Privacy Policy Connector Internal

Privacy Policy

Eastside Microfarms QuickBooks Sheets Connector
Effective date: September 20, 2026

This policy describes how Eastside Microfarms, LLC, doing business as Max Power Microgreens, LLC ("we" or "us"), handles information in its internal QuickBooks Online to Google Sheets connector (the "Connector"). The Connector supports restaurant order and payment reporting for our business. This policy applies to the Connector, not to our other websites or services.

Information the Connector handles

After an authorized QuickBooks Online company is connected, the Connector requests Customer, Recurring Transaction, Invoice, and Payment records from the QuickBooks Online Accounting API. The responses may contain more fields than the Connector writes to the Sheet. The Connector writes selected fields, including:

  • Restaurant customer identifiers, names, company names, active status, and balances.
  • Recurring invoice template identifiers, schedules, item descriptions, products, quantities, prices, and amounts. These templates are used as expected order or PAR baselines.
  • Invoice numbers, dates, due dates, totals, open balances, products, quantities, prices, and line amounts.
  • Payment identifiers, dates, amounts, unapplied amounts, and links to invoices when available.
  • Derived order comparisons, possible skipped orders, payment timing, past-due status, and synchronization results or errors.

The Connector also handles the QuickBooks company identifier and OAuth credentials needed to maintain the connection. Its client secret and refresh token are stored in Google Apps Script Script Properties, not in worksheet cells. Access to the Sheet and the Apps Script project is controlled through the applicable Google account permissions.

How we use the information

We use this information to refresh the reporting Sheet approximately once per day; compare recurring invoice templates with actual invoices by restaurant, product, and quantity; review payment timing and balances; and investigate sync errors. A single invoice difference does not automatically change a restaurant's expected PAR. Possible skipped orders and payment timing are review indicators and may require confirmation against QuickBooks.

Where information is kept and who can access it

The selected business records and derived results are kept in a Google Sheet. OAuth credentials are kept in the associated Google Apps Script project. Intuit supplies the QuickBooks data through its API, and Google provides the Sheet and Apps Script services. We limit access to the business owner and authorized internal staff. Anyone granted access to the Google Sheet or script may be able to view data according to their Google permissions.

Retention and deletion

Each successful refresh replaces the current customer, template, invoice, payment, and summary tables. The Connector also retains captured template line history, prior expected-order snapshots, and an append-only sync log in the Sheet. These records remain until an authorized operator deletes them or a retention process is established. [Confirm whether the business will adopt a specific retention period.] Revoking the QuickBooks authorization or stopping the daily trigger stops future access or refreshes, but it does not by itself erase records already stored in Google Sheets. An authorized operator must separately remove stored records and credentials when they are no longer needed.

Security

We limit operation of the Connector to authorized accounts and rely on access controls provided by Intuit and Google. The Connector's QuickBooks business-record requests use GET operations; it does not include code to create, change, void, or delete QuickBooks accounting records. The QuickBooks Online Accounting authorization scope itself is broader than read-only, so we restrict the Connector's code and access to its credentials.

Questions and changes

For questions about the Connector or its stored data, contact sergey@eastsidemicrofarms.com. We may update this policy when the Connector or our practices change. The effective date above will identify the current version.