Skip to main content
CPA Support Desk logo CPA Support Desk
Home End-User Agreement Open Portal
Privacy Policy

Privacy Policy

Last updated: May 11, 2026

CPA Support Desk is built for CPA firms, accounting teams, and client companies that need secure financial workspaces. This policy explains what information we collect, how we use it, and how connected services such as QuickBooks Online are handled.

1. Information We Collect

We collect information needed to create accounts, operate client workspaces, process accounting workflows, and provide support.

  • Account information such as name, email address, role, phone number, company name, and profile image.
  • Company information such as address, tax ID, logo, currency preference, client records, and workspace settings.
  • Financial workflow information such as invoices, bills, expenses, ledger entries, payment status, notes, files, and activity logs.
  • Uploaded documents such as PDFs, invoice images, receipts, and related attachments stored in Firebase Storage.
  • Technical information such as browser, device, authentication status, logs, and security events.

2. How We Use Information

We use data to operate the platform and deliver accounting workflow functionality.

  • Authenticate users and enforce role-based access.
  • Create and manage client workspaces, invoices, purchases, expenses, ledgers, payments, and activity history.
  • Generate PDFs, send invoice emails, process document uploads, and provide AI-powered analysis where enabled.
  • Connect to third-party services requested by users, including QuickBooks Online.
  • Improve reliability, security, user experience, and support response quality.

3. QuickBooks Online Data

When you connect QuickBooks Online, CPA Support Desk uses your authorization only to perform actions you request from inside the platform.

  • We may store the connected QuickBooks company ID, connection status, token expiry metadata, synced chart-of-account categories, vendors, and customers.
  • Access tokens and refresh tokens are stored server-side and encrypted. They are never exposed in frontend code.
  • We use QuickBooks data to sync categories/vendors/customers and to publish user-approved invoices or bills from the invoice detail page.
  • We do not automatically publish documents to QuickBooks during upload or creation.
  • We do not sell QuickBooks data or use it for unrelated advertising.

4. AI Features

Some features may use AI models to extract invoice data, suggest categories, summarize ledger activity, or answer workspace questions. AI output is provided as assistance and should be reviewed by the user before making accounting, tax, or business decisions.

5. Data Sharing

We share information only when needed to operate the service, comply with law, or perform user-authorized integrations.

  • Firebase and Google Cloud services for authentication, database, storage, hosting, and backend functions.
  • Email providers for transactional emails such as invites, invoices, and reminders.
  • QuickBooks Online when a user connects and manually publishes approved documents.
  • Gmail or Google Workspace when a user connects their own mailbox to view, send, reply, search, or link emails inside the platform.
  • AI service providers when AI-powered features are used.

6. Gmail and Google Workspace Data

When you connect Gmail, CPA Support Desk uses your Google authorization only to provide visible inbox features that you choose to use inside the platform.

  • We request limited Gmail permissions for reading mailbox metadata/body on demand and sending email from your connected Gmail account.
  • Email metadata such as sender, recipient, subject, labels, snippet, message IDs, thread IDs, and client-link status may be stored to power the inbox view.
  • Full email bodies are fetched from Gmail when you open a message and are not stored by default.
  • OAuth tokens are stored server-side and encrypted. They are never exposed in frontend code.
  • Your inbox is private by default. Other workspace users see an email only when you explicitly link it to a client, request, invoice, or saved document workflow.
  • We do not sell Google user data, use it for advertising, or allow humans to read mailbox content except with your explicit direction for support or legal/security needs.

7. Security

We use authentication, role-based access controls, company/client isolation, server-side secrets, encrypted QuickBooks and Gmail tokens, and Firebase security controls. No system is perfectly secure, but we design the platform to reduce unauthorized access and protect workspace data.

8. Data Retention and Deletion

We retain account, workspace, invoice, activity, and connected-service metadata while your account or company workspace is active, unless deletion is requested or required by law. To request deletion or export of data, contact us at contact@cpasupportdesk.com.

9. Your Choices

  • You can update profile and company information in the platform.
  • You can disconnect QuickBooks from the Profile/Settings page.
  • You can disconnect Gmail from the Inbox page. Disconnecting removes active Gmail token access from CPA Support Desk.
  • You can request access, correction, export, or deletion of personal information by contacting us.

10. Contact

For privacy questions, data requests, or QuickBooks/Gmail integration questions, contact CPA Support Desk at contact@cpasupportdesk.com.

This page is provided for transparency and product review purposes. It is not legal advice.