Effective August 1, 2026

Privacy Policy

This policy describes the CoS Receipt Intake integration operated by ThirtyNine Capital.

Data we process

We process receipt images and PDFs; receipt metadata such as merchant, transaction date, amount, currency, card or account last four digits, category, and business purpose; source-message identifiers; QuickBooks account references and expense records; and OAuth tokens needed to access authorized Microsoft 365 and QuickBooks accounts.

Purpose and authority

Data is processed only at the direction of the account owner to capture receipts, identify duplicates, prepare or create initial QuickBooks Online expense entries, attach source receipts, maintain an audit trail, and diagnose delivery or posting failures. The integration does not reconcile the ledger, process payments, sell data, build advertising profiles, or use financial data for unrelated purposes.

Service providers

Authorized data may pass through Microsoft 365, Meta/WhatsApp, Intuit QuickBooks Online, and infrastructure providers used to operate the private workflow. If the account owner enables cloud extraction, a receipt may be sent to Anthropic solely to extract structured receipt fields. Public policy pages hosted by Cloudflare contain no receipt or accounting data.

Storage, access, and security

Runtime records, receipt objects, and credentials are kept outside source control on access-restricted infrastructure. Credentials are stored in permission-restricted files and transmitted only over encrypted connections. Access is limited to the account owner and specifically authorized operators. Logs minimize full financial identifiers and use account last-four digits where practical.

Retention and deletion

Receipt records and audit events are retained while needed for bookkeeping, audit, security, or legal obligations. On QuickBooks disconnect, OAuth tokens are revoked or deleted promptly, automated access stops, and cached data derived solely from Intuit is deleted within 30 days unless retention is legally required. Source receipts independently retained as accounting records are handled under the owner’s bookkeeping retention policy. Requests for access or deletion may be sent to the contact below.

Sharing

We do not sell personal information or QuickBooks data. We disclose data only to the service providers above as needed to run the workflow, to authorized bookkeeping or professional advisers at the owner’s direction, or when legally required.

Changes

Material changes will be posted here with a new effective date.