ETRUSIA ← Back to extrusia.com

Privacy Policy

Effective 9 September 2026 · Last updated 9 September 2026

Extrusia is business software for window and door manufacturers. This policy explains what information we collect, why we have it, who else can see it, and what you can do about it. It covers our website at extrusia.com, the Extrusia workspace at erp.extrusia.com, Dealer Connect, Extrusia Link, and the Josie assistant.

1. Who we are

Extrusia is a cloud-based enterprise resource planning suite for fenestration manufacturers. It is provided by [LEGAL ENTITY NAME], of [REGISTERED ADDRESS] ("Extrusia", "we", "us"). We are responsible for the personal information described in this policy, and we are the point of contact for any question about it.

2. Whose data this is

Two very different kinds of information pass through Extrusia, and they are not treated the same way.

Information we hold for ourselves

When you visit our website, ask for a demo, or sign in to a workspace, we hold a small amount of information about you: your name, your work email address, the workspace you belong to, and technical records of your visit. We decide how that is used, and this policy governs it.

Information our customers put into their workspace

A manufacturer using Extrusia enters their own business records: quotes, orders, customers, dealers, suppliers, prices, production and shipping records, employee time entries, and accounting figures. Some of that is personal information about people who are not our customers, such as a homeowner named on an order or an employee clocking on at a bench.

That data belongs to the customer, not to us. We hold and process it on their instructions so that we can run the service for them. We do not sell it, we do not use it to advertise, and we do not use one customer's business data to serve another. If you are a homeowner, dealer or employee whose details are in a manufacturer's Extrusia workspace, that manufacturer is the right first point of contact, and we will help them respond to you.

3. What we collect

WhatExamplesWhy we have it
Account details Name, work email address, job role, workspace, password (stored only as a cryptographic hash), and any second-factor setting To create your sign-in, decide what you are allowed to see, and keep the account secure
Business records Quotes, orders, customers, dealers, suppliers, catalogues and prices, production and shipping records, invoices, bills, payments and time entries This is the service. Without it there is nothing to run
Connected accounting data What we read from and write to QuickBooks Online, described in section 5 To keep the books and the workspace agreeing with each other
Enquiries What you type into the demo request form on extrusia.com, and emails you send us To answer you and to keep a record of the conversation
Technical records IP address, browser and device type, pages and API endpoints requested, timestamps, and error diagnostics To keep the service running, to investigate faults, and to detect abuse
Audit records Who changed what, and when, inside a workspace Accountability. An ERP that cannot say who changed a price is not usable in a business

We do not run advertising networks or third-party tracking pixels on extrusia.com, and we do not buy personal information about you from data brokers.

4. How we use it

5. QuickBooks and Intuit data

A customer may connect their QuickBooks Online company to their Extrusia workspace. This section describes exactly what that connection does, because it involves a third party's system and a customer's financial records.

How the connection is made

Connecting is done through Intuit's own authorisation screen. You sign in to QuickBooks at Intuit, not at Extrusia, and you approve the connection there. We never ask for and never receive your QuickBooks username or password. Intuit gives us access tokens instead, and we request a single permission scope, com.intuit.quickbooks.accounting.

What we send to QuickBooks

What we read from QuickBooks

The read side cannot change your books. The part of Extrusia that reads accounts payable issues no request other than a read. It cannot create, edit, void or delete anything in QuickBooks.

How the tokens are held

Access and refresh tokens are encrypted before they are stored, using AES-256-GCM with a key held outside the database. They are decrypted only at the moment they are used to make a request to Intuit. They are never shown in the application, never written to logs, and never included in an error message.

Disconnecting, and what happens then

Any administrator can disconnect QuickBooks from the Integrations screen in the workspace. When you do, we ask Intuit to revoke the authorisation and we delete every stored credential immediately. You can also disconnect from within QuickBooks itself. After disconnecting, we stop sending and stop reading. Records already created in QuickBooks stay in QuickBooks, and records already in your Extrusia workspace stay in your workspace, because both are your business records.

We do not sell QuickBooks data, we do not use it for advertising, and we do not share it with anyone except the infrastructure providers listed in section 8 who host the service on our behalf.

6. Other connected services

Some features rely on outside services. Those marked optional only run if a customer switches them on.

ServiceUsed forWhat it receives
Intuit QuickBooks OnlineAccountingAs described in section 5
QuickBooks Time (optional)Plant capacity from the crew who clocked inA read of who is on the clock and daily hours
StripeCard payments and subscriptionsPayment details, which go to Stripe directly. We do not receive or store full card numbers
ResendSending emailThe recipient address and the contents of the message being sent
AnthropicThe Josie assistant and other AI featuresSee section 7
Open-MeteoWeather for the plant locationA town or city name only. No personal information
Social networks (optional)Publishing marketing posts a customer has writtenOnly the post the customer chose to publish

7. Artificial intelligence features

Josie and the other assistive features work by sending relevant parts of your workspace content to Anthropic's API so that a model can answer a question, draft a message, or summarise a situation.

8. Who we share with

We do not sell personal information, and we never have. We share it only in these circumstances:

9. How long we keep it

10. How we protect it

No system is perfectly secure. If we become aware of a breach affecting personal information, we will notify affected customers without undue delay and comply with applicable law.

11. Your choices and rights

Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict how we use it, and to withdraw consent you previously gave. You will never be treated differently for exercising these rights.

To make a request, contact us using section 13. If the information is inside a manufacturer's workspace, we will pass your request to that manufacturer and support them in answering it, because it is their record and they are the ones who decided to collect it.

You can turn off product marketing email at any time using the unsubscribe link it carries. We will still send you service and security notices, because you need those to use the account safely.

12. Location, children, and changes

Where the data lives. Extrusia is hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the United States.

Children. Extrusia is business software. It is not directed at children, and we do not knowingly collect personal information from anyone under 16.

Cookies. We use only what is necessary to keep you signed in and to remember small preferences, such as which colour theme you chose. We do not use advertising cookies.

Changes. If we change this policy we will update the date at the top. If a change materially affects how we handle personal information, we will give notice in the workspace or by email before it takes effect.

13. Contact us

Questions, requests and complaints about privacy go to:

Extrusia
[LEGAL ENTITY NAME AND REGISTERED ADDRESS]
Email: privacy@extrusia.com

We aim to answer within 30 days. If you are not satisfied with our response, you may have the right to complain to your local data protection authority.