Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains how LedgerWatch ("we", "us") collects, uses, and protects information when you use the LedgerWatch application (the "Service").
1. Information we collect
- Account information: the email address you register with and authentication metadata handled by our authentication provider. We never store your password in plain text.
- QuickBooks Online data: once you authorize a company, we read via Intuit's APIs the company name and realm identifier, bank and credit card account names, balances and last activity dates, and transaction records including date, amount, description, payee/vendor, and assigned account or category.
- OAuth tokens: access and refresh tokens issued by Intuit, stored encrypted at rest.
- Operational data: sync timestamps, sync outcomes, and error messages used to display connection health.
2. How we use information
We use the information solely to provide the Service, specifically to:
- Show which client companies have uncategorized or unreviewed transactions.
- Flag transactions missing a vendor or payee.
- Detect potentially stale or disconnected bank feeds and high transaction volume.
- Cluster repeating transaction descriptions into suggested categorization rules.
- Maintain, secure, troubleshoot, and improve the Service.
We do not sell personal information, we do not share it with advertisers, and we do not use QuickBooks data for advertising or for training third-party models.
3. Legal basis and consent
We access QuickBooks Online data only after you explicitly authorize a company through Intuit's OAuth 2.0 consent screen. You can revoke that authorization at any time from within LedgerWatch or from your Intuit account settings.
4. Service providers
We use third-party infrastructure to operate the Service, including cloud application hosting and a managed database and authentication provider. These providers process data on our behalf under their own security and confidentiality obligations. We also exchange data with Intuit Inc. to authorize connections and read QuickBooks Online data at your direction.
5. Security
- All traffic to the Service is encrypted in transit using HTTPS/TLS.
- Intuit OAuth tokens are encrypted before being written to the database.
- Database access is restricted with row-level security so each account can read only its own companies, accounts, transactions, and rule suggestions.
No system can be guaranteed perfectly secure, but we work to protect data using industry standard practices.
6. Data retention and deletion
Cached QuickBooks data is retained while a company remains connected so the dashboard can display current status. When you disconnect a company, its tokens and cached accounts, transactions, and rule suggestions are deleted from the Service. When you delete your account, all associated data is removed. You may also request deletion using the contact details below.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal information we hold about you, and to withdraw consent for QuickBooks access. To exercise these rights, contact us using the details below.
8. Children's privacy
The Service is a business tool and is not directed to children under 16, and we do not knowingly collect their personal information.
9. International transfers
Data may be processed in the United States or other countries where our service providers operate. We rely on appropriate safeguards for any cross-border transfer.
10. Changes to this policy
We may update this policy from time to time. The revision date at the top of this page will reflect the most recent update.
11. Contact
Privacy questions and deletion requests can be sent to Agate CPA at support@agatecpa.com.
Intuit and QuickBooks are trademarks of Intuit Inc. LedgerWatch is not affiliated with, endorsed by, or sponsored by Intuit Inc.