Simple Accounting
Terms & EULAEspañolClient portal
On this page
  1. Scope and relationship
  2. Information we collect
  3. How we use information
  4. QuickBooks and connected services
  5. Automated and AI-assisted features
  6. How we disclose information
  7. Retention and deletion
  8. Security and access controls
  9. Your choices and rights
  10. Children, location, and transfers
  11. Changes and contact
Trust & data stewardship

Privacy Policy

How Simple Accounting handles business, financial, payroll, and connected-service information in Simple Accounting OS.

EffectiveSeptember 11, 2026
01

Scope and relationship

This Privacy Policy explains how Simple Accounting PR ("Simple Accounting," "we," "us," or "our") handles information through Simple Accounting OS (the "Platform"), our website, and related accounting support services. It applies to business clients, their authorized users, employees whose information is provided by a client, and Simple Accounting team members who use the Platform.

A separate engagement letter or services agreement may govern professional accounting, payroll, tax, or advisory services. If such an agreement includes additional privacy obligations, those obligations also apply.

02

Information we collect

We collect information that you provide and information generated while you use the Platform. We collect information from a connected service only when its integration is operational, enabled for the client, and authorized by an authorized user.

  • Account and profile information, including name, business email, role, company assignment, authentication identifiers, and business contact or company-profile information entered in the Platform.
  • Portal records, including module and pricing configuration, tasks and requests, compliance items, notifications, uploaded-document metadata, approvals, and audit history.
  • Documents and communications submitted through the Platform, including bank statements, ACH reports, receipts or other files, request responses, attachments, and notes supplied for review. Email replies are collected only if an email-response feature is later made available and enabled.
  • For the current QuickBooks connection, the QuickBooks company identifier, company name and country returned by Intuit, encrypted OAuth credentials and expiration information, connection state, verification results, and technical error context. Additional QuickBooks data or information from banking, payroll, timekeeping, Google Drive, Stripe, or other providers is collected only if the corresponding integration is made operational, enabled, and authorized.
  • Operational and security information, including module settings, approval history, audit events, connection health, service errors, and records used to prevent duplicate requests.
  • For certain retryable form submissions, the browser tab temporarily stores a request key and the submitted action details in sessionStorage. This data is cleared after a successful request or otherwise when the browser tab or session ends, and is not used for advertising.
03

How we use information

  • Operate currently available portal functions, including accounts, company profiles, module configuration, document uploads, tasks and requests, compliance tracking, approvals, notifications, connection status, and audit records.
  • Provide financial dashboards, cash-flow analysis, payroll summaries, automated document processing, connected storage, billing, payment, or other services only when the corresponding capability is operational and enabled for the client.
  • Connect, verify, maintain, and troubleshoot services that a client has expressly authorized.
  • When the relevant capability is operational and enabled, prepare bookkeeping drafts, classifications, reconciliations, alerts, forecasts, and supporting work for review by authorized users and Simple Accounting personnel.
  • Authenticate users, enforce company-level permissions, maintain audit trails, detect abuse, and protect the Platform and client data.
  • Communicate through the Platform about requests, service updates, security events, and support matters, and by email only when the applicable email function is enabled.
  • Comply with legal, regulatory, tax, accounting, and professional obligations and enforce our agreements.
04

QuickBooks and connected services

When an authorized user connects a QuickBooks Online company, Intuit presents the authorization screen and the user selects the company to connect. The current integration receives the company identifier and uses the authorized connection to retrieve the company name and country for confirmation and connection verification. We store the OAuth access and refresh credentials and their expiration information in encrypted form. Additional QuickBooks accounting data is requested only if the corresponding function is made operational and enabled, and only within the access authorized through Intuit.

If IDEAL is enabled, no certification search starts at sign-in. An authorized user must choose the Certifications module and press the retrieval button for the active client. Certifications returned with that company’s authorization are routed to that client’s Google Drive folder named “certificaciones actualizadas.” The complete employer identification number is not retained by the Platform.

