Privacy
Effective
This is the privacy policy for TDR Preflight, including how data read from an optionally connected QuickBooks Online company is handled. It is the current published version customers accept during checkout and activation.
Tenant-scoped product processing, optional consented public-page analytics, and no sale or advertising use of customer data.
- We process account, contract, normalized transaction, billing, audit, and—when connected—minimized QuickBooks company and sales data to provide the service. OAuth credentials are encrypted and excluded from APIs and organization exports.
- The optional QuickBooks Online connection requests only Intuit's com.intuit.quickbooks.accounting scope. On an explicit user action it reads company identity, items, customers, and invoice and sales-receipt lines for the selected range; it never writes to QuickBooks, reads attachments or payroll data, or syncs on a schedule. What it keeps is an immutable, checksummed, minimized snapshot in private tenant-scoped storage.
- Customer data goes only to the processors that run the service: payment processing through Stripe, transactional email delivery, and the managed database, cache, and private object storage the application runs on. We do not sell customer data, share it for advertising, or put source values into metrics and traces.
- On public editorial pages, Google Analytics runs only after a visitor chooses Allow analytics. It receives the page URL without its query string, a sanitized referrer, and browser and device information. It is excluded from the public contract checker, account and sign-in screens, invitation and recovery links, and the reporting workspace; it never receives contract numbers, uploaded files, transaction values, account fields, or QuickBooks data. The choice is stored in browser local storage and can be changed through Analytics settings in the footer.
- Disconnecting revokes the Intuit grant where possible and removes stored credentials. Period snapshots, checksums, mappings, and evidence already created remain under the customer's retention policy, and an owner can export all organization data or start deletion, which removes tenant data after a cancellable 30-day read-only window.
- Privacy questions and export or deletion requests go to [email protected]; an organization owner can also run export and deletion directly in Administration.
Every published document — including the security and data boundary and the billing and cancellation policy — is at tdrpreflight.com/legal.