Privacy Policy
How A Pebble Co. collects, uses, and protects information when you use the Pebble platform and related services.
1. Overview
A Pebble Co. (“Pebble,” “we,” “us”) is the modern B2B order-writing platform for wholesale distributors. This policy describes how we collect, use, share, and protect personal information about customers, end users of customer accounts, and visitors to onpebble.com. By using the platform you agree to the practices described here.
We treat customer data as the customer's data. We don't sell it, rent it, or use it to train models. Where this policy describes what Pebble does with information, it's either to run the service the customer is paying for, comply with the law, or improve the product in aggregate.
2. Information we collect
2.1 Information you give us
- Account information. Name, work email, company, role, and credentials when you sign up or your administrator provisions you.
- Customer content. Products, prices, customers, orders, and other records you upload to or generate on the platform.
- Communications. Messages you send to support, on demo calls, or in response to a survey.
- Billing information. Payment instrument and billing address. Card data is processed by our payment processor and not stored by Pebble.
2.2 Information we collect automatically
- Usage data. Pages viewed, features used, errors encountered, and similar activity logs.
- Device data. IP address, browser, operating system, and screen size.
- Cookies and similar technologies. Small files that keep you signed in, remember your preferences, and let us measure aggregate product use.
2.3 Information from third parties
- Integration data. When you connect Pebble to your ERP or other systems, we receive the records the integration is configured to sync.
- Authentication providers. Profile and identity-verification data when you sign in with a third-party identity provider.
3. How we use information
- To provide, secure, and improve the platform.
- To process orders, sync data with your integrations, and run other features you've enabled.
- To communicate with you about your account, billing, security, and product updates.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with applicable law and respond to lawful requests.
We don't use customer content to develop public-facing features or train AI models. Aggregated, de-identified product analytics may be used to understand how the platform performs.
4. Sharing
We share information only as described in this section.
- Service providers. Vendors that help us run the platform — hosting, monitoring, payment processing, email delivery — under written agreements that restrict their use of the data to services they provide to us.
- Your integrations and your administrators. If your administrator connects an integration or invites you to a workspace, the linked services and your administrator can access data within their scope.
- Legal and safety. When required by law, to protect rights, or to prevent harm.
- Business transfers. In connection with a merger, acquisition, or sale of assets, with notice to affected customers.
We don't sell personal information.
5. Connected accounting systems and ERPs
Pebble connects to the accounting system or ERP you already run — Intuit QuickBooks Online, NetSuite, SAP Business One, Microsoft Dynamics, Acumatica, Epicor Prophet 21, Sage, and others — so that catalog, customer, and order data stays consistent between Pebble and your books. A connection is created only when an administrator at your organization authorizes it, and it can be revoked at any time.
5.1 What we access
When you connect an accounting system or ERP, Pebble reads and, for the records you choose to sync back, writes the business data the integration needs:
- Customers. Company names, billing and shipping addresses, contact names, emails, phone numbers, tax status, and payment terms.
- Items. Products, SKUs, descriptions, units of measure, and categories.
- Pricing and inventory. Price levels, customer- specific pricing, quantities on hand, and warehouse locations.
- Orders and invoices. Sales orders, estimates, invoices, line items, totals, and their status.
- Accounts receivable. Balances, aging, and payment records used to show reps a customer's credit position.
- Company and connection metadata. The company or realm identifier, and the access and refresh tokens that keep the connection alive.
We request the narrowest permission scope that supports the features you've turned on. We do not access payroll, banking credentials, or employee records.
5.2 How we use it
Solely to operate the features you enabled: showing reps an accurate catalog and live inventory, applying the right price to the right customer, surfacing AR balances, and pushing completed orders into your accounting system. We use it for no other purpose.
Specifically, we do not sell data from a connected accounting system, share it for advertising, use it to train AI models, or disclose it to other Pebble customers. Per-tenant isolation means one distributor's synced data is never returned in another's query.
5.3 How we protect and store it
Synced data is encrypted in transit (TLS 1.3) and at rest (AES-256), and held in the same isolated tenant store as the rest of your workspace. OAuth access and refresh tokens are encrypted with restricted key access and are never exposed in logs or to other customers. Access by Pebble staff is role-based, logged, and limited to those who need it to support you.
5.4 Disconnecting and deletion
An administrator can disconnect an integration at any time from Pebble's integration settings, or revoke Pebble's access from within the connected system — for QuickBooks Online, under Settings → Apps in your Intuit account. Disconnecting immediately stops all further syncing and invalidates the stored tokens.
On disconnection we delete the stored tokens right away. Data already synced into your workspace stays there so your order history remains intact; you can delete it, or ask us to, and we will remove it from active systems within thirty (30) days, with backup copies aging out on the 45-day rotation. To request deletion of everything we hold from a connected system, email privacy@onpebble.com.
Your use of a connected service is also governed by that provider's own terms and privacy policy. Pebble doesn't control those services and isn't responsible for their practices.
6. Retention
We keep information for as long as your account is active or as needed to provide the platform, comply with legal obligations, resolve disputes, and enforce agreements. When customer content is deleted by an administrator, we remove it from active systems within thirty (30) days; backup copies are removed on the regular backup-rotation schedule (45 days).
7. Security
Pebble uses commercially reasonable administrative, technical, and physical safeguards to protect personal information, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, audit logging, and routine encrypted backups. Detailed practices are described on our Security page.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, port, or delete your personal information; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, contact us at privacy@onpebble.com.
For Pebble customer-account end users, requests to access or delete customer content should be directed to your administrator first; we'll support administrators in fulfilling them.
9. Cookies and tracking
We use cookies and similar technologies to keep you signed in, remember your preferences, and measure product usage. You can control cookies through your browser settings. Disabling cookies may break parts of the platform.
10. Children
Pebble is built for businesses; it's not directed to children under 16. We don't knowingly collect personal information from children under 16. If we learn we have, we'll delete it.
11. International transfers
Pebble is operated from the United States. If you access the platform from outside the United States, your information may be processed in the United States and other countries where our service providers operate. Where required, we use approved mechanisms (such as Standard Contractual Clauses) to legitimize cross-border transfers.
12. Changes
We may update this policy from time to time. Material changes will be posted here with a new effective date and, where appropriate, sent to account administrators. Continued use of the platform after changes take effect indicates acceptance.
13. Contact
Privacy questions, complaints, and requests: privacy@onpebble.com. To book time with our team about your specific deployment, see /book-a-demo.
This policy is based on the Common Paper Standard Privacy Policy, licensed under CC BY 4.0, adapted for A Pebble Co. Customers should review this document with their own counsel before relying on it for compliance. See also the Cloud Service Agreement and the End-User License Agreement.