AMDG Consulting
Privacy Policy

What we touch, and what we don't.

AMDG Accounting Operations is a private QuickBooks Online integration. This page explains exactly what it reads, what it is allowed to write, how the authorization is held, and how to end it.

Effective August 13, 2026



01

Who this covers

This policy describes how AMDG Consulting LLC (“AMDG Consulting,” “we,” “us”) handles information in connection with AMDG Accounting Operations (the “Integration”), a private integration with QuickBooks Online that we operate for our own accounting work and for clients who have engaged us and connected their own QuickBooks Online company.

The Integration is not a public application and is not offered for general download or sign-up. It runs only for companies whose authorized administrator has connected it.

AMDG Consulting is an independent consulting practice. We are not affiliated with, endorsed by, sponsored by, or a partner of Intuit Inc. QuickBooks and QuickBooks Online are trademarks of Intuit Inc., used here only to identify the service the Integration connects to.

02

Access begins with your authorization

The Integration accesses QuickBooks Online data only after an authorized administrator of your QuickBooks company completes Intuit’s OAuth 2.0 authorization flow and grants access. We never ask for, collect, or store QuickBooks usernames or passwords, and we have no way to reach your accounting data without that authorization.

Authorization is granted through Intuit’s own consent screen, which shows the scopes being requested before you approve. Revoking that authorization ends the Integration’s access. See Disconnecting below.

03

What accounting data we access

Within the scopes you approve, the Integration may read accounting records from your QuickBooks Online company, including:

  • Company and account settings, including the chart of accounts.
  • Customers, vendors, and employees recorded in QuickBooks, including the names, addresses, email addresses, and phone numbers stored on those records.
  • Transactions such as invoices, bills, payments recorded in the ledger, expenses, journal entries, credit memos, and deposits.
  • Products, services, classes, locations, and other categorization data.
  • Reports generated from the records above, such as profit and loss, balance sheet, and aging reports.
  • Attachments and memo or description fields attached to those records.

Some of this information may identify individuals — a customer contact, a vendor representative, an employee named on a transaction. We treat it as confidential client information and use it only to operate the Integration for you.

We do not collect QuickBooks Payroll detail, bank login credentials, or full payment card numbers through the Integration.

04

Reading and approved writing

Reading. The Integration reads accounting data to produce reconciliations, categorization suggestions, exception reports, close checklists, summaries, and similar operational output for the people you designate.

Writing.The Integration can write back to QuickBooks Online — for example creating or updating an invoice, bill, journal entry, or categorization — only where you have authorized that action. Write access is granted in writing as part of your engagement, is scoped to the record types you name, and can be narrowed or withdrawn at any time. Where an action is configured to require a person’s approval, the Integration does not write until an operator on your side approves it.

We do not use your accounting data to train machine learning models, and we do not sell, rent, or license it. We do not share it with third parties for advertising or marketing.

05

No payment processing

The Integration does not use the QuickBooks Payments API. It does not process payments, initiate transfers, move funds, charge cards, or debit or credit any bank account.

Recording a payment in the ledger — where you have authorized write access — is a bookkeeping entry describing money that moved elsewhere. It does not move money.

06

OAuth tokens and how we hold them

Intuit’s authorization flow issues an access token and a refresh token that let the Integration call the QuickBooks Online API on your behalf. These tokens are credentials. We handle them as follows:

  • Tokens are stored encrypted at rest and are never written to application logs, analytics, or error reports.
  • Tokens are transmitted only over TLS-encrypted connections to Intuit's API endpoints.
  • Access tokens are short-lived and refreshed automatically; refresh tokens are rotated according to Intuit's requirements.
  • Access to stored tokens is limited to the personnel who operate the Integration.
  • Tokens are invalidated and deleted when you disconnect, when the engagement ends, or when we no longer need them.
07

Service providers, including Composio

We use Composio as our OAuth and integration service provider. Composio brokers the QuickBooks Online OAuth connection, stores the resulting tokens, and relays authorized API calls between the Integration and Intuit. In doing so, Composio processes the accounting data described above on our behalf, under its own terms and privacy commitments.

We also rely on a small number of infrastructure providers — application hosting, database hosting, and error monitoring — that may process Integration data incidentally in the course of running the service.

Each of these providers acts as a processor for us: they may use the data only to provide their service to us, not for their own purposes. We do not add advertising, data-broker, or profiling services to this chain.

08

Security

The controls we maintain around the Integration include:

  • Encryption in transit (TLS) for all connections, and encryption at rest for stored credentials.
  • Least-privilege OAuth scopes — we request only the scopes the engagement requires.
  • Access restricted to named personnel, on accounts protected by multi-factor authentication.
  • Secrets held in a managed secret store, never in source control.
  • Logs that record which actions ran, without recording tokens or unnecessary record detail.
  • Prompt revocation of access when an engagement ends or personnel change.

No system is perfectly secure. If we become aware of a breach affecting your QuickBooks data, we will notify you without undue delay and describe what we know, what we have done, and what we recommend.

09

Retention and deletion

We keep QuickBooks data only as long as it is needed to operate the Integration for you. QuickBooks Online remains the system of record; where the Integration caches data, it does so to perform the work you have asked for, not to build a parallel archive.

  • Cached accounting records are deleted within 30 days after you disconnect or the engagement ends, unless you ask us in writing to keep specific work product.
  • OAuth tokens are deleted promptly on disconnection.
  • Operational logs are retained for up to 90 days and then deleted.
  • Deliverables we produced for you — reports, reconciliations, documentation — are retained per your engagement agreement and returned or deleted on request.

You may request deletion at any time by emailing michael@amdgconsulting.ai. We will confirm when it is done. We may retain records where a law or a legitimate accounting or legal obligation requires it, and we will tell you if that applies.

10

Disconnecting

You can end the Integration’s access at any time, without notice to us:

  • In QuickBooks Online, an administrator can revoke the connection under Settings → Apps → Manage → Disconnect.
  • In your Intuit account, you can review and revoke connected apps directly.
  • Or email michael@amdgconsulting.ai and we will disconnect it and confirm.

Revocation takes effect immediately. Once revoked, the Integration cannot read or write anything in your QuickBooks company, and we delete the associated tokens.

11

Your rights

The QuickBooks company you connect is yours, and the data in it is yours. On request, we will tell you what Integration data we hold, provide a copy in a usable format, correct anything inaccurate, restrict how it is used, or delete it, subject to the retention section above.

Depending on where you or the individuals in your records are located, additional rights may apply under laws such as the California Consumer Privacy Act or the GDPR. Where the data we process on your behalf includes personal information about your customers, vendors, or employees, you are the controller of that information and we act as your processor. We will assist you in responding to requests those individuals make to you.

We do not sell or share personal information as those terms are defined under California law.

12

Changes to this policy

If we change how the Integration handles data, we will update this page and move the effective date at the top. Where a change is material — a new category of data, a new provider in the chain, a broader use — we will tell connected clients directly before it takes effect.

13

Contact

Questions about this policy, about what the Integration touches, or about a data request:

AMDG Consulting LLC
michael@amdgconsulting.ai

We answer within one business day.


The terms that govern use of the Integration sit alongside this policy.