Privacy policy
Last updated: August 26, 2026
This Privacy Policy explains how GSAT, INCORPORATED collects, uses, discloses, retains, and protects information through its private QuickBooks integration (the Integration). The Integration is intended for authorized internal business use and is not offered for public registration.
1. Information covered
Depending on the capability an authorized person invokes, the Integration may process QuickBooks company and realm identifiers; OAuth access and refresh credentials; company settings; chart-of-accounts and reference data; accounting transactions and reports; customer, vendor, product, invoice, payment-status, and related accounting information; user and service identities; request identifiers; configuration metadata; audit events; and idempotency or incident records needed to operate the Integration safely.
The initial production release does not intentionally collect Social Security numbers, complete bank-account or payment-card numbers, dates of birth, full home addresses, or unrelated human-resources data. Payroll processing, payment credential collection, charges, refunds, and money movement are outside the initial production scope.
2. Sources of information
Information may come from Intuit and QuickBooks Online through an administrator-authorized OAuth connection, from authorized GSAT, INCORPORATED personnel, from approved internal systems, and from security or operational events produced by the Integration.
3. How information is used
GSAT, INCORPORATED uses information to authenticate and authorize access; connect and disconnect QuickBooks Online; perform approved accounting reads and guarded workflows; support reconciliation, reporting, invoice-status, and related operations; prevent duplicate or unauthorized activity; investigate errors and uncertain provider outcomes; maintain security and audit evidence; comply with law and contracts; and improve the reliability and safety of the Integration.
4. Artificial intelligence
Authorized personnel may use OpenAI or Anthropic services through a local MCP client to process bounded QuickBooks information returned by explicit Integration capabilities for audit, reconciliation, anomaly review, classification assistance, and explanations. AI output is advisory and human-reviewed. GSAT, INCORPORATED does not intentionally use QuickBooks information to train or fine-tune AI models and prohibits such training within the Integration workflow.
5. Disclosure and service providers
GSAT, INCORPORATED may disclose information to Intuit for QuickBooks Online and OAuth services; Cloudflare for hosting, network security, encrypted state, and operational infrastructure; OpenAI or Anthropic when an authorized user invokes an AI-assisted workflow; professional advisers under appropriate duties; and authorities or other parties when required by law, necessary to protect rights or security, or involved in a permitted business reorganization.
GSAT, INCORPORATED does not sell QuickBooks information, use it for cross-context behavioral advertising, or provide it to unrelated parties for their independent marketing. Service providers may process information only for authorized purposes and under their applicable agreements and settings.
6. Retention and deletion
Encrypted OAuth credentials are retained while the QuickBooks connection is active or while needed to resolve a recorded authorization incident. The normal disconnect process revokes the provider authorization before deleting the gateway credential record. Bounded QuickBooks response data is generally processed transiently unless an approved workflow requires a defined record.
Routine OAuth lifecycle and report-read audit records are configured for a 30-day retention window and bounded record caps, with expired records removed during the next applicable audited operation. Capability-operation records for successful and failed outcomes are normally eligible for removal after 30 days. Uncertain operations, unresolved security or authorization incidents, legal holds, accounting obligations, disputes, and records needed to prevent duplicate activity may be retained longer until the relevant purpose is resolved.
7. Security
GSAT, INCORPORATED uses measures designed to protect information, including encrypted OAuth credentials, separate sandbox and production environments, least-privilege access controls, fixed provider destinations, typed and bounded capabilities, request and response validation, redacted diagnostics, confirmation gates for sensitive operations, and direct provider readback. No system can guarantee absolute security.
8. Access and choices
An authorized administrator may review or revoke the QuickBooks connection through QuickBooks Online or the protected Integration administration area. Authorized personnel may request correction or deletion of Integration-controlled information, subject to identity verification and any security, contractual, accounting, or legal retention requirement. Revoking the Integration does not delete accounting records held by QuickBooks Online.
9. Data locations
The Integration and its service providers may process information in the United States and other locations where they operate, subject to their contractual and legal safeguards. The initial Integration is configured for United States QuickBooks Online connections.
10. Children
The Integration is a business accounting tool and is not directed to children. GSAT, INCORPORATED does not knowingly use it to collect information from children.
11. Changes to this Policy
GSAT, INCORPORATED may update this Policy when the Integration, its data practices, service providers, or legal requirements change. The revised version will be posted at this URL with an updated date. Material changes will be communicated when required.
12. Contact
Legal and privacy questions may be sent to ebodor@gsati.com.