Privacy Policy
Effective 1 January 2026
Tompkins R&D operates QIF Importer Pro. This policy describes what the service collects, why, and how long it keeps it.
What we collect
- Identity. When you sign in with Intuit we receive your Intuit subject identifier, name, email address, and whether Intuit has verified that address. We store these to identify your account.
- Connection credentials. An OAuth refresh token for each connected QuickBooks company, plus the company’s realm id.
- Uploaded files. The QIF files you upload and the parsed ledger derived from them. These contain account names, payees, amounts, memos and in some cases account numbers.
- Operational records. Which entities were created in which company, and an audit log of significant actions such as connecting, pushing and disconnecting.
What we do not collect
We do not read QuickBooks data beyond what an import needs: the chart of accounts, and transactions inside the date range of your import when you use merge review. We do not sell data, and we do not use your financial data to train models.
How it is protected
- Refresh tokens are encrypted at rest with AES-256-GCM under a key held outside the database and never sent to a browser.
- Traffic is TLS-encrypted end to end.
- Access is scoped per organization, and every query that touches your data is filtered by your membership.
How long it is kept
- Uploads and parsed ledgers are deleted automatically after your organization’s retention window, 30 days by default. You can delete one sooner from the import page.
- The record of what was created is kept for as long as the connection exists. It contains no financial detail — only that a given source line became a given QuickBooks id — and it is what prevents a re-import from duplicating your books.
- Audit log entries are kept for two years to support security review.
Sub-processors
Intuit (the QuickBooks Online API), our hosting and database provider, and Stripe for subscription billing. Stripe receives your billing details directly; we never see a card number.
Your choices
- Disconnect a QuickBooks company at any time from Settings. This revokes our token at Intuit immediately.
- Delete your account to remove your uploads, parsed data and profile. Records already created in your QuickBooks company are yours and stay there.
- Request a copy of your data by writing to support@example.com.
Contact
support@example.com. See also our security overview.