PowerBoot Account Management Integration — Privacy Policy

Application privacy policy · Last updated: September 9, 2026

This policy covers the PowerBoot Account Management Integration application only — the data it reads from and writes to a connected QuickBooks Online company. Our general privacy policy covers the PowerBoot website and our consulting engagements, and continues to apply alongside this one. Privacy questions or requests: [email protected].

1. Who We Are and Our Role

PowerBoot ("we," "us," "our") is an automation consulting firm based in Alberta, Canada. We publish and operate the Application. You can reach us at [email protected] or +1 (587) 412-5222.

The Application is used by an accounting or bookkeeping practice (the Firm) to serve its own client (the Connected Business) — the business whose QuickBooks Online company is connected.

For the accounting data accessed through the Application, the Connected Business and the Firm determine why the data is processed. PowerBoot processes it on their instructions, as a service provider — a processor under GDPR terminology, and an organization processing on behalf of another under PIPEDA. We do not use that data for our own purposes.

2. What the Application Accesses

The Application requests one QuickBooks Online permission scope: Accounting (com.intuit.quickbooks.accounting). Within that scope, it reads only what is needed to compare your ledger against a reference statement:

  • Transactions and expenses recorded in the company — date, amount, description, memo, and account coding
  • Bills, cheques, deposits, transfers, and journal entries relevant to the period being reconciled
  • The chart of accounts, and the bank and credit card account registers in the company file — account names, types, and balances
  • Vendor, customer, and payee names as they appear on those transactions
  • Reconciliation status and cleared/uncleared state for the period
  • Basic company profile information — legal and trade name, address, fiscal year end, and the QuickBooks Online company (realm) identifier

The Application does not access payroll or employee compensation records, online banking credentials or bank feed logins, Intuit sign-in credentials, payment card numbers, or government identification numbers such as SIN or SSN.

3. What the Application Writes

The Application creates ledger entries in the connected company for transactions that appear on the reference statement but are missing from QuickBooks Online, and records the reconciliation acknowledgement for the period once the comparison is complete.

It does not delete existing entries, does not restructure the chart of accounts, and does not alter transactions already recorded correctly.

4. Reference Statements

To perform the comparison, the Application needs a reference bank or credit card statement for the period. This is supplied to us by the Firm or by the Connected Business — it is not retrieved from your bank, and the Application holds no banking credentials.

A statement typically contains the account holder's name and address, a full or partial account number, the statement period, opening and closing balances, and the individual transaction lines. We treat the whole statement as confidential, and use it only for the comparison described above.

What happens to the document. On receipt it is read by optical character recognition to extract the transaction lines (section 7). The comparison and any resulting ledger entries are then completed against QuickBooks Online, and the connection is closed. The original document is filed into the Firm's own SharePoint environment — owned, operated, and solely administered by the Firm, in the Firm's own Microsoft tenant. PowerBoot's working copy, and the extracted data derived from it, are purged at that point. We do not keep an archive of your statements.

5. Why We Process This Data

Purpose limitation is a hard boundary, not a preference. Data accessed through the Application is used only to:

  • Identify transactions present on the reference statement but missing from QuickBooks Online
  • Create those missing entries in the ledger
  • Record the reconciliation acknowledgement for the period
  • Produce a record of what the Application did, so the Firm can review it
  • Diagnose faults and maintain the security and reliability of the Application

We do not sell, rent, or trade this data. We do not use it for advertising or marketing. We do not use it to train machine learning or AI models. We do not aggregate it into benchmarks, market data, or any product offered to third parties.

6. Legal Basis and Consent

Processing is grounded in the authorization the Connected Business grants in QuickBooks Online, and in the Firm's professional engagement with the Connected Business. Under PIPEDA and Alberta PIPA, that authorization is the consent for the purposes described in section 5. Where GDPR applies, the legal basis is performance of a contract and the legitimate interests of the Firm and the Connected Business in accurate books.

Consent is withdrawn by disconnecting the Application — see section 10.

7. Automated Processing

Where a reference statement arrives as a PDF or scanned image, its transaction lines are read by optical character recognition before any connection to QuickBooks Online is opened. We use Mistral OCR, operated by Mistral AI SAS (France), for this step, under commercial API terms that prohibit the use of customer content to train models. The document is transmitted for extraction and the text is returned; it is not stored by us for any purpose beyond completing that reconciliation.

Matching the extracted lines to ledger entries is also automated, as is the verification that the statement and the connected company belong to the same business — the Application will not write to a company where those checks disagree.

Automated matching produces a proposal, not a professional judgement. The Firm reviews the result. No decision with legal or similarly significant effect on an individual is made solely by automated means.

8. Storage, Location, and Security

The Application processes data in a working session rather than accumulating it. Statements and extracted accounting data exist only for as long as the reconciliation takes, on servers located in Canada, with OVH Cloud in the Beauharnois, Quebec region. When the work finishes, the connection is closed and that working data is purged.

