Privacy Policy
This Privacy Policy is published by Byram Advisory Group, LLC ("BAG," "we," "us," or "our") and applies to the Peregrine software-as-a-service platform (the "Service") and the Peregrine marketing website at theperegrine.ai (the "Site"). It is hosted at theperegrine.ai/privacy.
1. Introduction & Scope
BAG is a Texas limited liability company that provides Peregrine, a business-to-business (B2B) software-as-a-service platform built on QuickBooks Online ("QBO"). Peregrine helps business entities manage, analyze, and act on their accounting and financial data.
Who the Service is for. Peregrine is offered only to business entities that are registered with a Secretary of State (or comparable authority) and to the individual employees, contractors, and agents those entities authorize to use the Service on their behalf ("authorized users"). Peregrine is not designed for, directed to, or knowingly offered to individual consumers for personal, family, or household purposes. See Section 13.
What this policy covers. This policy describes how we handle personal information in connection with:
- the Service (the authenticated Peregrine application and its features); and
- the Site (our public marketing website).
Relationship to our other agreements. Your use of the Service is governed by the Peregrine Terms of Service (the "ToS"). Where we process personal information contained in Customer Data on a customer's behalf, our Data Processing Addendum (the "DPA") — offered by default and entered into with each customer — governs that processing. If there is any conflict between this Privacy Policy and the DPA with respect to personal data within Customer Data, the DPA controls. Capitalized terms not defined here have the meaning given in the ToS.
2. Our Two Roles: Controller vs. Processor / Service Provider
Peregrine involves two legally distinct data relationships. We keep them separate throughout this policy because the applicable rights, retention rules, and request-handling procedures differ.
| Relationship | Data in scope | Our role | Governing instrument |
|---|---|---|---|
| Account, authorized-user, marketing, billing, and telemetry data | Names, business emails, roles, authentication events, Site analytics, usage/log data, Stripe billing information | Controller — we decide the purposes and means of processing | This Privacy Policy |
| Customer Data — QBO financial data and uploaded documents processed for a customer | Ledger and financial records, transactions, uploaded source documents, and any personal data embedded within them | Processor / service provider — we act only on the customer's documented instructions | The DPA (and the customer's own privacy notice) |
What this means in practice. When we act as a controller, we are responsible for the data and you can exercise your rights with us directly (Section 12). When we act as a processor/service provider, the customer (typically the business that engaged Peregrine) is the controller of that data. Requests from individuals about Customer Data are routed to the relevant customer; we assist that customer as its processor and do not respond to such requests directly. See Sections 10 and 12.
3. Information We Collect
The table below serves as our notice at collection. It lists the categories of personal and other information we handle, examples, the sources, our role, the sub-processors involved, and the retention approach for each category.
| Category | Examples | Source | Our role | Sub-processor(s) | Retention |
|---|---|---|---|---|---|
| (a) Account & authorized-user data | Name, business email address, role/permissions | Provided by the customer or user at signup and during use | Controller | Stytch (identity/authentication) | For the life of the account; deleted or de-identified within a reasonable period after account termination (we apply the 30-day window described in Section 10 for consistency) |
| (a2) Authentication & session data | Login events, session identifiers, auth logs | Generated via Stytch at sign-in | Controller | Stytch | Rolling, based on operational and fraud-prevention needs |
| (b) Customer Data — QBO financial data | Ledger and financial records, transactions, account balances, and any personal data embedded in them | Retrieved from QBO via Intuit OAuth (read, and human-approved write-back) | Processor | Intuit (source system), Cloudflare (storage), Anthropic / OpenAI (AI features), Render (hosting) | Per Section 10: export available for 14 days post-termination; deleted or de-identified no later than 30 days post-termination |
| (b2) Customer Data — uploaded documents | Source documents and files uploaded by authorized users | Uploaded by authorized users | Processor | Cloudflare (S3-compatible object storage), Anthropic / OpenAI (if processed by AI features), Render | Same as (b) |
| (c) Usage / telemetry / log data | Feature usage, performance metrics, error logs, IP address, device/browser metadata | Generated automatically through use of the Service | Controller (for our own operational logs) | Render (hosting) | Rolling operational retention; may be de-identified or aggregated and retained |
| (d) Marketing-site cookies & analytics | Analytics identifiers, ad-attribution data, cookie data | Collected automatically from Site visitors | Controller | Google (GA4 analytics and Google Ads tag) | Per Google/GA4 controls and cookie lifetimes (see Section 6) |
| (e) Billing data | Business billing contact, subscription and transaction records; payment method details entered at checkout | Entered at checkout | Controller | Stripe (payments) | Retained as required by tax and accounting laws; we do not store full card numbers (Stripe does) |
4. How We Use Information (Purposes & Legal Bases)
Controller-role data (categories a, a2, c, d, e). We use this information to:
- provide, operate, maintain, and secure the Service and Site;
- authenticate users and prevent fraud and abuse;
- provide customer support and service communications;
- process subscription billing and payments (we are the merchant of record);
- monitor reliability, debug, and improve our products; and
- conduct marketing and measure the effectiveness of our marketing.
