FS Consolidation · Privacy
We are committed to protecting your privacy and take appropriate measures to safeguard the confidentiality of data processed by the Application. Last updated: September 15, 2026.
Via QuickBooks Online (Intuit) OAuth2, with your explicit authorization, we read: Balance Sheet, Profit & Loss, and Trial Balance report data — GL account names, account types, and balances. We do not request or collect personal data through this integration.
Separately, to operate the Application's own sign-in and role-based access
control, we hold a small amount of account data for each authorized user:
username, display name, role, and a session identifier stored in an
HttpOnly cookie. We do not use this data for any purpose beyond
authenticating you and enforcing what your role is permitted to do.
Financial report data is used solely to map, consolidate, and generate the consolidated financial statements (Balance Sheet, Income Statement, Cash Flow Statement) the Application produces. We do not sell this data or use it for advertising. Account data is used solely to authenticate you and enforce role-based permissions within the Application.
The Application sets one functional cookie — an HttpOnly,
SameSite=Lax session cookie that keeps you signed in. It contains
only an opaque session identifier, never your credentials. It is not used for
advertising or cross-site tracking, and is cleared when you sign out.
OAuth refresh tokens, session data, and account credentials (password hashes, never plaintext) are stored outside the application image, in a gitignored, volume-mounted secrets store during this pilot phase; per our organization's standards, production deployments move this to AWS Secrets Manager / SSM Parameter Store. Financial data at rest is stored as file artifacts on an encrypted local volume during this pilot phase, moving to a private, encrypted Amazon S3 bucket — accessible only to authorized personnel — once the Application is deployed to AWS. Access is limited to authorized personnel.
The Application links to QuickBooks Online (Intuit) for authorization, and to this Privacy Policy and our End User License Agreement. We are not responsible for the privacy practices of Intuit's own sites — see QuickBooks' own privacy policy for how they handle your data.
We share data with Intuit only as required by the OAuth2 protocol itself (token refresh/revocation). We do not share your financial data or account data with any other third party.
Report data is retained for as long as the Application is in active use for the NYNM engagement, and for up to seven (7) years thereafter to support audit and financial record-keeping requirements, unless a longer period is required by law. You may disconnect QuickBooks Online at any time via the Application or your Intuit account settings, which revokes our access going forward. Account data is retained for as long as your account remains active; deactivated accounts are kept (never hard-deleted) solely to preserve the audit trail of actions they took.
You may request access to, correction of, or deletion of data we hold about your connected entities or your account by contacting us using the details below.
We will review, change, or update this Privacy Policy as and when required, and will update the "Last updated" date above whenever we do.
Questions about this Privacy Policy or how your data is handled — reach out using any of the details below.