Privacy policy
Last updated 2026-10-08
This policy covers the connector at this address, operated by Iflowchain LLC. Iflowchain LLC is responsible for the handling described here. It is a private deployment: data is not sold, rented, shared for advertising, or used to train any model.
What is stored
- Intuit connection. For each QuickBooks company a firm connects, Intuit's refresh token, encrypted. Access tokens are kept only in memory, for the hour Intuit issues them for, and never written to storage.
- Firms and staff. Each firm's name, status, and whether changes through the connector are paused for it. For each person who uses the connector on a firm's behalf: their email address, their firm, their role (admin, staff, or viewer), and when they were added.
- Company records. For each connected company: the Intuit realm id, company and legal name, country, the email address of the Intuit account that authorized it, whether the firm allows changes through the connector, whether the connection is working (with the last error if not), and when it was connected.
- Activity log. One entry per action, through the assistant or the operator's admin console: when, which firm, who acted (their email address), where (read, write, admin, console, or the company connection page), which tool, which company (its realm id), the person the action was about when it was about one — for example the staff member added or the console account changed — and whether it succeeded. Never the content of a request or a result.
- Sign-in and authorization records. Registered assistant client details; for each sign-in grant, a hash of the token together with the signed-in person's email address and firm, so the assistant can stay connected without signing in every time; sign-ins in progress for up to ten minutes, each tied to the browser that started it by a random cookie, of which only a hash is stored. When Intuit sends you back, the answer — the code returned to the assistant, or the company-connection page — is stored encrypted for 2 minutes, so that a browser which sends Intuit's return twice gets the same answer. Signing in keeps nothing from Intuit: the sign-in is used to read the verified email address and then discarded, never stored.
- Operator console accounts. For the operator's own staff who administer the connector: email address, role, whether the account is active, the password as a one-way hash (argon2id), the two-factor secret encrypted, the last two-factor code step used, the count of recent failed sign-ins and any lockout time. One-time setup links are stored only as a hash, with the email, purpose and expiry (24 hours). Console sessions are stored as a hash of the session token, the email address, and an expiry of at most 8 hours.
What is never stored
- QuickBooks accounting records are not copied into a database here. Requests from the assistant are passed through to Intuit's API and the results returned; they are not retained after the request completes.
- The content of requests and results, in the database or in logs.
- Passwords, session tokens, setup links, and sign-in or authorization codes in readable form — only hashes.
- The Intuit sign-in grant used to confirm a person's email address.
- IP addresses: they are used in memory to limit repeated attempts, and not written to the database or the logs.
How it is protected
- Refresh tokens are sealed with envelope encryption: a per-record AES-256-GCM key, wrapped by a key belonging to the company's firm, itself wrapped by a master key held only in the service's configuration and never written to storage. Two-factor secrets are sealed under the master key.
- Each firm's data is kept apart in the database layer and again by row-level security.
- All traffic is HTTPS, TLS 1.2 or better.
- Logs are structured records carrying realm ids, firm ids, and hashed person ids — never email addresses. Tokens, authorization codes, and encrypted values are never logged.
Retention and deletion
- A company's record and stored token are deleted when it is disconnected. Revoking the app inside QuickBooks invalidates Intuit's tokens immediately.
- A person's staff record and sign-in records are deleted when they are removed from their firm.
- Sign-ins in progress, the encrypted answers to Intuit's return (after 2 minutes), authorization codes, expired sign-in grants, setup links and console sessions are deleted once they expire.
- The activity log is kept as the record of what was done, for the operator's retention period, and then deleted. When a firm leaves, its encryption key is destroyed first, which makes its stored tokens unreadable, and its records are removed.
- Operational logs are retained for a limited period for troubleshooting.
Your requests
To ask what is held about you, or to have it deleted, write to info@iflowchain.com.