← Back to Integration & Legal Info

FS Consolidation · Privacy

Our Privacy Policy

We are committed to protecting your privacy and take appropriate measures to safeguard the confidentiality of data processed by the Application. Last updated: September 15, 2026.

1. What We Collect

Via QuickBooks Online (Intuit) OAuth2, with your explicit authorization, we read: Balance Sheet, Profit & Loss, and Trial Balance report data — GL account names, account types, and balances. We do not request or collect personal data through this integration.

Separately, to operate the Application's own sign-in and role-based access control, we hold a small amount of account data for each authorized user: username, display name, role, and a session identifier stored in an HttpOnly cookie. We do not use this data for any purpose beyond authenticating you and enforcing what your role is permitted to do.

2. How We Use It

Financial report data is used solely to map, consolidate, and generate the consolidated financial statements (Balance Sheet, Income Statement, Cash Flow Statement) the Application produces. We do not sell this data or use it for advertising. Account data is used solely to authenticate you and enforce role-based permissions within the Application.

3. Cookies

The Application sets one functional cookie — an HttpOnly, SameSite=Lax session cookie that keeps you signed in. It contains only an opaque session identifier, never your credentials. It is not used for advertising or cross-site tracking, and is cleared when you sign out.

4. Storage & Security

OAuth refresh tokens, session data, and account credentials (password hashes, never plaintext) are stored outside the application image, in a gitignored, volume-mounted secrets store during this pilot phase; per our organization's standards, production deployments move this to AWS Secrets Manager / SSM Parameter Store. Financial data at rest is stored as file artifacts on an encrypted local volume during this pilot phase, moving to a private, encrypted Amazon S3 bucket — accessible only to authorized personnel — once the Application is deployed to AWS. Access is limited to authorized personnel.

5. Links to External Sites

The Application links to QuickBooks Online (Intuit) for authorization, and to this Privacy Policy and our End User License Agreement. We are not responsible for the privacy practices of Intuit's own sites — see QuickBooks' own privacy policy for how they handle your data.

6. Data Sharing

We share data with Intuit only as required by the OAuth2 protocol itself (token refresh/revocation). We do not share your financial data or account data with any other third party.

7. Data Retention

Report data is retained for as long as the Application is in active use for the NYNM engagement, and for up to seven (7) years thereafter to support audit and financial record-keeping requirements, unless a longer period is required by law. You may disconnect QuickBooks Online at any time via the Application or your Intuit account settings, which revokes our access going forward. Account data is retained for as long as your account remains active; deactivated accounts are kept (never hard-deleted) solely to preserve the audit trail of actions they took.

8. Your Rights

You may request access to, correction of, or deletion of data we hold about your connected entities or your account by contacting us using the details below.

9. Changes to This Policy

We will review, change, or update this Privacy Policy as and when required, and will update the "Last updated" date above whenever we do.

How to Contact Us

Questions about this Privacy Policy or how your data is handled — reach out using any of the details below.

Email
info@flatworldsolutions.com
Phone
800-514-7456
Provided by
Flatworld Solutions Pvt. Ltd.
USA
116 Village Blvd, Suite 200, Princeton, NJ 08540
India
Survey No.11, 3rd Floor, Indraprastha, Gubbi Cross, 81, Hennur Bagalur Main Rd, Kuvempu Layout, Kothanur, Bengaluru, Karnataka 560077
Philippines
Aeon Towers, J.P. Laurel Avenue, Bajada, Davao 8000