Privacy Policy

Last updated: August 24, 2026

Beta Program Notice

BridgeBooks is currently in a private beta program.

  • We are not SOC 2, HIPAA, PCI-DSS, or ISO 27001 certified. Do not upload data requiring those certifications.
  • The beta service is provided without compensation, warranty, or SLA. See our Terms of Service, Section 5.
  • Deletion and data-export requests are handled within thirty (30) days.

1. Who We Are

BridgeBooks LLC ("BridgeBooks," "we," "us") is a B2B tool that helps accounting firms import bank, credit-card, and Venmo statements into QuickBooks Online. This policy describes what we collect, how we use it, who we share it with, and your choices.

Firms that upload statements on behalf of their clients are the controllers of that data; BridgeBooks acts as their processor and only handles the data on their behalf.

2. What We Collect

  • Account info — email, name, password (stored as a one-way hash by our auth provider), 2FA codes.
  • Firm info — firm name, team-member roles, invitation history.
  • Statement data — PDF/CSV statements you upload and the transactions extracted from them (date, amount, description, vendor, account, balance).
  • QuickBooks connection data — OAuth tokens (encrypted at rest), realm ID, and the chart of accounts / vendors / bank list we read from your QBO file to power extraction and push.
  • Device + usage basics — IP address, browser/OS, and which pages you visit. Used for security, debugging, and product-usage analytics.

3. How We Use It

To run the service — extract transactions, push approved rows to your QBO file, authenticate you, send transactional emails (statement-ready notices, invitations, password resets), maintain audit logs, and prevent abuse. That's it — we don't use your firm's or your clients' financial data for anything else.

4. Who We Share It With

We do not sell or rent personal information. We use a small set of vetted service providers ("subprocessors") strictly to operate the service:

  • A US-based cloud infrastructure provider for authentication, database, file storage, and edge compute
  • An email delivery provider for transactional email
  • A web hosting + edge network provider for the app and marketing site
  • A statement-extraction pipeline operated on BridgeBooks-controlled infrastructure
  • Intuit / QuickBooks Online — destination for transactions you explicitly push (the whole point of the product)

Each subprocessor is bound by contract to protect your data and process it only on our instructions. A current list of specific subprocessors is available on written request to the contact address below.

5. Data Retention

Statements, extracted transactions, and QBO connection data are retained while your account is active. Audit logs and invitation history are kept indefinitely as a compliance record. You can request earlier deletion of any of the above by emailing the address in Section 8; we'll comply within thirty (30) days (except where retention is required by law).

6. Your Rights

You can request access to, correction of, deletion of, or a portable export of your personal data by emailing us. We'll respond within 30 days. California residents (CCPA) and EU/UK residents (GDPR) have additional statutory rights that we honor by the same process.

7. Security & Cookies

TLS everywhere in transit; encrypted at rest at the database and storage layer; row-level access controls so a firm can only ever see its own data; OAuth with CSRF nonce for the QuickBooks connection; optional 2FA via email OTP. No security program is perfect — email us if you find a vulnerability.

We use essential cookies + localStorage entries to keep you signed in and remember basic preferences (active firm, sidebar state, trusted device for 2FA). The marketing site also uses privacy-friendly analytics (page views, Core Web Vitals). No advertising cookies.

8. Contact

For anything privacy-related — questions, corrections, exports, deletions, security reports — email hello@bridgebooks.app. BridgeBooks is operated by BridgeBooks LLC, Connecticut, USA.

9. Changes

We'll update the "Last updated" date above whenever this policy changes. Material changes will also trigger an in-app re-acceptance prompt before you can continue using BridgeBooks.