← Receiva

Privacy Policy

Last updated 24 August 2026

What we collect

Account information (name, email address) that you provide when signing up, and business accounting records imported from your connected QuickBooks Online company: customer names and contact details, credit limits, payment terms, invoices, payments and balances.

Why we use it

Solely to operate the workspace: calculating credit exposure and aging, showing collections activity and sending reminders you configure. We do not sell personal data and we do not use your accounting data for advertising or to train models.

QuickBooks Online access

Authorisation uses Intuit's OAuth 2.0 flow with the accounting scope. Access and refresh tokens are encrypted at rest with AES-256-GCM and are only ever used server-side; they are never exposed to the browser. Receiva reads data only and does not create or modify records in your QuickBooks company.

Storage and security

Data is stored in a managed PostgreSQL database with row level security so each workspace can only read its own records. Access is over TLS, and administrative credentials are held in an encrypted secret store.

Retention and deletion

Data is kept while your account is active. Disconnecting QuickBooks destroys the stored tokens immediately; closing your account deletes workspace data within 30 days. You can request an export or deletion at any time.

Sub-processors

We use infrastructure and database hosting providers to run the service, and Intuit as the source of accounting data. Each processes data only to deliver the service.

Your rights

You may request access to, correction of, or deletion of your personal data, and you may withdraw QuickBooks authorisation at any time from workspace settings.

Contact

Privacy requests can be sent to the workspace owner's registered contact address.