QuickBooks Online Integration
Privacy Policy — ASLLC Invoice Automation
Effective date: June 15, 2026
1. Introduction
Company Vitals LLC ("we", "us", or "our") operates ASLLC Invoice Automation, an application that integrates with QuickBooks Online. It is operated for the internal use of a single company and is not distributed to the general public.
This Privacy Policy explains what data the application accesses through QuickBooks Online, how that data is used and protected, and the choices available regarding it.
2. What the App Does
ASLLC Invoice Automation is used for generating a single company's recurring monthly invoices in QuickBooks Online.
3. Data We Access
Through the QuickBooks Online Accounting API, the app accesses only the data required to perform its function:
- Invoices (create/read/update)
- Customers (read)
- Products and services / items (read)
The app does not request or access QuickBooks Online data beyond what is listed above.
4. How Data Is Used and Stored
- QuickBooks Online data is processed in-memory during application executions to perform the function described above.
- QuickBooks Online data is not copied to a separate database or data warehouse.
- OAuth tokens are encrypted at rest.
- All traffic between the app and Intuit is sent over HTTPS/TLS.
- Access to the application and its credentials is restricted to authorized personnel.
5. Security Measures
- All data in transit is encrypted using HTTPS/TLS with a valid certificate.
- OAuth access and refresh tokens are encrypted at rest using an application encryption key. The encryption key is never hardcoded or stored in plaintext.
- The application runs on an access-controlled host that uses key-based administrative authentication.
- The host operating system and software are kept patched and up to date.
- No QuickBooks Online data is persisted to a separate database.
6. Data Sharing
We do not sell, rent, or share QuickBooks Online data. No third-party subprocessors receive QuickBooks Online data accessed by the app, and the data is not used for advertising, marketing, or profiling.
7. Data Retention and Deletion
OAuth tokens are retained only while the app remains connected to QuickBooks Online. You may disconnect the app at any time from the QuickBooks Online "Apps" settings or from the app's own credentials page; doing so revokes and removes the stored tokens. QuickBooks Online data itself remains in QuickBooks under Intuit's policies and is not held by us in a separate store. Deletion requests can be made at any time via the contact email below and will be honored.
8. Data Breach Notification
In the event of a suspected or confirmed data breach involving QuickBooks Online data, we will investigate promptly and notify affected parties and Intuit without undue delay, consistent with applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.
10. Contact
For privacy questions, requests, or data deletion requests, contact us at info@companyvitals.com.