1. Scope
This Privacy Policy applies to the Tax Shack Bookkeeping Operations web application (the “App”) operated by Tax Shack for authorized staff and administrators. The App is a controlled internal beta, not a public bookkeeping service or consumer product.
This policy does not replace the privacy terms of QuickBooks Online, Intuit, Karbon, or other services that a user separately accesses. It also does not govern Tax Shack websites or services that link to a different privacy notice.
2. Information we process
The App may process the following categories of information:
- Staff identity and access data: name, work email address, role or administrative capabilities, password verification data, session records, and sign-in security events.
- Karbon workflow data: permitted client or organization identifiers and names, roster membership, staff references, work-item titles, assignments, status, due dates, completion details, and related operational metadata.
- QuickBooks Online data: connected company identifiers and profile information, preferences, account information, and the financial reports the current App is built to retrieve, including profit-and-loss and balance-sheet observations.
- Connection credentials: OAuth access and refresh tokens, connection status, expiration dates, and authorization metadata. Token values are encrypted before database storage and are not displayed to App users.
- Operational and security data: request time, provider route, status, duration, redacted error category, provider request identifier, sync state, browser or user-agent information, and protected network-origin indicators used for security and audit purposes.
The App is not designed to collect payment-card details, consumer login credentials for banks, or tax documents through these provider connections. Because financial reports and workflow records can still contain sensitive business or personal information, users must treat all App data as confidential.
3. Where information comes from
- Authorized Tax Shack staff who create accounts, sign in, select a client, or start an approved connection or sync.
- Karbon, through Tax Shack’s authorized firm-level API credentials.
- QuickBooks Online, after an authorized administrator grants access to a specific company through Intuit’s OAuth consent flow.
- The App’s hosting, database, and security infrastructure when it records operational events needed to run and protect the service.
4. How we use information
Tax Shack uses information processed by the App to:
- authenticate authorized staff and maintain secure sessions;
- show a provider-backed client roster and bookkeeping work context;
- connect an authorized QuickBooks company to the matching internal client record;
- retrieve and display the limited company, account, preference, and financial-report data supported by the current beta;
- monitor connection health, troubleshoot failures, prevent misuse, and maintain auditability; and
- meet legal, security, and professional obligations applicable to Tax Shack’s operations.
The current beta is read-oriented. Its ordinary product workflows do not post accounting entries to QuickBooks Online or modify Karbon records. A disabled low-level Karbon write primitive in the codebase is not an approved or user-facing write workflow.
5. How information is shared
Access is limited to authorized Tax Shack personnel and service providers that host or support the App under appropriate confidentiality and security obligations. Information may also be exchanged with Intuit or Karbon as necessary to complete an authorized connection, retrieve requested data, refresh authorization, or diagnose a provider error.
Tax Shack does not sell personal information, share it for cross-context behavioral advertising, or use App data to deliver targeted advertising. Information may be disclosed when required by law, to protect rights or security, or as part of a business reorganization subject to appropriate safeguards.
6. Cookies and local storage
The App uses strictly necessary cookies for staff sessions, session re-verification, and the short-lived security state needed for QuickBooks authorization. The private workspace may also use browser storage for interface preferences or clearly identified demo-only state. Provider credentials are not stored in browser local storage.
Blocking necessary cookies may prevent sign-in or provider authorization from working. The current App does not use third-party advertising cookies.
7. Security
Tax Shack uses administrative, technical, and organizational safeguards appropriate to an internal financial-operations tool. Current controls include restricted staff access, named sessions, authorization checks around integration routes, encrypted QuickBooks OAuth tokens, server-side provider credentials, and redacted operational logging.
No system can guarantee absolute security. Authorized users must protect their access credentials, avoid copying client information into unapproved systems, sign out of unattended devices, and report suspected exposure promptly through Tax Shack’s private support process.
8. Retention and deletion
Tax Shack retains App information only for as long as reasonably needed for the controlled beta, bookkeeping operations, security and audit records, legal or professional obligations, and dispute resolution. Different records may have different retention periods. Backup copies may remain for a limited period before routine expiration.
An authorized company administrator may revoke Tax Shack’s QuickBooks access through Intuit. Revocation stops future provider access but does not automatically erase records already held in the App. To request disconnection or deletion of App-held information, contact Tax Shack using the channel below. Tax Shack will verify authority, assess legal and professional retention duties, remove or de-identify eligible information, and explain any information it must retain.
9. Your choices
Depending on your relationship to Tax Shack and applicable law, you may ask to:
- review or correct your staff account information;
- deactivate a staff account or revoke an active session;
- disconnect a QuickBooks company and revoke its grant;
- access, correct, or delete eligible App-held personal information; or
- receive an explanation of a retention or access decision.
Requests must use a trusted Tax Shack contact channel and may require identity and authority verification. Client-company requests may need to come from the company’s authorized representative.
10. Children
The App is a professional, staff-only operations tool and is not directed to children. Tax Shack does not knowingly use the App to collect personal information from children.
11. Changes and contact
Tax Shack may update this policy as the beta and its data practices change. The date at the top identifies the current version. Material changes will be communicated to authorized users through an appropriate internal channel before they take effect when required.
For privacy questions, access or deletion requests, or a security concern, use the verified contact channel published at mytaxshack.com and identify the request as concerning Tax Shack Bookkeeping Operations. Do not include passwords, OAuth tokens, bank credentials, or client financial records in an initial message.
