← Back to sign in

Privacy Policy

Effective Date: April 9, 2026  ·  Last Updated: April 9, 2026


1. Introduction

CFOLink LLC ("CFOLink," "we," "us," or "our") operates the CFOlink platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you access or use the Service.

Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of your information as described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

This Privacy Policy should be read alongside our Terms of Service.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account or use the Service, we may collect:

  • Account information: Full name, email address, and password (stored as a cryptographic hash — we never store your plaintext password)
  • Profile information: Business name, job title, or role, if provided
  • Communications: Any messages or inquiries you send to us at info@cfolink.ai

2.2 Information Collected Automatically

When you use the Service, we automatically collect certain technical information, including:

  • Log data: IP address, browser type, operating system, pages visited, time and date of visit, and referring URLs
  • Device information: Device type, screen resolution, and browser version
  • Usage data: Features accessed, actions taken within the Service, and session duration
  • Cookies and similar technologies: See Section 7 below

2.3 Information from Third-Party Integrations — QuickBooks

If you connect your QuickBooks Online account to the Service, we access your QuickBooks financial data (including transaction records, account balances, and reports) through the Intuit OAuth 2.0 authorization flow. This access is governed by the permissions you grant during the OAuth authorization process.

Important: At the time of this policy, QuickBooks financial data is processed transiently — it is used in real time to generate reports and is not persistently stored on CFOLink's servers beyond what is required to fulfill your request. This may change in the future, and we will update this Privacy Policy and notify you prior to any such change.

We do store the following in connection with your QuickBooks integration:

  • Your QuickBooks OAuth tokens (access token and refresh token), which are encrypted at rest using industry-standard encryption before being stored in our database
  • Metadata about your QuickBooks company/realm ID, used to identify which QuickBooks account is connected to your CFOLink organization

2.4 Information We Do Not Collect

We do not collect:

  • Social Security Numbers, government-issued ID numbers, or tax identification numbers
  • Bank account or payment card numbers directly (payment processing is handled by our third-party payment processor)
  • Biometric data

3. How We Use Your Information

We use the information we collect for the following purposes:

PurposeLegal Basis
To create and manage your accountPerformance of contract
To provide, operate, and improve the ServicePerformance of contract / Legitimate interest
To authenticate you and secure your accountPerformance of contract / Legitimate interest
To process your QuickBooks data and generate reportsPerformance of contract
To send you service-related communicationsPerformance of contract / Legitimate interest
To respond to your inquiries and support requestsLegitimate interest
To detect, prevent, and investigate fraud or security incidentsLegitimate interest / Legal obligation
To comply with applicable legal obligationsLegal obligation
To enforce our Terms of ServiceLegitimate interest

We do not use your data for:

  • Selling or renting your information to third parties
  • Serving third-party advertising
  • Training machine learning or AI models on your QuickBooks financial data

4. How We Share Your Information

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

4.1 Service Providers

We share information with trusted third-party vendors who assist us in operating the Service, including:

Provider TypePurpose
Cloud infrastructure (Railway, Cloudflare, Neon)Hosting, database, and content delivery
Payment processorSubscription billing (they receive payment card data directly — we do not)
Email service providerTransactional email delivery

These providers are contractually obligated to protect your information and use it only for the services they provide to us.

4.2 Intuit (QuickBooks)

When you connect your QuickBooks account, data flows between CFOLink and Intuit's servers via the Intuit API. Intuit's own privacy practices govern their handling of your data. We encourage you to review Intuit's Privacy Policy.

4.3 Legal Requirements

We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of CFOLink
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users or the public
  • Protect against legal liability

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred to the successor entity. We will notify you via email or prominent notice on the Service prior to your information being transferred and becoming subject to a different privacy policy.

4.5 With Your Consent

We may share your information with other parties when we have your explicit consent to do so.

5. Data Retention

We retain your information for as long as your account is active or as necessary to provide the Service.

Data TypeRetention Period
Account informationDuration of account + 30 days after deletion
QuickBooks OAuth tokensDeleted immediately upon QuickBooks disconnection or account deletion
Transient QuickBooks financial dataNot retained beyond the request lifecycle
Log and usage dataUp to 12 months on a rolling basis
Support communicationsUp to 3 years

After the applicable retention period, we will delete or anonymize your data. Some data may be retained longer if required by applicable law or for legitimate business purposes such as fraud prevention.

6. Data Security

We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These include:

  • Encryption in transit: All data transmitted between your browser and the Service is encrypted using TLS (HTTPS)
  • Encryption at rest: QuickBooks OAuth tokens are encrypted using industry-standard encryption before storage
  • Authentication: JWT-based authentication with short-lived tokens for all API access
  • Access controls: Role-based access controls limit internal access to your data to authorized personnel only
  • Multi-tenant isolation: Your data is logically isolated from other tenants in our database architecture

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, and we encourage you to use a strong, unique password and to report any suspected security issues to info@cfolink.ai immediately.

7. Cookies and Tracking Technologies

7.1 What We Use

CFOLink uses the following types of cookies and local storage:

TypePurposeCan You Opt Out?
Essential / Authentication cookiesMaintain your login session; required for the Service to functionNo — required for Service operation
Session storageTemporarily cache report data within a browser sessionNo — required for Service operation
Analytics cookies (if enabled)Understand how users interact with the ServiceYes — see below

7.2 Third-Party Analytics

If we use third-party analytics services (such as Google Analytics), those services may place their own cookies. We will update this section to identify any such services as they are added.

7.3 Managing Cookies

You may configure your browser to refuse cookies or to alert you when cookies are being set. Note that disabling essential cookies will prevent you from logging in or using the Service.

8. Geographic Scope and Data Transfers

The Service is intended for users located in the United States only. Our servers and infrastructure are operated within the United States. By using the Service, you consent to the processing and storage of your information in the United States.

If you are accessing the Service from outside the United States, please be aware that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. If you are located outside the United States, you should not use the Service.

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a person under 18, please contact us at info@cfolink.ai and we will promptly delete such information.

10. Your Rights and Choices

10.1 Access and Correction

You may access and update your account information at any time through your account settings within the Service. For information not accessible through your account settings, contact us at info@cfolink.ai.

10.2 Account Deletion

You may request deletion of your account and associated personal data by sending an email to info@cfolink.ai with the subject line "Account Deletion Request." We will process your request within a reasonable time and confirm when deletion is complete.

Upon deletion:

  • Your account information will be removed
  • Your QuickBooks OAuth tokens will be revoked and deleted
  • Transient financial data is not stored, so no further action is required for that data
  • Log data may be retained in anonymized form per our retention schedule

10.3 Opt-Out of Non-Essential Communications

You may opt out of non-essential marketing communications by following the unsubscribe link in any marketing email or by contacting us at info@cfolink.ai. Note that you cannot opt out of service-critical communications (e.g., security alerts, billing notices).

10.4 QuickBooks Disconnection

You may revoke CFOLink's access to your QuickBooks account at any time through the Service's settings or directly through your Intuit account. Upon disconnection, we will delete your stored OAuth tokens.

11. Third-Party Links and Services

The Service may contain links to third-party websites or services (e.g., Intuit/QuickBooks). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with our Service.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email to your registered address, or via a prominent notice within the Service

Your continued use of the Service after the effective date of the updated Privacy Policy constitutes your acceptance of the changes.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

CFOLink LLC
Email: info@cfolink.ai

We will respond to your inquiry within a reasonable time.


© 2026 CFOLink LLC  ·  Terms of Service  ·  Privacy Policy