Privacy policy
Effective September 9, 2026. Operator: Sandy Hills Information Security, North Carolina, United States. Contact: info@sandyhillsinfosec.com.
Who this covers
This policy applies to the private QuickBooks Online integration operated by Sandy Hills Information Security (“we”), as part of our system-integration work. Intuit is not our processor for this app; we access QuickBooks data as a third-party app after you authorize it. Intuit handles its own data under the Intuit Global Privacy Statement.
Data we access
After you connect a QuickBooks Online company, we may access company, customer, vendor, invoice, bill, payment, expense, account, and related bookkeeping records needed to keep the books. We also store OAuth tokens, company (realm) identifiers, and connection status. We do not collect data that is not needed for that bookkeeping work.
How we use it
We use this data only to perform accounting tasks you or an authorized Sandy Hills operator request: reviewing transactions, drafting or posting entries, reconciling, and producing reports. We do not sell it. We do not use it for advertising. We do not share one customer’s identifiable QuickBooks data with another customer.
AI processing
Bookkeeping requests may be sent to an AI model provider (currently xAI) so an assistant can interpret instructions and propose or carry out QuickBooks actions. Only the data needed for that request is sent. Do not put secrets unrelated to the task into those prompts.
Processors and hosting
This website is hosted on Cloudflare. QuickBooks API traffic goes to Intuit. AI requests go to xAI. Those providers process data to deliver their services. We do not process QuickBooks user data on Intuit’s behalf.
Retention and deletion
OAuth tokens are kept only while the company stays connected. Disconnecting revokes tokens and stops API access. Operational logs are kept only as long as needed for security and troubleshooting, then deleted. You may email us to request deletion of retained connector records that we control.
Security
Client ID, client secret, and tokens are stored as secrets, not in this public site. Access is limited to authorized Sandy Hills operators. We will notify Intuit and affected users if a breach requires notice under applicable law.
Your choices
You can refuse to connect, disconnect at any time from QuickBooks or via our disconnect page, and email us to ask what we hold. If you are in a jurisdiction with additional privacy rights (for example CCPA), we will honor applicable requests at the contact above.
Changes
If our use of QuickBooks data changes, we will update this page and, when required, the Intuit app assessment.