Privacy policy
Last updated 2026-09-05. Applies to Fuel The Fire Connect, the QuickBooks Online connection service operated by Fuel The Fire LLC at connect.fpfuel.com.
Fuel The Fire LLC is a Hawaiʻi limited liability company that builds custom software for small firms. This policy explains what we do with the QuickBooks Online data your firm authorizes us to access, and with the small amount of information this website itself collects. It is written to be read, not to be survived.
Who is responsible
Fuel The Fire LLC, Honolulu, Hawaiʻi, United States, is the controller of the data described here. Contact: contact@fuelthefirellc.com. Where we process QuickBooks data on your firm's instructions as part of a build we delivered to you, we act as your processor and your own agreement with us governs.
What we access from QuickBooks Online
We request exactly one OAuth scope,
com.intuit.quickbooks.accounting, against the single company you
select on Intuit's consent screen. Within that scope, the application built for
your firm reads only the records it needs to do its job. Depending on your
build, that can include:
| Category | Examples |
|---|---|
| Company profile | company name, legal address, fiscal year start, currency |
| Chart of accounts | accounts, classes, departments, tax codes |
| Names | customers, vendors, employees as they appear on transactions |
| Transactions | invoices, estimates, bills, expenses, payments, credit memos, journal entries, time activities |
| Items | products, services, and their rates |
| Reports | profit and loss, balance sheet, aging, and similar standard QuickBooks reports |
We do not request the QuickBooks Payroll, Payments, or Time scopes, and we do not receive your Intuit sign-in credentials at any point. Authentication happens entirely on Intuit's servers.
Why we access it
- To run the software you hired us to build — reporting, reconciliation, dashboards, document generation, or whatever your specific engagement covers.
- To support and debug it when something breaks, using the least data that answers the question.
- To keep the connection alive, which means storing and periodically refreshing OAuth tokens.
That is the complete list. We do not use your accounting data to train machine-learning models, to build profiles, to benchmark you against other clients, or for advertising of any kind.
What this website stores
- Invite codes — only a SHA-256 hash, never the code itself, plus a label so we know who it was issued to.
- OAuth tokens — the access token and refresh token for your company, each encrypted at rest with authenticated symmetric encryption (Fernet, AES-128-CBC with an HMAC-SHA256 tag). The encryption key is derived at start-up from a passphrase held in a secrets vault and never written to this server's disk in plaintext.
- Your QuickBooks company ID (the "realm ID") and the token expiry timestamps.
- Webhook notifications from Intuit, which tell us that a record changed. These carry record IDs and types, not record contents.
- Server logs — request method, path, timestamp, and response status. We do not log tokens, invite codes, authorization codes, or our client secret, and the application is written so that those values cannot be echoed back in a page.
This site sets no cookies, runs no analytics, embeds no third-party JavaScript, fonts, or stylesheets, and has no trackers or advertising pixels. Nothing on these pages is loaded from another company's server.
Who we share it with
Nobody. We do not sell, rent, trade, or otherwise disclose your QuickBooks data or personal information to third parties, and we never have. We do not share it for cross-context behavioural advertising. The only parties in the chain are:
- Intuit, whose API is the source of the data and who operates the consent and token infrastructure.
- Our hosting provider, DigitalOcean, which runs the server this application sits on.
We disclose data otherwise only where a valid legal process compels it, and we will tell you unless we are legally barred from doing so.
How long we keep it
- OAuth tokens: for as long as the connection is live. When you disconnect — from QuickBooks or by asking us — we revoke the tokens with Intuit and delete the encrypted material.
- Company ID and connection record: retained after disconnection only as an inactive record that the connection existed, for up to 24 months, so we can answer audit questions. It contains no accounting data.
- Webhook events: 90 days.
- Accounting data cached inside the application we built for you: governed by that project's own retention terms, which we set with you in writing. Absent a different agreement, we purge on request within 30 days and on the termination of the engagement.
- Server logs: 30 days.
Deletion on disconnect
Disconnection is the deletion trigger, and it works from either side. When you disconnect the application in QuickBooks Online, Intuit invalidates our tokens immediately. On our side we then revoke and delete the stored token material for that company. If you want the derived data gone too, email us and say so — we will confirm deletion in writing within 30 days.
Security
- All traffic is served over TLS. There is no plaintext endpoint.
- Tokens are encrypted at rest; the encryption key is held in a secrets vault and injected at process start, never written to disk.
- Connections are invite-only and each invite code works exactly once.
- Every webhook is verified against Intuit's HMAC-SHA256 signature before it is stored; anything unsigned or altered is refused.
- Access to the server is limited to Fuel The Fire LLC personnel who need it.
No system is perfect. If we discover a breach affecting your data we will notify you without undue delay and, where the law sets a clock, within it.
Your rights
Wherever you are, you can ask us to tell you what we hold about you, to give you a copy, to correct it, or to delete it. Write to contact@fuelthefirellc.com. We answer within 30 days and we do not charge for it.
California (CCPA / CPRA)
California residents have the right to know what personal information we collect and why, to request its deletion, to request correction, and to opt out of sale or sharing. We do not sell or share personal information, and we have not in the preceding twelve months. We do not use or disclose sensitive personal information beyond the purposes described above. We will not discriminate against you for exercising any of these rights. You may use an authorized agent; we will ask for proof of authorization.
Europe and the United Kingdom (GDPR / UK GDPR)
Our lawful basis is contract — processing necessary to deliver the software your firm engaged us to build — and, for security logging, our legitimate interest in keeping the service safe. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where consent is the basis. Withdrawing is as simple as disconnecting in QuickBooks. You may lodge a complaint with your supervisory authority. Data is processed in the United States; where we receive personal data from the EEA or UK we rely on the Standard Contractual Clauses.
Canada (PIPEDA)
We collect, use, and disclose personal information only for the purposes identified above and with your knowledge and consent, we limit collection to what those purposes require, and we keep it accurate and safeguarded. You may challenge our compliance by writing to us at the address below; unresolved complaints may be taken to the Office of the Privacy Commissioner of Canada.
Children
This is a business tool. It is not directed at anyone under 16 and we do not knowingly collect information from children.
Changes
If we change this policy we update the date at the top and, for anything material, email the contact on every live connection before it takes effect.
Contact
Fuel The Fire LLC
Honolulu, Hawaiʻi, United States
contact@fuelthefirellc.com
https://fpfuel.com
Ask and we will provide our full postal address for a formal written request.