Effective Date: 2025-08-27
App Name: dff-report-generator
Company: Biocode, LLC
Primary Contact: john@biocodellc.com,
25362 High Pass Road, Junction City, OR 97448
Draft TODOs
- Replace privacy request email placeholders with final addresses.
- Confirm whether a "Do Not Sell or Share" link is needed and where it should point.
- Confirm retention periods for logs, support records, backups, and OAuth tokens.
- Confirm actual subprocessors and analytics/cookie practices.
Plain-English Summary
The App connects to QuickBooks Online (QBO) only with customer consent, reads data needed to generate requested reports, and does not sell personal information. Customers can disconnect access from QBO or by contacting the app operator.
1. Scope
This Policy describes how we handle personal data when you use the App, our websites, and support channels. It does not cover third-party services such as Intuit QuickBooks Online, which have their own policies.
2. Personal Data We Collect
- Account and contact data: Name, email, company, role, and billing contact details.
- Auth and connection data: OAuth tokens, realm/company ID, scope grants, and connection timestamps.
- QBO data: Chart of accounts, customers, invoices, sales receipts, payments, products/services, classes/locations, and related metadata needed to generate requested reports.
- Usage and device data: App interactions, logs, IP address, browser/OS metadata, and diagnostics.
- Support content: Messages, attachments, and context sent to support.
Do not submit sensitive personal data unless necessary and permitted by law.
3. Sources of Data
- You, when you install or use the App, connect QBO, or contact support.
- Intuit QBO APIs, after access is granted.
- Service providers that help operate the App.
4. How We Use Data
- Provide, operate, and maintain the App.
- Generate reports and outputs requested by customers.
- Authenticate, secure, prevent abuse, debug, and resolve incidents.
- Respond to requests and provide support.
- Analyze and improve features and performance where appropriate.
- Comply with legal obligations and enforce terms.
We do not sell or share personal information for cross-context behavioral advertising.
5. Legal Bases
Where GDPR or UK GDPR applies, processing bases may include performance of a contract, legitimate interests, consent for optional features, and legal obligations.
7. International Transfers
Data may be processed in the United States and other countries. Where required, appropriate safeguards should be confirmed during legal review.
8. Data Retention
Retention periods are draft values and must be confirmed before publishing.
- OAuth tokens: Stored while the QBO connection remains active.
- Logs and diagnostics: [TODO: retention period].
- Support records: [TODO: retention period].
- Backups: [TODO: retention period].
9. Security
We implement reasonable technical and organizational measures such as encryption in transit, access controls, least-privilege practices, and monitoring. No method is completely secure.
10. Your Rights and Choices
- Request access, correction, deletion, portability, restriction, or objection where applicable.
- Withdraw consent for optional features where processing is based on consent.
- Disconnect QBO access from within QBO or by contacting us.
- Submit privacy requests to [TODO: privacy email].
- California CPRA link, if required: [TODO: Do Not Sell or Share URL].
12. Children's Privacy
The App is not directed to children under 16. Contact us if you believe data from a child was collected.
13. Controller / Processor Roles
For user/account data, we act as a controller. For QBO data processed on customer instructions to generate reports, we act as a processor/service provider.
14. Changes to this Policy
We may update this Policy from time to time. If changes are material, we will provide notice and update the Effective Date.
15. Contact
Questions or requests? Contact [TODO: privacy email] or write to the postal address above.
Annex: Subprocessors
Current subprocessors must be confirmed before publishing.
- Cloud hosting and database: [TODO].
- Error monitoring: [TODO].
- Email delivery: [TODO].
- Analytics, if used: [TODO].