
Last updated August 28, 2026
In short
We collect what we need to run your account and bill you: your name and email, the company names you attach to subscriptions, and your subscription history. Payment card details go directly to Stripe and never reach us.
We do not sell your information, we do not run advertising or analytics tracking, and because we do not connect to the software we resell, we cannot see what you keep inside it.
Fynbridge Tools is operated by The Corner Office CFO. This policy explains what personal information we collect through the Fynbridge Tools platform, why we collect it, who we share it with, and what you can ask us to do about it.
It covers the platform only. Software you buy through the Marketplace is operated by the vendor that makes it, and what you put into that software is governed by that vendor's privacy policy, not this one. See the Terms of Service for how that relationship works.
Information you give us. Your name and email address; a password, which we store only as a cryptographic hash and cannot read; your organization's name and time zone; what brought you to the platform, which you tell us at signup; and the company name you attach to each subscription.
Security information. If you use an authenticator app for two-factor authentication, we store its secret in encrypted form. If you use email codes, we store the one-time code until it expires.
Billing information. Your subscriptions, their status and billing periods, invoice amounts and dates, and identifiers linking your account to your records at our payment processor. Your billing address is collected at checkout by Stripe and held by Stripe, which uses it to calculate sales tax — we do not store it as part of your account, and nothing in the application reads or displays it.
Technical information. We keep a security and activity log of significant actions — signing in, changing a subscription, opening the billing portal — and that log records the IP address and browser user-agent the action came from. We also keep the notification messages our payment processor sends us, exactly as they arrive. Some of those messages include your name, email address and billing address, so although we do not record your address against your account, a copy of it does persist in that log.
Consent records. When you accepted our terms, and whether and when you opted in to or out of marketing email. We keep these even after a withdrawal, because the record is the proof that the choice was yours.
This section applies if you use QBO Extractor. It is separate from everything in section 2: that is information about you, held to run your account. This is information about your clients, suppliers, and employees, which passes through our systems only while a run is in progress.
How the connection works. You authorize us on Intuit's and Microsoft's own consent screens. We never see your password for either. We store the resulting access tokens in encrypted form so that scheduled runs can continue without asking you again, and you can revoke them at any time.
What we read. On each run we read records from the QuickBooks company you connected: the chart of accounts, customers, vendors, employees, items and price lists, and transactions — invoices, bills, payments, deposits, purchases, journal entries, estimates, sales receipts, credit memos, purchase orders, and time activities. These ordinarily contain personal information, including names, contact details, and amounts owed or paid.
What happens to it. It is held in a temporary working area on our server for the few minutes a run takes, converted into a spreadsheet, uploaded to the SharePoint location you chose, and then deleted. It is never written to our database, and we keep no copy once the run ends.
What we keep about a run. Which organization and user started it, the name of the QuickBooks company and the SharePoint folder, when it started and finished, whether it succeeded, and the name of and link to the file in your SharePoint. We also keep a technical log of each request we made to QuickBooks — which type of record was asked for, the response code, and how long it took — which is how we track usage against Intuit's limits. Neither record contains the accounting data itself.
When a run fails. We record why, show it to you, and send it to our error monitoring provider (see sections 7 and 8). What we record is a short technical summary — the type of failure and, where QuickBooks refused a request, the response code and which endpoint was called. It does not include the accounting records the run was reading.
For this data we act on your instructions and on your behalf. You remain responsible for it, for being entitled to extract it, and for who can reach the SharePoint location you send it to.
We do not sell personal information, and we do not trade or rent it.
We use cookies only to keep you signed in. They are first-party, strictly necessary for the service to work, and set with the `Secure`, `HttpOnly` and `SameSite` protections. There are no advertising or analytics cookies, which is why you are not asked to consent to any.
We share personal information only with service providers who process it on our behalf, under contract, and only for the purposes below. Every provider we use is listed here.
| Provider | What they do for us | Where |
|---|---|---|
| Stripe | Payments, subscriptions, invoices, sales-tax calculation | United States and global |
| Twilio SendGrid | Sending transactional email | United States |
| Sentry | Error and performance monitoring | United States |
| Hostinger | Server and database hosting | United States |
| Microsoft | Encrypted off-site database backups (OneDrive) | Microsoft 365 tenant region |
Our error monitoring is configured to include request details, which means an IP address and the identifier of the signed-in user can be attached to a report when something goes wrong. We use this to fix faults, not to profile anyone.
We may also disclose information where the law requires it, or to establish or defend a legal claim — including responding to a payment dispute you or your card issuer raises.
Our application servers and database are hosted in United States. Several of the providers above operate in the United States, so some personal information is stored or processed outside Canada.
While it is in another country it may be accessible to that country's courts and law enforcement under their laws. We use providers who commit contractually to protecting it to a comparable standard, but we cannot exempt them from those laws, and you should know that before deciding to use the service.
We keep account and subscription information for as long as you hold an account, and afterwards for as long as we need it to meet tax, accounting, and legal obligations — billing records in particular have to be retained for several years regardless of whether you remain a customer.
Security and activity logs are kept for a limited period for security investigation. Encrypted database backups are kept on a rolling schedule, so information deleted from the live system can persist in backups for about one month before ageing out.
No system is perfectly secure. If a breach occurs that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as the law requires.
Write to us at the address in section 13 and you may:
We will respond within 30 days. We may need to verify your identity first, so that nobody else can obtain your information by asking for it.
The service is for business use and is not directed at children. We do not knowingly collect information from anyone under 18.
If we change this policy in a way that materially affects you, we will tell you by email or in the application before it takes effect. The date at the top shows when it was last revised.
For any privacy question, or to exercise any of the rights above, contact our privacy officer:
The Corner Office CFO
14-3710 Eastgate Drive, Regina, SK, S4Z 1A5
support@fynbridge.com
© The Corner Office CFO