Privacy Policy
Boselli OS — QuickBooks Integration · Last updated 18 August 2026
Who this covers
This policy applies to the Boselli OS QuickBooks Integration ("the Application"), private software operated by The Boselli Foundation ("the Foundation") for its own internal accounting use.
The Application is not offered to the public, not distributed, and cannot be installed by anyone else. It connects to exactly one QuickBooks Online company: the Foundation's own. There are no third-party users.
This policy covers the Application only. It does not cover the Foundation's website, donation processing, or programme activities.
What the Application accesses
Through Intuit's QuickBooks Online API, using the
com.intuit.quickbooks.accounting scope, the Application reads:
- Company profile information
- Financial reports: balance sheet, profit and loss, statement of cash flows
- Accounts receivable and accounts payable ageing detail
What is stored, and where
- Authorisation tokens are stored in a single file on a computer the Foundation controls. They are never transmitted anywhere except to Intuit's own token endpoint, in order to refresh access.
- Financial snapshots — the reports listed above — are written as local files on that same computer, so routine internal reporting can run without repeatedly querying Intuit.
No data is stored on any third-party server, cloud database, or hosted service operated by or for the Application.
What is not done with the data
The Foundation does not:
- Sell, rent, licence, or trade any data obtained through the Application
- Share it with advertisers, data brokers, or analytics providers
- Transfer it to any third party, except where required by law
- Use it to train machine-learning models
- Collect data from anyone other than the Foundation itself
Who can see it
Access is limited to Foundation officers and staff with a legitimate need — principally the Treasurer and those responsible for the Foundation's finances. The data resides on Foundation-controlled equipment.
Security
Credentials and tokens are held in files excluded from version control and are never committed to any code repository. Access tokens are short-lived and refreshed automatically. Authorisation can be revoked at any time from the Intuit account, which immediately ends the Application's access.
Retention
Snapshots are retained for internal financial record-keeping and historical comparison. Tokens are retained only while the integration is in use, and are discarded when authorisation is revoked.
Children's data
The Application accesses accounting records only. It does not collect, process, or store information about programme participants, including minors.
Changes
Material changes to this policy will be reflected in the "Last updated" date above.
Contact
The Boselli Foundation
PO Box 16385, Jacksonville, FL 32245
www.bosellifoundation.com/contact