Privacy Policy
TODAMU LLC ("we," "us," or "Operator") operates TODAMU QuickBooks Connector. This policy explains what information the current Service accesses, why it is used, where it is stored, how long it is retained, and how to request deletion.
1. Scope and current functionality
The current Service is a private, read-only QuickBooks Online connector.
After an authorized user grants access, it retrieves the QuickBooks company
identifier and basic CompanyInfo, such as the company name, only
to verify that the intended company is connected. It does not currently
retrieve transactional accounting data and contains no create, update, or
delete accounting operations.
2. Information processed
- OAuth metadata: one-time authorization code, anti-forgery state, and a random bridge ticket.
- Connection credentials: Intuit Client ID and Client Secret entered by the operator, short-lived access tokens, and the latest refresh token.
- Company metadata: QuickBooks company ID, company name, connection environment, authorization status, and verification timestamps.
- Operational security information: limited error and health information needed to keep the Service secure and available. Public callback access logging is disabled to avoid recording OAuth query parameters.
3. Purposes
We process this information only to initiate and complete OAuth authorization, verify the selected QuickBooks company, refresh authorized access, maintain security and troubleshoot errors, comply with law and platform obligations, and respond to support or deletion requests. We do not use QuickBooks data for advertising, profiling, or unrelated purposes.
4. Storage, security, and architecture
The public HTTPS bridge stores an authorization code only in volatile memory, for at most five minutes, and releases it once through an authenticated one-time ticket. It does not receive or store the Intuit Client Secret, access token, or refresh token. On the authorized Windows computer, Client credentials and refresh tokens are encrypted with Windows DPAPI for the current Windows user. Access tokens remain in application memory and are not persisted. Transport uses HTTPS where data crosses the internet.
5. Retention and deletion
- Bridge authorization codes expire automatically within five minutes or are deleted immediately when the one-time ticket is consumed.
- Access tokens remain only in memory and expire according to Intuit's token lifetime.
- Encrypted Client credentials, refresh tokens, company metadata, and connection status are retained on the authorized local computer until the connection or local credential record is deleted, access is revoked, or they are no longer needed for the stated purpose.
- To request deletion or assistance revoking access, email info@todamu.com. We will verify the requester's authority before deleting information.
6. Disclosure and service providers
We do not sell QuickBooks data. Information is exchanged with Intuit as necessary for OAuth and QuickBooks Online API operation. Hostinger and internet infrastructure providers may process routine network or server metadata as service providers. We may disclose information if required by law, to protect rights or security, or with the authorized user's direction. We do not provide third parties access to QuickBooks data for their own marketing or independent use.
7. International processing
The Service and its providers may process information in countries other than the user's location. Where required, we use applicable safeguards and limit processing to the purposes described in this policy.
8. Your choices and rights
You can decline authorization, revoke the app in QuickBooks Online, stop using the Service, and request access, correction, or deletion by contacting info@todamu.com. Available legal rights may vary by location. We may retain limited information when required by law or necessary to establish, exercise, or defend legal claims.
9. Children
The Service is intended for authorized business users and is not directed to children.
10. Changes and contact
We may update this policy when functionality, providers, or legal requirements change. The effective date above identifies the current version. Questions or privacy requests should be sent to info@todamu.com.