Where the EU or UK General Data Protection Regulation ("GDPR" / "UK GDPR") applies to authorized-user personal data, our legal bases are: performance of a contract (providing and administering the Service and billing), legitimate interests (securing, improving, and marketing our products in a way that is not overridden by your rights), and consent (for non-essential cookies and certain marketing on the Site, which you may withdraw at any time).
Customer Data (categories b, b2). We process Customer Data solely as a processor, on the customer's documented instructions, to deliver the Service to that customer as described in the ToS and DPA. We do not use Customer Data for our own purposes, and we do not use it to build or improve independent products except as permitted through aggregated and de-identified data.
5. AI Processing & No-Model-Training Commitment
Some Peregrine features use large language models ("LLMs") to analyze and act on financial data.
- Sub-processors. AI features send relevant Customer Data to Anthropic and OpenAI as sub-processors for inference (that is, to generate the output you request).
- No-training configuration. These LLM providers process data under configurations that do not permit the provider to train its models on your data.
- We do not train models on your data. BAG does not use Customer Data to train or fine-tune foundation models or LLMs.
- Human-in-the-loop. AI outputs are subject to human control. In particular, any write-back to QBO requires human approval before it is executed (see Sections 8 and 9).
We want to be accurate rather than absolute: Customer Data processed by AI features does leave our systems to reach these LLM sub-processors, under contract and under the protections described above. We do not claim that your data never leaves our infrastructure.
6. Cookies & Analytics (Marketing Site)
The disclosures in this section apply to the marketing Site (theperegrine.ai) only, not to the authenticated Peregrine application.
What we use. On the Site we use:
- Google Analytics 4 (GA4) — to measure Site traffic and understand how visitors use the Site; and
- a Google Ads tag — a conversion and remarketing tag used for advertising attribution.
Cookie categories. Cookies on the Site fall into essential (necessary to operate the Site) and non-essential (analytics and advertising) categories.
Consent. For visitors in the EU/UK and other regions requiring prior consent, our cookie banner/consent tool gates the analytics and advertising tags so they load only after you opt in. You can decline non-essential cookies through that tool.
The Google Ads tag and "sharing." The Google Ads tag is the single place where Peregrine may share personal information for cross-context behavioral advertising, as that concept is defined under the California Consumer Privacy Act as amended ("CCPA/CPRA"). We disclose it here expressly, and it is the sole exception to our no-sharing statement in Section 7.
Your controls and opt-outs.
- Cookie banner: decline analytics/advertising cookies through our Site consent tool.
- Global Privacy Control (GPC): we treat a valid GPC browser signal as a request to opt out of "sale"/"sharing" for that browser.
- Google Analytics: install the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout).
- Google Ads: adjust your ad personalization through Google Ads Settings (adssettings.google.com).
- Browser controls: most browsers let you block or delete cookies.
You can also exercise the CCPA/CPRA opt-out described in Section 12 with respect to this tag.
7. How We Share Information — Sub-Processors & No Sale
Sub-processors. We share information with vetted service providers ("sub-processors") who process it on our behalf to deliver the Service and operate our business. Our current sub-processors are:
- Intuit — QBO source system for financial data;
- Cloudflare — S3-compatible object storage for uploaded documents and data;
- Stytch — identity and authentication;
- Anthropic and OpenAI — LLM processing for AI features;
- Render — application hosting;
- Stripe — payment processing; and
- Google — analytics and advertising on the marketing Site.
Our live, maintained sub-processor list is published at theperegrine.ai/subprocessors. Consistent with the DPA, we provide notice of material changes to our sub-processors.
Other sharing. We may also disclose information: (i) to comply with law, legal process, or a lawful government request, or to protect the rights, safety, and property of BAG, our customers, or others; and (ii) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this policy or notify affected parties as required by law.
No sale of personal information. We do not sell personal information as "sale" is defined under CCPA/CPRA or comparable laws. We also do not share personal information for cross-context behavioral advertising, except for the marketing-site Google Ads tag described in Section 6. We do not otherwise trade personal information for money or other valuable consideration.
8. QuickBooks Online / Intuit
Connecting your QBO account to Peregrine is central to the Service, so we describe it specifically here.
- Connection via Intuit OAuth. You connect QBO using Intuit's OAuth authorization flow. We store encrypted OAuth tokens, not your QBO login credentials.
- Scope. Access is limited to the QBO company file(s) the customer authorizes.
- Read and write model. Peregrine reads QBO data to deliver the Service, and any write-back to QBO requires human approval before it is executed.
- Customer control. Customers and their authorized users control the connection and can revoke Peregrine's access at any time through Intuit or within the Service.
