Privacy Policy for ARVIS Financial Connector
Effective September 2, 2026
ARS, Inc., an Oregon corporation (“ARS,” “we,” “us,” or “our”), operates ARVIS Financial Connector for authorized internal business users. This policy explains how the connector handles information associated with QuickBooks Online.
Information accessed
With authorization from an ARS QuickBooks administrator, the connector may access accounting information needed for reconciliation, accounts-receivable monitoring, project-cost and profitability analysis, margin reporting, and management reporting. Approved categories may include company connection information, customer and project identifiers and relationships, invoice totals and balances, due dates, payment-to-invoice relationships, credits, and project-assigned purchase or bill amounts.
Production QuickBooks access is not currently active.
How information is used
ARS uses approved QuickBooks information to operate internal accounting controls, reconcile records, monitor receivables, analyze project costs and margins, produce management reports, secure and troubleshoot the connector, respond to authorized requests, and comply with applicable obligations.
The connector does not process payments and does not provide functions that create, update, void, or delete QuickBooks accounting records.
Data minimization
The connector requests explicit approved fields and applies an additional projection boundary before calculation, storage, logging, or downstream handling. Unexpected identity or contact fields, banking information, tax and payroll information, free text, memos, descriptions, attachments, and other unapproved fields are discarded. They are not permitted in application logs or AI systems.
QuickBooks and ARVIS AI
No QuickBooks-related AI feature is authorized. No QuickBooks information is sent to an AI model or provider. The connector does not maintain QuickBooks-derived AI prompts or outputs.
Any future QuickBooks-related AI capability would require a separate security and privacy review, updated public disclosure, any required Intuit approval, and explicit authorization before implementation or activation.
Service providers and disclosure
ARS does not sell QuickBooks data and does not use it for advertising, advertising audiences, or commercial data enrichment.
The connector uses approved Google Cloud services for hosting, identity protection, OAuth security metadata, secret storage, application logging, build, and artifact management. Intuit provides QuickBooks Online and OAuth services. WordPress and SiteGround host the connector’s public information pages and are not permitted to receive QuickBooks data from the connector.
No AI provider is authorized to receive QuickBooks information.
ARS may disclose information to approved service providers operating under applicable confidentiality, security, and data-handling obligations, or when reasonably necessary to comply with law, protect rights and systems, investigate misuse, or respond to lawful process.
Credentials and security
The connector is designed to store OAuth credentials in Google Cloud Secret Manager, separate sandbox and production environments, restrict administrator routes through Google Identity-Aware Proxy and an application allowlist, use HTTPS, reject unsupported methods, apply sensitive-response cache and browser-security headers, and record fixed-schema security metadata rather than QuickBooks payloads.
ARS limits access to authorized personnel with a business need. No safeguard or transmission method can guarantee absolute security.
Retention
- QuickBooks API cache: ephemeral only and retained for no more than 15 minutes. It is not placed in persistent backups.
- Connector-generated report results: not retained by the connector after the active response or session completes. A report deliberately exported by an authorized user is governed by the existing ARS accounting and records policy after export.
- QuickBooks-derived AI prompts and outputs: not applicable because QuickBooks-to-AI processing is not authorized.
- Application security logs: fixed-schema metadata only, retained for 90 days, excluding QuickBooks payloads, credentials, tokens, authorization codes, free text, attachments, and complete accounting records.
- QuickBooks-derived backups: none under the approved design. Any future QuickBooks-derived backup requires a new written retention decision and updated disclosure before activation.
- OAuth credentials: retained only while authorization remains active. Following a validated disconnect, retrieval stops and connector-controlled active access-token, refresh-token, and connected-company identifier secret versions are revoked or destroyed within one business day.
- Security and incident evidence: metadata-only evidence may be retained for 12 months after an incident is closed.
If a longer legal, accounting, insurance, employment, litigation, or security hold is required, it must be written, case-specific, limited to the minimum necessary information, approved by the President and privacy owner, reviewed at least every 90 days, and released promptly when no longer required. A hold will not be used to retain OAuth credentials that can safely be revoked or destroyed.
Disconnection and deletion
An authorized QuickBooks administrator may remove the application’s authorization through QuickBooks Online or request assistance from support@restoringvancouver.com. ARS independently validates the requester through an authenticated corporate identity and administrator confirmation. ARS will not request a password, token, secret, authorization code, QuickBooks export, or credential screenshot.
After validation, ARS will acknowledge the request within one business day, stop retrieval and revoke or destroy active credentials within one business day, and complete other eligible connector deletion and send a completion notice within five business days. If a documented hold prevents deletion, the notice will identify the retained category, reason, approving role, review date, and eventual deletion trigger without exposing sensitive information.
Disconnecting the connector does not delete or change accounting records in QuickBooks Online.
Privacy requests and choices
Subject to applicable law and ARS’s obligations, an individual may request access to, correction of, or deletion of personal information handled through the connector. ARS may verify the requester’s identity and authority before acting and may retain or deny access to information where permitted or required by law. Requests may be sent to privacy@restoringvancouver.com.
QuickBooks administrators may withdraw the connector’s authorization through QuickBooks Online. Authorized users may also stop using the connector and request assistance through the support address above.
Incidents
ARS investigates suspected unauthorized access, incorrect-company connections, credential exposure, and improper disclosure under its incident process. Any legally required notice will be provided in accordance with applicable requirements. Suspected incidents should be reported to support@restoringvancouver.com without including credentials or QuickBooks exports in the message.
Changes to this policy
ARS may update this policy when the connector, service providers, operating controls, or applicable requirements change. The effective date identifies the current version. Material changes require approval, an updated effective date, and appropriate notice.
Contact
ARS, Inc.
9808 NE 126th Ave, Suite C
Vancouver, WA 98682
United States
privacy@restoringvancouver.com
