Privacy Policy
FinAccrual is a product of Aveera LLC (“Aveera,” “we,” “us”), an Ohio limited liability company. This policy describes what information the FinAccrual service — our Microsoft Excel add-in, the FinAccrual customer portal, and the supporting cloud services (together, the “Service”) — collects, how we use it, and the choices you have.
1. Information we collect
Account information
- Your name and email address, provided when you create a FinAccrual account. Sign-in is operated through Microsoft Entra External ID; we never see or store your password.
Accounting-system connection data
- When the workspace owner connects a QuickBooks Desktop company file, we record the company file’s identifier and display name, the workspace it belongs to, and which users of that workspace may post to it. There is no authorization token: the connection between Excel and QuickBooks is made locally on your computer under QuickBooks’ own permission dialog, and our servers never communicate with Intuit. FinAccrual’s servers prepare each QuickBooks request; Excel executes it locally through the QuickBooks Desktop SDK and returns QuickBooks’ reply to our servers to be read. The owner can disconnect a file from the customer portal at any time.
- Reference data stays with you. Your chart of accounts and class list live in your own Excel file and, for the desktop product, in an encrypted cache on your own computer (readable only by your Windows user) so new workbooks load quickly. FinAccrual’s servers prepare each QuickBooks request; Excel executes it locally through the QuickBooks Desktop SDK and returns QuickBooks’ reply to our servers to be read. When you sync, that reply is the full list of accounts and classes; our servers parse it, hand it straight back to your workbook, and do not retain it. When a run validates or posts, the workbook sends the records that run references, which are likewise not retained after the request completes. Customer, vendor and employee names are never stored by FinAccrual anywhere — not in our cloud, not on disk; they are checked live in QuickBooks only for the names a run is about to use.
- No QuickBooks Desktop credentials. For the desktop product, FinAccrual holds no password or credential to your QuickBooks company file. The connection between Excel and QuickBooks is made locally on your computer, under QuickBooks’ own permission dialog.
Journal and posting records
This is the part customers ask about most, so we are specific. When you post an entry, we retain only what is needed to prevent duplicate postings and to show you an audit trail:
- What we store: the company identifier, the document number, the identifier of the journal created in your accounting system, the posting period, the posting status and timestamps, the outcome of posting attempts, and a one-way hash of the entry's content used to detect a repeat post. A hash cannot be reversed into the underlying values.
- What we do NOT store: journal amounts, debit and credit values, account balances, account names or mappings, line-item descriptions, memos, or any other financial content of your entries. Those exist in your Excel workbook and in your accounting system — not in our database.
Billing information
- Subscription plan, status, and billing dates. Payments are processed by Stripe; card details are entered directly with Stripe and never reach our servers. We store only the Stripe customer and subscription identifiers needed to manage your plan.
Technical and usage data
- Standard service logs (timestamps, request status, diagnostic identifiers) used for security, reliability, and support.
2. How we use information
- To provide the Service: generating schedules and journal entries and, on your explicit instruction, posting them to your accounting system.
- To secure the Service: authentication, tenant isolation (your data is only visible to your own workspace), fraud and abuse prevention.
- To support you: responding to questions and investigating issues you report.
- To improve the reliability, performance, and security of the Service: aggregate, de-identified operational metrics.
We use data read from your QuickBooks Desktop company file solely to provide the Service — validating and posting the journals you ask us to post. FinAccrual’s servers prepare each QuickBooks request; Excel executes it locally through the QuickBooks Desktop SDK and returns QuickBooks’ reply to our servers to be read. Replies, including the full account and class lists returned by a sync, pass through our servers and are not retained. We do not sell it or use it for advertising.
3. Where your data lives, and how it is protected
The Service is hosted on Microsoft Azure in data centers located in the United States (Central US region).
Controls in place include: HTTPS/TLS in transit (TLS 1.2 or later), encryption of authorization tokens before storage, secrets held in a managed key vault and accessed via managed identity, per-workspace data isolation, endpoints that fail closed when authentication cannot be verified, least-privilege access to production systems, platform-managed backups, and monitoring with alerting on elevated error rates. Our Security page describes these in more detail.
4. International data transfers
FinAccrual is operated from the United States and your information is processed there. If you access the Service from outside the United States — including from the United Kingdom, the European Economic Area, or Switzerland — your information will be transferred to and processed in the United States, where we and our service providers operate.
