Scope
This policy describes Thomas FinOps, a private, no-fee, single-owner reporting tool operated locally. Publication of this policy does not imply that Intuit has approved the proposed private-app arrangement.
Operator
Thomas FinOps is operated by Thomas Barcier. The public privacy and support contact is thomas@thomasbarcier.com.
Data retrieved and generated
With the owner's authorization, the connector retrieves the connected QuickBooks Online company's CompanyInfo, Chart of Accounts, Profit and Loss, Balance Sheet, and General Ledger data for explicitly selected reporting periods. It also processes the company's realm identifier and OAuth credentials and tokens required to maintain the connection. The connector generates encrypted source snapshots, validation results, report comparisons, mapping exceptions, and proposed local staging rows.
Purpose and access
The data is used only to validate and prepare monthly rental-accounting management reports for the authorized owner. Access is limited to the owner/operator and local processes they run on the operator's computer. The connector does not sell data, use it for advertising, make it available to unrelated parties, or expose it through these public informational pages.
Storage and protection
OAuth tokens are stored as encrypted ciphertext in a local database. Retrieved source snapshots are stored as encrypted, write-once local files. The encryption key is held separately in the host operating system's credential manager. Client secrets are supplied only to the local process and are not stored in the public site, browser, repository, or plaintext configuration.
Read-only accounting access
Intuit's QuickBooks accounting OAuth scope is not a granular reporting-only permission. The connector enforces its read-only boundary in code by exposing only GET accounting operations for company identity, accounts, and the three reports. OAuth token exchange, refresh, and revocation use Intuit's OAuth services but do not modify QuickBooks accounting records.
Retention and deletion
Encrypted reporting evidence is retained only while the owner needs it for historical reporting or validation. The owner reviews retained evidence annually and chooses any deletion explicitly. This version has no automatic age-based purge.
Disconnect is a separate confirmed action. It first asks Intuit to revoke the selected authorization, blocks further retrieval while revocation is pending, and removes that connection's local OAuth credentials only after Intuit confirms revocation. Disconnect does not automatically delete historical reports.
The owner may separately preview and confirm deletion of specifically selected encrypted snapshots using the local deletion command. The command does not select connection credentials or the shared encryption key. It performs ordinary filesystem deletion and does not claim secure erasure of backups, filesystem history, storage-device remnants, or copies made outside the connector. Any such copies must be identified and handled separately by the owner.
Sharing and transfers
The current implementation keeps financial processing and storage local. It does not publish report data to a hosted service or the live reporting workbook. Hosting of this page package would be limited to public informational pages and must not receive or serve financial reports. The separate Production HTTPS OAuth callback is not provided by these static pages.
Changes and questions
Material changes to how the connector handles data will require review of this policy. Questions may be sent to thomas@thomasbarcier.com.