  • OAuth access and refresh tokens for your QuickBooks Online company are encrypted at rest, held only while your authorization remains active, and never displayed to Firm staff or PowerBoot staff
  • All traffic to Intuit, to Mistral AI, and to PowerBoot systems is encrypted in transit using TLS
  • Access to production systems is restricted to PowerBoot personnel who need it, under individual credentials with multi-factor authentication
  • Each connected company is identified by its QuickBooks Online realm identifier; a Firm can only reach the companies connected to it
  • Before any entry is written, the Application verifies that the statement and the target company match on several independent points, and halts rather than writing to a company it cannot confirm

Your QuickBooks Online data itself continues to reside in Intuit's infrastructure, which is outside PowerBoot's control and governed by your agreement with Intuit.

9. Retention

PowerBoot does not retain your accounting data. There is no archive, no data warehouse, and no copy kept "in case it is useful later."

  • Reference statements: not retained. Purged once the reconciliation is complete and the original has been filed to the Firm's SharePoint environment.
  • Extracted and compared accounting data: not retained. Purged at the end of the same working session.
  • Access tokens: held only while your authorization remains active, so the Firm can run the next period's reconciliation without asking you to re-authorize. Revoked and deleted on disconnection.
  • Event log: the one thing that persists. It records that an action occurred — timestamp, company identifier, which operation ran, how many records were read or written, and whether it succeeded or halted. It does not contain statement images, transaction details, or account balances. Retained for up to 12 months so that a past run can be explained, and for security monitoring.

Entries the Application wrote into your QuickBooks Online company are part of your books, held by Intuit, and are not deleted by us. The original documents you supplied live in the Firm's SharePoint environment under the Firm's own retention policy, which PowerBoot does not control.

10. Disconnection and Deletion

The Connected Business may disconnect the Application at any time from Settings → Apps → My Apps in QuickBooks Online. On disconnection:

  • The Application's access to your company ends immediately
  • We revoke the stored OAuth tokens with Intuit and delete them from our systems
  • No accounting data or statements remain to be deleted — under section 9 these are already purged at the end of each run
  • The event log ages out on the schedule in section 9

You may ask us to confirm deletion in writing, or request erasure of the event log entries for your company, by emailing [email protected]. Documents held in the Firm's SharePoint environment are requested from the Firm, not from us.

11. Who We Share Data With

We share data accessed through the Application only with:

  • The Firm engaged by the Connected Business — this is the point of the Application
  • Intuit Inc. — the source and destination of the accounting data, under your own agreement with Intuit
  • OVH Cloud — hosting of PowerBoot infrastructure, in Canada
  • Cloudflare, Inc. — network security and routing for PowerBoot endpoints; Cloudflare handles connection metadata in transit
  • Mistral AI SAS (France) — optical character recognition of statements supplied as PDF or image, as described in section 7; contractually barred from training on customer content
  • Microsoft Corporation — the Firm's SharePoint environment, where original documents are filed. This is the Firm's own tenant under the Firm's agreement with Microsoft, not PowerBoot's.
  • Legal requirements — where disclosure is compelled by law, court order, or regulatory authority

Each provider processes data on our behalf under contract. None of them is permitted to use your data for their own purposes.

12. International Transfers

PowerBoot's own processing for the Application takes place in Canada. Optical character recognition is performed by Mistral AI in the European Union, which Canadian privacy law treats as a transfer to a third party for processing and which is subject to comparable protection under EU law. Intuit and Cloudflare operate globally and may process data outside Canada. Each provider maintains data processing terms and, where GDPR applies, appropriate transfer mechanisms including Standard Contractual Clauses. The location of your QuickBooks Online company data is determined by Intuit, and the location of the Firm's SharePoint tenant by the Firm.

13. Your Rights

Under PIPEDA, Alberta PIPA, and where applicable the GDPR, you may request access to the personal information we hold, correction of inaccurate information, deletion, restriction of processing, a portable copy, or withdrawal of consent.

Because PowerBoot processes this data on behalf of the Firm and the Connected Business, requests are normally directed to the Firm first, and we assist the Firm in fulfilling them. You may also contact us directly at [email protected], and we will respond within 30 days. You may lodge a complaint with the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner of Alberta, or your applicable supervisory authority.

14. Breach Notification

If a breach of security safeguards affecting data accessed through the Application creates a real risk of significant harm, we will notify the affected Firm and Connected Business, and the applicable privacy regulators, without unreasonable delay and in accordance with PIPEDA and any other applicable law.

15. Children

The Application is a business tool and is not directed to individuals under the age of majority. We do not knowingly collect personal information from children.

16. Changes to This Policy

We may update this policy. Material changes are reflected in the "Last updated" date above. Where a change expands what the Application accesses or what we do with the data, we will communicate it through the Firm and, where a broader permission scope is required, request a fresh authorization in QuickBooks Online before the change takes effect.

17. Contact

For privacy inquiries, access or deletion requests, or complaints regarding the Application: