Effective date: September 5, 2026
Fintrust Company LLC ("Fintrust," "we," "us," or "our") provides bookkeeping, tax-support, business-registration, and related business services. This Privacy Policy applies to our website at https://www.fintrustcompany.com/, communications and service inquiries submitted through the website, and FinTrust Cleanup App (the "Application"). The Application is a locally operated utility used to review and correct selected QuickBooks Online accounting records with the authorization of the applicable QuickBooks company administrator.
Contact: beniamin.petrosyan@fintrustcompany.com
Website: https://www.fintrustcompany.com/
This Policy describes how we collect, access, use, store, share, retain, and protect information through our website, business communications, and the Application. It also describes choices available to website visitors, authorized Application users, and client companies. Third-party services, including Intuit and our website host, are governed by their own privacy statements and terms.
Website and communications information may include:
• Contact details and other information you choose to submit, such as your name, business name, email address, telephone number, service interests, and message contents.
• Information reasonably necessary to respond to an inquiry, schedule a consultation, prepare a proposal, or provide requested services.
• Basic technical information made available by browsers and website-service providers, such as device or browser type, approximate location derived from an IP address, referring page, pages visited, and timestamps.
• Cookies or similar technologies used by our website host for security, basic functionality, preferences, or measurement, where enabled. You can control cookies through your browser, although some site functions may be affected.
FinTrust Cleanup App information may include:
When an authorized administrator connects a QuickBooks Online company, the Application may receive or access:
• OAuth authorization information, including access tokens, refresh tokens, token-expiration information, the QuickBooks company Realm ID, company name, and connection status.
• QuickBooks chart-of-accounts information, including account names, account types, and account IDs.
• Existing Receive Payment records selected by company, date range, and Deposit To account. These records may contain transaction IDs, synchronization tokens, dates, customer names and identifiers, amounts, payment methods, memos, references, Deposit To account references, and links to applied invoices or other transactions.
• Locally generated technical and audit information, including timestamps, error messages, dry-run reports, update-result reports, and before-and-after copies of records changed through the Application.
The Application does not request online-banking credentials or create replacement or duplicate customer payments as part of its supported workflow. Please do not submit passwords, security codes, full payment-card details, or other credentials through our website contact forms.
We use information as reasonably necessary to:
• Operate, secure, maintain, and improve our website and business communications.
• Respond to questions, consultation requests, and service inquiries.
• Communicate about services requested by you or your organization.
• Prepare and administer client engagements and provide authorized bookkeeping or related services.
• Authenticate authorized connections to QuickBooks Online.
• Display connected companies and available accounts.
• Identify Receive Payments matching criteria selected by an authorized operator.
• Produce read-only dry-run reports for review.
• Make an expressly approved correction to the Deposit To account on an existing Receive Payment.
• Verify that the payment's customer, amount, date, transaction ID, and invoice applications remain unchanged.
• Create audit records, investigate errors, support rollback, maintain bookkeeping accuracy, and meet contractual or legal recordkeeping obligations.
• Protect the security and integrity of the Application and connected accounting records.
We do not use QuickBooks data for advertising, behavioral profiling, or unrelated purposes. We do not sell personal information or QuickBooks data. Where applicable, we process information with consent, to provide requested or contracted services, to meet legal obligations, or for legitimate business purposes such as security and responding to inquiries.
Our public website is hosted using third-party website infrastructure. Information submitted through a website form may be processed by the website host and delivered to Fintrust. Avoid sending sensitive accounting records through a general contact form unless Fintrust has provided an approved secure method.
The Application is a local command-line utility operated on a Fintrust-controlled computer. QuickBooks requests travel directly between that computer and Intuit's OAuth and QuickBooks Online API services.
OAuth token documents are stored separately for each QuickBooks company in a local database. Tokens are encrypted using a key kept in the operating-system credential store or another securely configured local secret store. Client secrets and tokens are excluded from source control. The Application does not print complete tokens in logs.
Dry-run CSV reports and update audit records are stored locally in a restricted application-data directory. An audit record may include complete before-and-after JSON representations of an updated Receive Payment and therefore may contain customer and transaction information.
We may disclose information only:
• To our website, communications, and technology providers as necessary to operate and secure the website and respond to requests.
• To Intuit as necessary to authenticate and use the QuickBooks Online APIs.
• To personnel and contractors authorized by Fintrust or the applicable client company who need the information to provide or review the requested bookkeeping service and who are subject to confidentiality obligations.
• To service providers used to secure, maintain, or support the authorized computing environment, subject to appropriate safeguards.
• When required by law, legal process, professional obligations, or to protect rights, security, and integrity.
• In connection with a business transaction, subject to applicable confidentiality and legal requirements.
We do not sell or rent QuickBooks data or personal information.
Website inquiries and business communications are retained only as long as reasonably necessary to respond, maintain business records, administer a relationship, and meet contractual, professional, tax, security, or legal obligations.
OAuth access and refresh tokens remain stored only while the QuickBooks company connection is maintained. Using the Application's Disconnect function requests token revocation from Intuit and removes the locally stored connection tokens after successful revocation.
Dry-run reports and audit records are retained only as long as reasonably necessary for the bookkeeping engagement, verification, rollback, dispute resolution, security, and applicable contractual, professional, tax, or legal recordkeeping requirements. An authorized client representative may request deletion. We will delete eligible local Application data within a reasonable period, normally within 30 days after verifying the request, unless retention is required or permitted by law, contract, or a professional obligation. Residual copies in protected backups may remain until the backups rotate, subject to continued safeguards.
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information. Website-related safeguards include access controls for our site and business accounts. Application safeguards include OAuth rather than collection of QuickBooks passwords, encryption of locally stored OAuth tokens, restricted local storage, separation of company connections by Realm ID, explicit approval before write operations, current-record and synchronization-token checks, immediate post-update verification, bounded retries, audit logging, and source-control exclusions for secrets.
No method of electronic storage or transmission is completely secure. If we learn of a security incident affecting protected information, we will investigate and provide notices as required by applicable law and our agreements.
You may choose not to submit information through the website and may control cookies through your browser. An authorized QuickBooks administrator can decline authorization, revoke the Application in Intuit, or ask Fintrust to run the Disconnect function. Website visitors and authorized client representatives may contact us to request access to, correction of, or deletion of eligible information associated with them or their company, subject to identity and authority verification and applicable retention obligations. Depending on location, additional privacy rights may apply.
Our website and Application are intended for business and adult users and are not directed to children. We do not knowingly collect children's personal information through them.
The Application is operated from the United States. Information may be processed in the United States and through Intuit's systems as described in Intuit's applicable privacy statements. Where required, we will use appropriate safeguards for cross-border processing.
We may update this Policy to reflect changes in the Application, our practices, or legal requirements. The updated page will show a revised effective date. Material changes will be communicated when required.
Questions or requests concerning this Policy or Application data may be sent to:
Fintrust Company LLC
Email: beniamin.petrosyan@fintrustcompany.com
Website: https://www.fintrustcompany.com/contact-us