At BizDoc ("BizDoc," "Company," "we," "our," or "us"), protecting your data and your clients' data is our highest priority. This Privacy Policy describes how we collect, use, store, share, and protect information when you use the BizDoc website (bizdoc.io), embeddable widgets, APIs, and related services (collectively, the "Service").
This Privacy Policy applies to: (1) Users — accounting professionals, bookkeepers, and financial advisors who create BizDoc accounts; and (2) Clients — individuals or businesses who connect their QuickBooks Online files through a User's embedded Widget.
BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. If you do not agree with our data practices, please do not use the Service.
We collect different types of information depending on how you interact with the Service:
When you register for a BizDoc account, we collect:
When a Client connects their QuickBooks Online file through a User's embedded Widget, we collect:
When a Client authorizes access to their QuickBooks Online file, we receive an OAuth2 access token from Intuit. Using this token, we access read-only data from specific QBO endpoints.
BizDoc requests only the following OAuth scopes from Intuit:
com.intuit.quickbooks.accounting (read-only access to accounting data)openid, profile, email (user identity verification)We do NOT request write permissions. BizDoc cannot create, modify, or delete any data in your QuickBooks Online file.
Within the accounting scope, we access only the following specific endpoints:
| Data Category | QBO API Endpoint | Why We Access This |
|---|---|---|
| Company Profile | CompanyInfo |
Identify the business name, fiscal year settings, and basic company details for the report header |
| Chart of Accounts | Account |
Analyze account structure, identify uncategorized accounts, and assess bookkeeping organization |
| Balance Sheet Report | Reports/BalanceSheet |
Calculate financial ratios (current ratio, debt-to-equity), assess solvency and stability |
| Profit & Loss Report | Reports/ProfitAndLoss |
Analyze revenue trends, expense patterns, and profitability for health scoring |
| Aged Receivables Report | Reports/AgedReceivables |
Calculate Days Sales Outstanding (DSO), identify collection risk and AR aging over 90 days |
| Aged Payables Report | Reports/AgedPayables |
Calculate Days Payable Outstanding (DPO), analyze payment patterns and overdue AP |
We access this data strictly to perform algorithmic analysis and generate Diagnostic Reports. Raw financial data is processed in-memory and discarded immediately after the report is generated. We do NOT permanently store your General Ledger, transaction history, or detailed financial records in our database.
When you access the Service, we automatically collect:
We may receive information about you from:
We use the information we collect for the following purposes:
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Performance of contract |
| Processing payments | Performance of contract |
| Sending transactional communications | Performance of contract |
| Marketing communications | Consent (opt-in) |
| Security and fraud prevention | Legitimate interests |
| Service improvement and analytics | Legitimate interests |
| Legal compliance | Legal obligation |
We do not sell, rent, or trade your personal information or your clients' financial data.
We share information only in the following circumstances:
When a Client connects their QBO file through a User's Widget, we share the following with that User: Client email address, company name, Financial Health Score, letter grade, and the full Diagnostic Report. This sharing is the core function of the Service.
We engage trusted third-party service providers who process data on our behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Railway | Cloud hosting and infrastructure | All Service data (encrypted) |
| Stripe | Payment processing and subscription billing | Payment and billing information |
| SendGrid | Transactional and marketing emails | Email address, name |
| Google Analytics | Website and usage analytics | Anonymized usage data, IP address (anonymized) |
All service providers are bound by data processing agreements and are prohibited from using your data for their own purposes.
We may disclose information if we believe it is necessary to:
If BizDoc is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. For example, we may publish industry benchmarks based on aggregated scoring data.
Our integration with QuickBooks Online complies with Intuit Developer Terms and data security requirements:
BizDoc requests read-only permissions only. We cannot create, modify, edit, or delete any data in connected QuickBooks Online files.
We practice data minimization and request only the OAuth scopes and access the specific API endpoints necessary to provide our Financial Health Score service. We do not request or access more data than is required for our stated purposes (see Section 1.3 for the complete list of data accessed).
OAuth2 access tokens received from Intuit are securely encrypted and stored only as long as necessary to maintain the authorized connection. Tokens are automatically invalidated when access is revoked.
You or your Clients can revoke BizDoc's access to a connected QuickBooks Online file at any time using any of these methods:
What happens when you disconnect: BizDoc's access token is immediately invalidated. We can no longer access any data from that QuickBooks file. Previously generated reports remain in your account history unless you delete them.
| Data Type | Retention Period |
|---|---|
| User Account Data | Duration of account + 30 days after deletion request |
| OAuth2 Access Tokens | Until disconnection or account cancellation |
| Diagnostic Reports (PDFs) | Until User deletes them or account is terminated |
| Lead/Client Contact Info | Until User deletes or account is terminated |
| Raw Financial Data (from QBO) | Not retained — processed in-memory and discarded after report generation |
| Payment Records | 7 years (for tax and legal compliance) |
| Server Logs | 90 days |
When we analyze a connected QBO file, the raw financial data (account balances, transaction summaries, report data) is fetched via API, processed in-memory by our analysis engine, and then discarded. This data is NOT permanently stored in our database. Only the generated scores, grades, and the final PDF report are retained.
You may request deletion of your account and associated data at any time. Upon receiving a verified deletion request, we will delete your personal information within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).
We implement industry-standard security measures to protect your information:
While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the security of your account credentials.
Depending on your location, you may have the following rights regarding your personal information:
You have the right to request a copy of the personal information we hold about you.
You have the right to request correction of inaccurate or incomplete personal information.
You have the right to request deletion of your personal information ("Right to be Forgotten"), subject to certain exceptions.
You have the right to receive your personal information in a structured, commonly used, machine-readable format.
You have the right to request restriction of processing of your personal information in certain circumstances.
You have the right to object to processing of your personal information based on legitimate interests.
Where processing is based on consent, you have the right to withdraw consent at any time.
You or your Clients may revoke BizDoc's access to QuickBooks Online files at any time via:
To exercise any of these rights, please contact us at privacy@bizdoc.io. We will respond to your request within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing certain requests.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share it.
You have the right to request deletion of your personal information, subject to certain exceptions.
You have the right to request correction of inaccurate personal information.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We will not discriminate against you for exercising your privacy rights.
In the past 12 months, we have collected the following categories of personal information:
You may designate an authorized agent to submit requests on your behalf. We may require verification of the agent's authority.
California residents may submit requests to: privacy@bizdoc.io or call us at the number provided in the Contact section.
BizDoc is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on:
By using the Service, you consent to the transfer of your information to the United States and other countries as described in this Privacy Policy.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, core functionality | Session / 30 days |
| Functional | Remember preferences and settings | 1 year |
| Analytics | Understand usage patterns, improve Service | 2 years |
We use Google Analytics to understand how users interact with the Service. Google Analytics sets cookies to collect information about your use of our website, including:
We have enabled IP anonymization in Google Analytics, which truncates your IP address before storage. Google's use of this data is governed by the Google Privacy Policy. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service. Most browsers allow you to:
Some browsers have a "Do Not Track" feature. We currently do not respond to Do Not Track signals, as there is no industry-standard interpretation.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@bizdoc.io.
The Service may contain links to third-party websites, applications, or services (such as Intuit QuickBooks Online, Stripe, etc.). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with BizDoc.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes:
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
BizDoc Financial Systems
Data Protection Officer
Email: privacy@bizdoc.io
General Inquiries: hello@bizdoc.io
Website: www.bizdoc.io
For EU/EEA residents, you also have the right to lodge a complaint with your local supervisory authority.
This Privacy Policy was last updated on January 24, 2026.