Our infrastructure providers (including Microsoft Azure and Stripe) commit to recognised transfer safeguards, such as the European Commission's Standard Contractual Clauses, under the data protection terms of their agreements with us. If your organisation requires a data processing agreement with us directly, or documentation of specific transfer safeguards, please contact us and we will tell you plainly what we can provide.
5. Service providers (subprocessors)
- Microsoft Azure — cloud hosting, database, and key management.
- Microsoft Entra External ID — customer sign-in and identity.
- Intuit (QuickBooks Desktop) — the accounting software the add-in posts to. It runs on your own computer and your use of it is governed by your agreement with Intuit; Intuit is not a subprocessor of ours, because our servers never communicate with Intuit.
- Stripe — subscription billing and payment processing. Card details are collected by Stripe directly and are never transmitted to or stored by us.
- Google Workspace — our business email for support correspondence.
6. Data retention and deletion
- Company-file connection records (file identifier and name, the workspace it belongs to, who may post to it, and the connection status) are retained while the file is connected. When the workspace owner disconnects a file from the customer portal, the record is marked disconnected and kept, together with its posting history, so your audit trail stays intact and the owner can reconnect the file later; the Service refuses to post to a disconnected file. Nothing is deleted on disconnect. Master data read during a sync is not retained at all (section 1). Connection records are purged when your account is deleted.
- Posting references and audit records are retained while your account is active, so your history and audit trail remain intact. (As set out in section 1, these contain no financial content.)
- To request deletion, email support@finaccrual.com from the address on your account. We verify the request, then delete your account identity, connection records, posting references, and audit entries. We action verified requests within 30 days and confirm when complete, except where retention is required for legal, tax, or audit obligations.
- Journal entries already posted into your accounting system remain there — they are your records, held by your accounting provider, and are not ours to delete.
7. Your rights and choices
You may request access to, correction of, or deletion of your personal information at any time using the contact below. You may disconnect your accounting platform at any time from within the add-in.
8. Legal bases for processing (UK/EU visitors)
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you have subscribed to: generating schedules, posting entries on your instruction, and maintaining your posting history.
- Legitimate interests — to keep the Service secure and reliable (authentication, abuse prevention, diagnostics, aggregate operational metrics), balanced against your rights.
- Consent — where the workspace owner explicitly connects a company file and where you allow FinAccrual in QuickBooks’ permission dialog. You may withdraw it at any time by disconnecting the file in the portal or removing FinAccrual from QuickBooks’ integrated applications.
- Legal obligation — where we must retain records to meet tax, accounting, or other legal requirements.
You may request access to, correction of, deletion of, or restriction of processing of your personal information, and object to processing based on legitimate interests. Where applicable, you may also request a portable copy of your personal information in a structured, commonly used, machine-readable format.
Where we act as a processor for accounting data you direct us to handle, you remain the controller of that data. You may lodge a complaint with your local supervisory authority.
9. California privacy rights
If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion, to request correction, and not to be discriminated against for exercising those rights. Section 1 describes the categories we collect (identifiers such as name and email, commercial information such as subscription status, and internet/technical activity such as service logs).
We do not sell or share personal information as those terms are defined under California law, and we have not done so in the preceding twelve months. To exercise any right, email support@finaccrual.com; you may use an authorized agent.
10. Cookies and similar technologies
The Service uses only what is necessary to operate; we run no advertising or cross-site tracking.
- Strictly necessary — sign-in session and authentication state, security and anti-abuse protections. These cannot be switched off without breaking sign-in.
- Functional — remembering your interface preferences within the add-in and portal.
- Analytics — we use server-side diagnostics only. We do not deploy third-party analytics or advertising cookies in the Service.
- Marketing — none.
11. Security incidents
We maintain monitoring and alerting intended to detect problems promptly. If a personal-data breach affecting your information occurs, we will investigate, take steps to contain and remediate it, and notify affected customers and any applicable regulators where we are required to do so by law, without undue delay and within the timeframes the applicable law prescribes. Notifications will describe what happened, what data was involved, and what we are doing about it.
12. Children
The Service is a business tool and is not directed to individuals under 18, and we do not knowingly collect information from anyone under 18 (or under 16 where a lower age applies by local law). If you believe a child has provided us information, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and continued use of the Service after changes take effect constitutes acceptance.
14. Contact
Aveera LLC (FinAccrual)
4285 Morse Rd, PMB 17041798
Columbus, OH 43230, USA
support@finaccrual.com