Privacy Policy
Last updated: July 25, 2026
This Privacy Policy explains how Finorbi (“Finorbi,” “Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the Finorbi Finance Data Manager application and related services (collectively, the “Service”). This Policy applies to visitors to our website, registered Users of the Service, and Authorized Users invited to an Account (collectively, “you”).
The Service connects to QuickBooks Online (“QBO”), a product of Intuit Inc. (“Intuit”), through Intuit’s official OAuth 2.0 authorization framework. This Policy describes Finorbi’s own data practices. It does not describe, and Finorbi does not control, how Intuit collects, uses, or protects data within QuickBooks Online itself — that is governed by Intuit’s own privacy statement, available at Intuit’s website.
This Policy is incorporated by reference into, and should be read together with, Finorbi’s End-User License Agreement.
1. Information We Collect
1.1 Information You Provide Directly
- Account information obtained through "Sign in with Intuit": your name and email address, as returned by Intuit's identity/OpenID Connect layer when you authenticate. Finorbi does not collect or store a separate password — authentication is handled entirely by Intuit.
- Company and role information: which QuickBooks Online company (or companies) you connect, and the role (e.g., Admin, Viewer) assigned to you or Authorized Users you invite within the Service.
- Uploaded files: Excel/CSV workbooks you upload for import, which may contain financial and business data such as vendor names, customer names, amounts, dates, memos, and account references.
- Communications: information you provide when contacting support, such as your email address and the content of your message.
- Billing information: your billing name, email, and related subscription details. Full payment card numbers are collected and stored directly by Stripe, Inc., our payment processor — Finorbi does not receive or store your full card number.
1.2 Information We Access From QuickBooks Online
Once you authorize a connection, and strictly within the scope of permissions you grant during QuickBooks Online’s own OAuth consent screen, the Service accesses accounting data necessary to perform the specific action you request, which may include:
- Transaction data (e.g., Bills, Invoices, Journal Entries, Payments, and similar records) for import, export, or deletion actions you initiate
- List/reference data (e.g., Vendors, Customers, Employees, Classes, Locations, Accounts, Products & Services) needed to validate, match, or create records as part of an import
- Company metadata (e.g., company name, realm identifier) needed to identify which QuickBooks Online company a given action applies to
Some of this reference data (for example, a list of Vendor or Account names) is cached locally by the Service to make repeated lookups faster and to reduce the number of calls made to QuickBooks Online’s API. This local cache reflects a snapshot of your QuickBooks Online data as of the last time it was synced and is used solely to operate the Service for your Account.
1.3 Information Collected Automatically
- Session and authentication data: a session identifier stored in an encrypted, signed browser cookie, used to keep you signed in and to enforce the Service's automatic idle-timeout security feature.
- Usage and log data: information about how you use the Service, such as pages visited, actions taken (e.g., an import or export was run), timestamps, IP address, and browser/device information, collected for security, troubleshooting, and service-improvement purposes.
- Import/export/deletion history: records of the actions you take through the Service — for example, that a particular file was imported on a particular date, how many rows succeeded or failed, and (where relevant to showing you useful results) the specific field values involved, such as a vendor name or transaction amount that appeared in a processed row.
2. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Service, including performing the imports, exports, and deletions you request
- Authenticate you and maintain the security of your Account and Connected Companies
- Process payments and manage your Subscription, through Stripe
- Send transactional communications, such as confirmation that an import or export completed, security notices (e.g., regarding your QuickBooks connection), and, where you have not opted out, product or account-related notifications
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Diagnose and fix technical problems, and improve the reliability and performance of the Service
- Comply with legal obligations and enforce our End-User License Agreement
We do not use your QuickBooks Online financial data to train general-purpose machine-learning models, and we do not sell your data.
3. How We Share Information
We do not sell your personal information or your QuickBooks Online data. We share information only in the following circumstances:
3.1 With Intuit / QuickBooks Online
By design, the Service reads data from and writes data to your Connected Company via QuickBooks Online’s official API, because that is the core function you are requesting. This is not a third-party “sale” or “sharing” in the marketing sense — it is the Service performing the action you directly asked it to perform.
3.2 Service Providers (Subprocessors)
We use a limited number of third-party service providers to operate the Service, each bound by contractual confidentiality and data-protection obligations appropriate to the data they process:
| Provider | Purpose | Data Involved |
|---|---|---|
| Stripe, Inc. | Payment processing and subscription billing | Billing name/email, payment method details (held by Stripe directly, not by Finorbi) |
| Intuit Inc. | Identity authentication (Sign in with Intuit) and the QuickBooks Online API | Name, email (via OpenID Connect); accounting data accessed per your authorization |
| Email delivery provider | Sending transactional emails, such as import/export completion notices and account notifications | Recipient email address, name, and the content of the relevant notification |
| Hosting/infrastructure provider | Application hosting and database storage | All data described in Section 1, as necessary to operate the Service |
3.3 Legal Requirements
We may disclose information if required to do so by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
3.4 Business Transfers
If Finorbi is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections. We will notify you of any change in ownership or use of your information as required by law.
3.5 With Your Consent
We may share information for any other purpose with your consent.
4. Data Security
We implement technical and organizational measures designed to protect your information, including:
- Encryption of QuickBooks Online OAuth access and refresh tokens at rest, using industry-standard authenticated encryption, with the encryption key stored separately from other application secrets
- Encryption of data in transit via HTTPS/TLS
- Signed, encrypted session cookies with a sliding idle-timeout that automatically ends an inactive session
- Logical separation of data between different Users and companies, so that access to one company's data is restricted to Users authorized for that specific company
- Role-based access controls limiting what Authorized Users with a given role (e.g., Viewer) can do within a Connected Company
- Signature verification on inbound webhook communications from our payment processor
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and any applicable regulator as required by applicable law.
5. Data Retention
We retain information for as long as reasonably necessary to provide the Service and for the purposes described in this Policy, and as follows:
- Account and Connected Company data is retained for as long as your Account remains active.
- QuickBooks Online OAuth tokens are retained until you disconnect a Connected Company or your Account is terminated, at which point they are deleted or rendered unusable.
- Import, export, and deletion history records (including which rows succeeded or failed and summary information about them) are retained to give you an ongoing audit trail of actions taken through the Service, for a period of 2 years.
- Files generated for export or download are retained for a limited operational period and may not remain available for the full duration that a corresponding history record is retained; where a previously generated file is no longer available, the Service will indicate this rather than provide a broken or incorrect download.
- Billing records are retained as required for tax, accounting, and legal compliance purposes.
Upon Account termination, we will delete or de-identify your personal information within a reasonable period, except where retention is required for legal, tax, security, or dispute-resolution purposes.
6. Your Rights and Choices
6.1 For All Users
- Access and correction: you can review and update your name/email through your connected Intuit account, since Finorbi does not maintain a separate password-based profile.
- Disconnecting QuickBooks Online: you may disconnect any Connected Company at any time from within the Service or from QuickBooks Online's own "Apps" menu, which ends the Service's ability to access that company's data going forward.
- Account deletion: you may request deletion of your Account and associated data by contacting us at the address in Section 12, subject to the retention exceptions described in Section 5.
- Marketing communications: where we send non-essential marketing communications, you may opt out via the unsubscribe mechanism in those messages; this does not apply to essential transactional or security-related communications about your Account.
6.2 Additional Rights for Residents of the EU/UK/EEA (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data; restrict or object to certain processing; request portability of data you provided to us; and lodge a complaint with your local data protection authority.
6.3 Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the right to: know what personal information we collect, use, and disclose; request deletion of your personal information; correct inaccurate personal information; and not receive discriminatory treatment for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined under the CCPA.
6.4 How to Exercise Your Rights
You may exercise any of the above rights by contacting us using the information in Section 12. We may need to verify your identity before fulfilling certain requests.
7. International Data Transfers
Depending on where you and our service providers are located, your information may be transferred to, stored, and processed in a country other than your own. Where required, we rely on appropriate safeguards for such transfers, such as Standard Contractual Clauses.
8. Cookies and Similar Technologies
The Service uses a strictly necessary session cookie to keep you signed in and to enforce security features such as the automatic idle-timeout. This cookie is essential to the Service’s operation and is not used for third-party advertising or cross-site tracking.
9. Children's Privacy
The Service is intended for business use by adults and is not directed to, and should not be used by, individuals under the age of 18 (or the applicable age of majority). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the “Last Updated” date above and, where required by law or where changes are significant, by providing additional notice (such as email or an in-app notification). Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise any of the rights described above, please contact:
Finorbi
Email: [email protected]
Website: https://www.finorbi.com
