Privacy Policy
This policy covers the Bravo QuickBooks Online integration (the "Integration"), which connects Bravo to QuickBooks Online.
Effective date: [TODO date] · Published by: [TODO legal entity name and address]
1. Where the Integration runs
The Integration is installed and runs on servers operated by the organisation using it. It is not a hosted or cloud service. QuickBooks data processed by the Integration stays on those servers. The publisher does not host, receive, store or maintain a copy of that data.
2. What QuickBooks data the Integration uses
With the permission granted when a QuickBooks company is connected, the Integration:
- Reads the company name, chart of accounts, items, payment terms, and customer and vendor records, so an administrator can choose where entries post and so documents can be matched to the right customer or vendor.
- Creates bills and invoices corresponding to payable vouchers and client invoices prepared in Bravo.
- Creates a customer or vendor when Bravo has one that the QuickBooks company does not yet contain, using the name and address held in Bravo.
The Integration does not read bank account details, payroll data, or transactions it did not create. It uses only the QuickBooks Online Accounting permission.
3. What is stored, and where
| Information | Where it is kept |
|---|---|
| QuickBooks identifiers for documents sent, with amounts, dates and the destination company | The organisation's own Bravo database |
| QuickBooks identifiers for matched customers and vendors | The organisation's own Bravo database |
| A record of each send attempt, including any error returned by QuickBooks | The organisation's own Bravo database |
| Sign-in tokens issued by Intuit | A file on the server, encrypted so that it can only be read on that machine |
| Activity logs, kept for 90 days | The server running the Integration |
Log entries can include document numbers, amounts and messages returned by QuickBooks, which may contain a customer or vendor name. Logs never contain sign-in tokens or passwords.
4. QuickBooks sign-in
Signing in happens on Intuit's own pages. The Integration never receives a QuickBooks user name or password. Intuit returns a token that authorises the Integration to act on the connected company. Tokens are refreshed automatically and are revoked when the company is disconnected.
5. Who the data is shared with
Nobody. QuickBooks data obtained through the Integration is not transmitted to the publisher, sold, rented, or shared with advertisers, analytics providers, or any other third party. The Integration communicates only with Intuit's APIs, over encrypted connections.
If an organisation asks for support, it may choose to send log extracts or screenshots. That information is used only to resolve the issue reported.
6. Security
- All communication with Intuit uses encrypted connections (TLS 1.2 or higher).
- The Integration's service accepts requests only from the machine it runs on; it is not reachable from the internet.
- Sign-in tokens are encrypted at rest and are tied to the machine holding them.
- Application credentials are held in a configuration file readable only by server administrators.
- Each connection is authorised by a QuickBooks administrator and can be withdrawn at any time.
7. Keeping and deleting data
Records of what was sent remain in the organisation's Bravo database for as long as that organisation keeps them, as accounting records. Disconnecting a company revokes and deletes the stored token. An organisation that stops using the Integration can remove the records with the uninstall steps supplied with it. Because the publisher holds no copy, deletion is entirely under the organisation's control.
8. Changes
If this policy changes, the revised version will be posted here with a new effective date.
9. Contact
Questions about this policy or about data handled by the Integration: support@rycoinfo.com · (800) 240-7926 · [TODO postal address]