Last updated: March 2026
Information we collect
When you use Yukti, we collect information necessary to provide our service:
- Account information: your name, email address, and password (encrypted)
- Restaurant details: restaurant name, address, city, state, and zip code
- Financial statement data: revenue amounts, fee breakdowns, tax amounts, tips, and deposit information extracted from uploaded delivery platform statements (DoorDash, Uber Eats, Grubhub) and POS reports (Toast, Clover)
- QuickBooks connection tokens: OAuth access and refresh tokens (encrypted at rest with AES-256-GCM)
How we use your information
We use your information solely to provide the Yukti service:
- Processing and parsing uploaded delivery platform and POS statements
- Generating balanced journal entries from parsed statement data
- Posting journal entries to your QuickBooks account (only at your explicit direction)
- Calculating sales tax liability and generating filing summaries
- Generating financial performance reports
- Authenticating your identity and managing your account
What we do not do
We are committed to protecting your data:
- We do not sell your personal information to any third party
- We do not share your financial data with third parties, except QuickBooks at your explicit direction
- We do not use your financial data for advertising or marketing purposes
- We do not use AI to make financial decisions — all calculations are deterministic code
Data retention
We retain your financial statements and journal entries for 8 years, consistent with IRS record retention requirements (IRC §6501) and California CDTFA retention guidelines. Your statements are stored on AWS S3 with encryption and versioning enabled.
You may request deletion of your account and data at any time (see below). Note that certain records may be retained as required by law.
Your rights
Under the California Consumer Privacy Act (CCPA), you have the right to:
- Know what personal information we have collected about you
- Request deletion of your personal information
- Opt out of the sale of your personal information (we do not sell your data)
- Not be discriminated against for exercising your privacy rights
Security measures
We implement industry-standard security measures to protect your data:
- AES-256-GCM encryption for OAuth tokens at rest
- HTTPS encryption for all data in transit
- JWT sessions with 8-hour expiry and periodic database validation
- bcryptjs password hashing (never stored in plain text)
- Rate limiting on authentication endpoints to prevent brute force attacks
- CSRF protection on OAuth flows
Contact us
If you have questions about this privacy policy, wish to exercise your privacy rights, or want to request deletion of your data, please contact us:
Email: privacy@goyukti.com
Address: Anaheim, California