- Role. QBO financial data is Customer Data, processed by us as a processor solely to deliver the Service.
- Intuit's terms. Your use of QBO is also governed by Intuit's own terms and privacy practices.
9. Data Security
We maintain administrative, technical, and organizational measures designed to protect the information we handle. These measures include:
- encryption in transit and at rest;
- encrypted storage of credentials and OAuth tokens;
- multi-tenant isolation so that one customer's data is logically separated from another's; and
- a human-approval gate before any write-back to QBO.
Authentication is delegated to Stytch, and we do not store user passwords in plaintext. Billing is handled by Stripe as merchant of record, and we do not store full payment card numbers.
No security program is perfect. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. We describe our measures as safeguards, not guarantees. We make no representation that we hold SOC 2 or any other security certification.
10. Data Retention & Deletion
Customer Data. Retention and deletion of Customer Data follow Section 19 of the ToS:
- On termination of the account, the customer may export its Customer Data for 14 days.
- We delete or de-identify Customer Data no later than 30 days after termination.
- Carve-outs. We may retain Customer Data beyond these periods to the extent required by legal or regulatory retention obligations; we may retain and use aggregated or de-identified data that no longer identifies any individual or customer; and copies may persist in routine backups until they expire on their ordinary backup cycle.
Controller-role data (account, authentication, billing, telemetry, and Site data). We retain this information for as long as needed for the purposes described in this policy. Account and authorized-user data is deleted or de-identified within a reasonable period after account termination (we apply the same 30-day window described above for consistency). Billing records are retained as required by tax and accounting laws. Telemetry and log data are kept on a rolling operational basis and may be de-identified or aggregated and retained. Site analytics and advertising cookie data are retained per the Google/GA4 controls and cookie lifetimes referenced in Section 6.
11. International Data Transfers
We are based in the United States, and we process personal information in the United States. Our sub-processors may process information in the United States and, depending on the provider, other locations.
To the extent we process EU or UK authorized-user personal data and transfer it internationally, such transfers are made under an appropriate transfer mechanism — including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — as implemented through the DPA. Where we process Customer Data as a processor, transfer mechanisms for that data are addressed in the DPA between BAG and the customer.
12. Your Privacy Rights
Because our role differs by data type (Section 2), how you exercise rights differs too.
12.1 Controller-role data (account, authorized-user, billing, marketing, telemetry)
For information we hold as a controller, and subject to applicable law and verification:
California (CCPA/CPRA). You may have the right to: know and access the categories and specific pieces of personal information we have collected; know the sources, purposes, and categories of third parties/sub-processors to whom we disclose it; delete your personal information; correct inaccurate personal information; and opt out of "sale" or "sharing." We do not sell personal information; the only "sharing" is the marketing-site Google Ads tag (Section 6), which you can opt out of via our cookie tool, GPC, or Google's controls. You have the right not to receive discriminatory treatment for exercising these rights.
EU/UK (GDPR / UK GDPR). To the extent we process your personal data as a controller, you may have the right to access, rectify, erase, restrict, or object to processing; to data portability; and to withdraw consent (without affecting prior processing). You may also lodge a complaint with your supervisory authority.
How to exercise. Submit requests to peregrine.cfo@byram-advisory.com. We will verify your identity before acting, typically by confirming information associated with your account, and you may use an authorized agent where the law permits.
12.2 Customer Data
For personal information contained in Customer Data, the customer is the controller. If you are an individual whose personal data appears in Customer Data and you wish to exercise rights, please contact the relevant customer directly. If you contact us, we will route your request to that customer and assist the customer as its processor in accordance with the DPA. We do not respond to such requests directly.
13. Businesses Only; Not Directed to Consumers or Children
Peregrine is offered only to business entities registered with a Secretary of State (or comparable authority) and to their authorized users, and only for business purposes. The Service is not directed to, or knowingly offered to, individual consumers for personal, family, or household use.
The Service is not directed to children, and we do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies). If you believe a child has provided us personal information, contact us at peregrine.cfo@byram-advisory.com and we will take appropriate action.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" and "Effective" dates and the version number at the top of this policy, and we will provide additional notice where required by law (for example, by email to account administrators or a notice within the Service or on the Site). Your continued use of the Service or Site after an update takes effect constitutes acceptance of the updated policy, except where additional consent is required by law.
15. Contact Us
Byram Advisory Group, LLC 6150 Eldorado Pkwy, Ste 190 #2037 McKinney, TX 75070 United States
Privacy contact / requests: peregrine.cfo@byram-advisory.com
To submit a privacy request, email the address above with the details of your request; we will verify and respond as required by applicable law. As of the Effective Date, we have not appointed a data-protection representative in the EU or UK or a dedicated data protection officer; if we do, we will identify them here.
*Peregrine is a product of Byram Advisory Group, LLC. This Privacy Policy is version 1.0, effective July 1, 2026, and is published at theperegrine.ai/privacy.*