Privacy Policy
This policy describes what Service Lots processes, why it is needed, and the choices available when you connect a QuickBooks company.
- Effective date
- Privacy contact
- info@servicelots.com
1. Scope
This Privacy Policy applies to the Service Lots website, workspace, support, and QuickBooks Online integration. Service Lots is built for business use and is not directed to children.
Intuit processes information separately when you use QuickBooks or its authorization screen. You can review the Intuit Privacy Statement for Intuit's practices.
2. Information we process
QuickBooks company data
After an authorized user connects a company, the current Service may retrieve and store the company name and permitted accounting data, including accounts, customers, vendors, products and services, invoices, payments, bills, bill payments, purchase orders, purchases, and related line and reference data. We also store source identifiers, source versions, and synchronization times needed to keep records scoped to the correct company and show freshness.
Connection and account data
We process the QuickBooks company identifier and OAuth credentials needed to maintain the authorized connection. We also process workspace identifiers, roles, session records, and a name or email address when one is supplied for an account or support request.
Supplier bill documents
Owners and admins may upload PDF, JPEG, or PNG supplier bills to a private company workspace. We store the uploaded source and local processing records, including filenames, extracted bill fields and line items, validation evidence, consent records, and deletion records. Uploading a document alone does not send it to an AI provider.
Technical and support data
Our hosting and security systems may process standard request information, such as timestamps, IP address, browser or device details, and error or security events. If you contact us, we process the message and information you choose to include.
3. How we use information
We use information to:
- connect the company you selected and maintain its authorization;
- synchronize, organize, and display source-backed business records;
- provide review workflows and preserve confirmed workspace choices;
- after an owner or admin explicitly confirms processing for one document, extract structured supplier-bill fields and line items with OpenAI;
- authenticate users and enforce organization and role boundaries;
- secure, troubleshoot, maintain, and improve the Service;
- respond to support, privacy, and security requests; and
- comply with applicable legal obligations.
We do not sell connected QuickBooks data or use it for targeted advertising. The current QuickBooks integration reads permitted data; it does not post transactions or local review decisions back to QuickBooks.
4. When information is shared
We may disclose information only as needed:
- to Intuit, to complete authorization, token exchange, synchronization, revocation, and other actions you request;
- to hosting, infrastructure, security, and support providers that process information for Service Lots;
- to OpenAI only after an owner or admin explicitly chooses AI processing for that particular supplier bill, and only for structured extraction;
- when required by law or reasonably necessary to protect users, the Service, or another person's rights and safety; or
- as part of a proposed business transaction, subject to appropriate confidentiality and data-protection requirements.
Contact us before connecting if you need current information about hosting location or service providers for a compliance review.
Service Lots requests store=false, so it does not ask OpenAI to retain the response as application state. OpenAI states that API data is not used to train its models by default unless the API customer explicitly opts in. OpenAI may still retain customer content in abuse-monitoring logs, generally for up to 30 days by default, or longer when legally required or reasonably necessary to protect its services or others. File and image inputs may be scanned for safety, and flagged content may be retained for review. See OpenAI's API data-controls documentation.
5. Retention, disconnection, and deletion
We retain connected data while it is needed to operate the workspace and as needed for security, support, dispute prevention, and legal obligations.
Each uploaded supplier bill shows when it becomes eligible for a local retention review, currently 365 days after upload. Eligibility is not an automatic browser-triggered deletion. An owner or admin may permanently delete the uploaded source and its linked local Draft Bill earlier from the Documents workspace. Limited consent, deletion, account, security, or audit records may remain where needed for the purposes described here. Provider copies, if any, follow OpenAI's separate retention practices described above.
The protected Disconnect QuickBooks control in Service Lots settings is designed to revoke the provider connection and remove the stored QuickBooks credentials and synchronized accounting copy for that workspace. If provider access is already inactive, the local synchronized copy is still removed. Disconnecting through QuickBooks stops future provider access, but you should also use the Service Lots control or contact us if you want locally stored data removed.
This public disconnection information page does not itself delete data. Some limited account, security, audit, or support records may remain where needed for the purposes above. You can request account or personal-information deletion by emailing info@servicelots.com.
6. Security
Service Lots uses technical and organizational safeguards appropriate to the information it processes. Sensitive QuickBooks connection values are kept server-side and protected at rest, access is scoped by organization and role, and production traffic is intended to use HTTPS. No online system can be guaranteed completely secure.
7. Your choices and requests
You can:
- choose whether to authorize a QuickBooks company;
- disconnect through Service Lots or QuickBooks;
- choose separately whether each uploaded supplier bill is sent to OpenAI;
- delete an uploaded supplier bill and its linked local Draft Bill;
- ask what personal information we hold about you;
- request correction or deletion, subject to applicable requirements; and
- raise a privacy or security concern.
Send requests to info@servicelots.com. We may need to verify your identity and authority over the relevant workspace before acting on a request.
8. Updates and contact
We may update this policy as the Service changes. We will post the updated policy here and change the effective date. For privacy questions, requests, or complaints, contact info@servicelots.com.