To disconnect the current QuickBooks connection, a user may revoke access through Intuit or contact Simple Accounting for assistance. An in-Platform disconnect option applies only when that control is expressly shown as available. Revocation through Intuit prevents future use of the revoked authorization; company metadata, audit records, or information already incorporated into professional work may remain subject to the retention terms below.

05

Automated and AI-assisted features

When Simple Intelligence is enabled, an authorized user’s question and a server-filtered selection of information that user may already view for the active company—such as document metadata, requests, and due dates—are sent to the OpenAI API to prepare an answer. The answer is stored in that user’s company-specific chat. Prompts do not authorize the system to take accounting, filing, payment, or other external action.

AI-assisted answers may be incomplete or incorrect and require human review, especially for accounting, tax, legal, payroll, payment, or compliance matters. The Platform instructs Simple Intelligence not to use another company’s context and does not place question or answer text in the audit event itself. OpenAI handles API data under its applicable business terms and privacy commitments. The Platform contains no advertising analytics and does not use Client Data for targeted advertising.

06

How we disclose information

We disclose information only as needed to provide authorized services, operate securely, comply with law, or complete a transaction directed by the client.

  • The Platform’s current technical service providers, including OpenAI for hosted access, sign-in, and enabled Simple Intelligence responses, and Cloudflare for application infrastructure and data or file storage.
  • Intuit when an authorized user connects QuickBooks. Google Drive, Stripe, banking, payroll, timekeeping, email, AI, or other providers receive Client Data only if the corresponding integration is later made operational, enabled, and authorized.
  • Authorized Simple Accounting platform or firm administrators and personnel assigned to support the client, according to their roles and the applicable engagement.
  • Government agencies, courts, or other parties when required by law or expressly directed by an authorized client representative.
07

Retention and deletion

We retain information for as long as reasonably necessary to provide the Platform and contracted services, maintain security and audit records, resolve disputes, and satisfy tax, accounting, professional, and legal obligations. Retention periods vary by record type and engagement.

Authorized users may request access, correction, export, or deletion by contacting us. The current Platform does not provide self-service data export or account deletion. We evaluate requests according to the client relationship, the requester’s authority, provider capabilities, and applicable retention requirements. Revoking a provider connection does not automatically delete metadata, audit records, or professional records already created from the data.

08

Security and access controls

Current safeguards include encrypted network transport, encryption at rest for QuickBooks OAuth credentials, company-aware and role-aware authorization, approval controls, and audit records. Authorized platform and firm administrators may access the client companies they are permitted to administer; client users are limited to their assigned company. Connection status is displayed and can be verified on demand, but not every provider has automated continuous monitoring.

No system can guarantee absolute security. Users must protect their sign-in methods, use authorized devices, promptly report suspected access, and keep company assignments and contact information current.

09

Your choices and rights

  • Request activation, deactivation, or pricing changes for optional modules. Authorized Simple Accounting administrators configure entitlements according to the applicable engagement; client users do not necessarily have self-service entitlement controls.
  • Revoke access through the connected provider or ask Simple Accounting to assist. In-Platform disconnection is available only where a disconnect control is expressly displayed.
  • Request access to, correction, export, or deletion of information through the contact below, subject to authority and applicable retention requirements.
  • Contact us with a privacy complaint or question. We may need to verify identity and company authority before acting on a request.
10

Children, location, and transfers

The Platform is a business service and is not directed to children under 13. Clients must have authority to provide employee information used for legitimate business, payroll, or compliance purposes.

Simple Accounting PR operates from San Juan, Puerto Rico. The Platform’s current hosting, authentication, storage, and connected-service providers describe their own processing locations and practices in their privacy terms.

11

Changes and contact

We may update this Policy as the Platform, providers, or legal requirements change. We will post the updated version with a new effective date. Any additional notice required by law or a signed agreement will be provided through an available contact channel.

Questions, requests, or complaints may be sent to the contact below. Please do not email bank passwords, full payment-card numbers, Social Security numbers, or provider secrets.

Privacy contactjulio.lopez@simpleaccountingpr.com

Simple Accounting PR · San Juan, Puerto Rico