarding the Platform.
This policy applies specifically to Depot. Our public marketing website at parcelhealth.co is also subject to our general website Privacy Policy. If the two documents conflict with respect to Platform operations, this policy controls.
Healthcare & PHI Notice: Parcel Health is not a healthcare provider or covered entity, and Depot is not an Electronic Health Record (EHR) system. Depot is strictly a B2B commercial packaging and supply procurement system. We do not knowingly collect, store, or process Protected Health Information (PHI) or individual patient medical records.
Intuit Inc. is not a party to this policy and does not operate Depot. Parcel Health is an independent company, and we do not process data on Intuit’s behalf.
2. How to Contact Us
Parcel Health Inc., 201 N Braddock Ave Suite 126, Pittsburgh, PA 15208, USA | Phone: +1 412-528-1115
3. Information We Collect
3.1 Information You or Your Organization Provide
- Account Identity: First name, last name, work email address, phone number, username, and assigned user role (such as platform admin, company admin, location admin, or customer buyer).
- Organization Profile: Organization legal/trade name, company segment, tax classification (taxable or tax-exempt), billing and shipping facility addresses, contact persons, and location hierarchies.
- Procurement & Commercial Records: Assigned product catalogues, SKUs, pricing schedules, purchase orders (standard, custom, blanket, release, and recurring), custom artwork specifications, quotes, invoices, payment terms, and uploaded compliance documents.
- Support & Communications: Feedback, inquiries, and notification preferences.
- Payment References: Third-party payment processor customer identifiers (e.g. Stripe customer IDs) where applicable. We do not store credit card or bank account numbers on Depot servers.
3.2 Information from QuickBooks Online
A Parcel Health platform administrator may connect Parcel Health’s internal QuickBooks Online company to Depot via Intuit OAuth 2.0. Customer organizations do not connect their own QuickBooks accounts through Depot.
We request the standard Intuit accounting scope (com.intuit.quickbooks.accounting).
We read from QuickBooks Online:
- Company realm ID and company display name;
- Chart of Accounts and selected income, expense, and asset accounts;
- Items (SKU, name, type, active status, unit price, quantity on hand, income/expense account references);
- Customers (display name, company name, active status, customer type, billing and shipping address, tax classification);
- Customer Types; and
- Vendor and employee name-list records, strictly to ensure display name uniqueness before creating customer or item records in QuickBooks.
We write to QuickBooks Online:
- Items: Created or updated from Depot products (inventory items for stock goods; non-inventory for custom items) with matching SKUs, unit prices, and account references;
- Customers: Created or updated from Depot company records with matching segment mappings and billing addresses; and
- Invoices (Planned): Unsent mirror invoices matching Depot order invoices (line items, units of measure, deposit applications, and shipping headers).
We store internally regarding QuickBooks Online:
- Encrypted OAuth access and refresh tokens, realm IDs, connection status, and token lifecycle timestamps;
- Entity link mappings between Depot product/company IDs and QuickBooks Item/Customer IDs;
- Chart of accounts configuration and company segment mappings; and
- Sync attempt and audit logs for accounting reconciliation.
All OAuth tokens are stored encrypted in a server-side Supabase Vault, accessible only to internal service processes and never exposed to the client or browser.
3.3 Information Collected Automatically
When using Depot, we automatically log browser/device characteristics, IP address (for security and approximate geolocation), timestamps, and request diagnostics.
3.4 Cookies & Storage
Depot uses strictly essential cookies and secure session tokens required to authenticate users, protect against CSRF attacks, and remember UI preferences (such as theme and selected facility location). Depot does not utilize third-party advertising tracking cookies or ad networks.
4. How We Use Information
We process collected data to:
- Deliver, operate, maintain, and secure the Depot procurement platform;
- Authenticate users and enforce strict role-based and organization-level tenant boundaries;
- Process purchase orders, blanket order drawdowns, quotes, invoices, and shipping labels;
- Synchronize Parcel Health’s internal accounting records between Depot and QuickBooks Online;
- Provide transaction notifications, shipment tracking, and customer support;
- Detect, prevent, and mitigate security threats, fraud, or system abuse; and
- Comply with applicable tax, commercial accounting, and legal recordkeeping requirements.
We do NOT sell personal data or customer records. We do NOT sell, lease, or share QuickBooks Online data with third parties for independent marketing or advertising.
5. Service Providers & Subprocessors
We engage trusted infrastructure and software service providers under confidentiality and data protection obligations:
| Provider | Function |
|---|---|
| Supabase | Primary database, authentication, file storage, and encrypted secret vault |
| Upstash Redis | Short-lived session state and shopping cart cache |
| Sentry | Application error logging (with PII and credential redaction) |
| Shippo | Carrier shipping rates, label generation, and tracking |
| Intuit QuickBooks Online | Internal ERP and accounting synchronization |
| Resend / n8n | Transactional email notifications and operational workflow automation |
| Attio | B2B customer relationship management (CRM) |
| Stripe | Payment processing identifiers where applicable |
6. Data Security
We enforce modern technical and organizational safeguards including HTTPS/TLS 1.2+ encryption in transit, AES-256 encryption at rest, role-based access controls, server-side secret vaulting for API credentials, automated credential redaction in diagnostic logs, and PostgreSQL row-level security (RLS).
7. Data Retention, Disconnection & Deletion
We retain account and procurement records for the duration of the customer relationship and as required by statutory accounting, tax, and legal requirements.
QuickBooks Online Disconnect: A Parcel Health platform administrator can disconnect QuickBooks Online at any time in Depot (Admin → Settings → Integrations). Disconnecting immediately:
- Revokes the OAuth access and refresh tokens with Intuit’s authorization servers;
- Permanently purges the vaulted token credentials from our database; and
- Terminates all automated background synchronization and API calls.
To request deletion of personal information or integration mapping data, contact [email protected]. We will process verified requests within statutory timeframes, subject to records we are legally required to retain.
8. Your Privacy Rights
Depending on your jurisdiction (including under CCPA/CPRA and applicable state laws), you have the right to request access to, correction of, or deletion of your personal information, as well as the right to opt out of any non-existent sale or sharing of your data. To exercise these rights, email [email protected].
9. Updates to This Policy
We may update this Privacy Policy periodically. If we make material modifications, we will update the effective date above and provide notice through Depot or via email.
Trademark Attribution: Intuit and QuickBooks are registered trademarks of Intuit Inc. Used with permission.
