Last updated 24 August 2026
Account information (name, email address) that you provide when signing up, and business accounting records imported from your connected QuickBooks Online company: customer names and contact details, credit limits, payment terms, invoices, payments and balances.
Solely to operate the workspace: calculating credit exposure and aging, showing collections activity and sending reminders you configure. We do not sell personal data and we do not use your accounting data for advertising or to train models.
Authorisation uses Intuit's OAuth 2.0 flow with the accounting scope. Access and refresh tokens are encrypted at rest with AES-256-GCM and are only ever used server-side; they are never exposed to the browser. Receiva reads data only and does not create or modify records in your QuickBooks company.
Data is stored in a managed PostgreSQL database with row level security so each workspace can only read its own records. Access is over TLS, and administrative credentials are held in an encrypted secret store.
Data is kept while your account is active. Disconnecting QuickBooks destroys the stored tokens immediately; closing your account deletes workspace data within 30 days. You can request an export or deletion at any time.
We use infrastructure and database hosting providers to run the service, and Intuit as the source of accounting data. Each processes data only to deliver the service.
You may request access to, correction of, or deletion of your personal data, and you may withdraw QuickBooks authorisation at any time from workspace settings.
Privacy requests can be sent to the workspace owner's registered contact address.