Privacy

This policy describes how the PSBP Law QuickBooks Connector (the “Application”) handles data. The Application is operated by PSBP Law, PLLC (“PSBP Law,” “we”).

1. Scope

The Application is a private, internal tool. It is not offered to the public, has no external users, and creates no customer accounts. It accesses only QuickBooks Online companies owned or controlled by PSBP Law and its affiliated entities, and only after an authorized representative has expressly granted access through Intuit’s authorization process.

2. Information the Application accesses

Through Intuit’s API, and limited to the accounting permission scope, the Application reads:

  • Vendor records (name, identifier, payment history)
  • The chart of accounts, including bank and expense accounts
  • Existing check transactions, used to detect duplicate payments

The Application writes only check transactions, and only into the “need to print” state for human review. It does not request or receive the payments permission scope and cannot process card transactions.

3. Where information is held

The Application runs on a workstation controlled by PSBP Law and located in the United States. QuickBooks data is used in memory to prepare a check and is not copied into any external database, data warehouse, or analytics platform.

4. What is retained

The Application keeps a local audit record of each check it creates: the entity, vendor name, amount, expense account, date, the source bill filename, and the resulting QuickBooks transaction identifier. This record exists so that payments can be traced to their supporting documents. No client information, no consumer financial data, and no payment card data is stored.

5. Credentials

Authorization tokens issued by Intuit are encrypted at rest using AES-256-GCM. The encryption key is stored in a separate file with owner-only permissions. Tokens are never written to logs, never displayed in full, and are never transmitted to any destination other than Intuit.

6. Disclosure to others

We do not sell, rent, share, or otherwise disclose QuickBooks data to any third party. The Application uses no subprocessors, no third-party hosting provider, no analytics service, and no advertising service. The only network destination it contacts is Intuit.

7. Revoking access

Authorization may be revoked at any time from within QuickBooks Online, or through the Application, which revokes the token with Intuit and deletes the stored credentials from the workstation. See Disconnect.

8. Changes

Material changes to this policy will be reflected by a revised effective date on this page.

9. Contact

Questions about this policy may be directed to Rakesh Patel, rpatel@psbplaw.com, PSBP Law, PLLC, 1125 Executive Circle, Suite 200, Irving, Texas.