1. Scope and roles
This Policy applies to Backline websites, Backline Books, online support, sales, and related business interactions. “Personal information” means information that identifies, relates to, or can reasonably be linked with a person.
Backline may act as a business or controller for account, visitor, sales, billing, security, and service-administration information. When we process records on behalf of a customer—such as its employee, vendor, customer, or transaction data—the customer generally controls that processing and requests should be directed to it. A signed data-processing agreement controls where applicable.
2. Information we collect
- Identity and account: name, business contact details, organization, role, authentication identifiers, profile, permissions, and preferences.
- Accounting and operations: chart of accounts, transactions, balances, bank metadata, invoices, bills, payments, payroll-related records, customers, vendors, journal entries, budgets, forecasts, tax settings, fixed assets, documents, approvals, reconciliations, and reporting configurations.
- Connected services: provider and company identifiers, OAuth tokens or connection credentials, data made available through approved scopes, and connection status.
- Commercial: plans, orders, engagements, invoices, payment status, support history, and correspondence. Payment processors handle payment-card details; Backline generally receives tokens and limited transaction metadata rather than full card numbers.
- Device, usage, and security: IP address, browser, device and operating-system information, approximate location derived from IP, timestamps, session and feature activity, logs, diagnostic events, and security signals.
- Content and communications: uploads, prompts, feedback, support messages, call or meeting notes where disclosed, and information you ask us to send to recipients.
- Inferences and automated output: suggested classifications, matches, summaries, exceptions, risk or confidence indicators, and other outputs produced from information submitted to enabled features.
3. Sources
We collect information directly from you and authorized users; from your organization, bookkeeper, accountant, or advisor; from connected services you authorize; from service providers; from public business sources; and automatically through your use of the Service. We receive QuickBooks data only after an authorized user completes Intuit’s consent flow.
4. Purposes and legal bases
We use information to:
- Provide, configure, synchronize, support, and bill for the Service and professional engagements.
- Create reports, forecasts, reconciliations, exports, workflow items, and communications requested by authorized users.
- Authenticate users, manage permissions, prevent misuse, protect data, investigate incidents, and maintain continuity.
- Respond to requests, administer customer relationships, and send service and limited business communications.
- Test, troubleshoot, analyze, and improve reliability, accessibility, usability, and feature performance.
- Comply with law, preserve records, enforce agreements, establish or defend claims, and complete corporate transactions.
Where a legal basis is required, processing is based on performing a contract, legitimate interests in operating and protecting a business service, compliance with law, or consent where requested. We do not sell connected accounting data, use it for third-party behavioral advertising, or create unrelated consumer profiles from it.
5. QuickBooks and financial connections
When you connect QuickBooks Online, Backline requests the com.intuit.quickbooks.accounting scope. Depending on enabled features, we may read company information, accounts, customers, vendors, invoices, bills, payments, journal entries, general-ledger detail, budgets, and reports. We use this information for customer-directed migration, reconciliation, bookkeeping, reporting, forecasting, consolidation, and export. We do not request the QuickBooks Payments scope or use QuickBooks data to initiate payments.
Bank-data providers may make available account metadata, balances, and transactions. Backline does not receive your online-banking password. Other integrations are governed by the scopes and instructions presented when connected.
6. AI and automated processing
Enabled features may use rules, statistical models, or generative AI to extract, classify, match, summarize, prioritize, or prepare drafts. Backline may send the minimum information reasonably needed to contracted model or document-processing providers. Automated output requires human review and is not used by Backline to make solely automated decisions producing legal or similarly significant effects on individuals. See AI Disclosures.
7. Disclosures
We may disclose information to:
- Authorized users, advisors, and recipients designated by the customer.
- Vendors providing hosting, database, identity, communications, workflow, monitoring, support, document processing, AI, payment, and financial-data connectivity services.
- Professional advisers, auditors, insurers, and financing sources under appropriate duties.
- A buyer, investor, successor, or transaction participant in a merger, financing, restructuring, or asset transfer, subject to appropriate safeguards.
- Authorities or other parties when required by law or reasonably necessary to protect rights, safety, data, the Service, or the public.
Providers may process information only for contracted purposes and applicable obligations. See Subprocessors & Service Providers. We do not disclose connected accounting data to data brokers or advertising networks.
8. Cookies and telemetry
We use essential cookies and similar storage for authentication, security, preferences, and operation, plus limited diagnostics and product telemetry. We do not use connected accounting data for behavioral advertising. Details and choices are in the Cookie Notice.
9. Retention
We retain information for the period needed to provide the Service or engagement and afterward for legitimate business records, legal obligations, security, backup and recovery, dispute resolution, and enforcement. Retention depends on the data type, contract, sensitivity, and legal need. OAuth credentials are deleted or made unusable when a connection is removed. Verified deletion requests are normally completed within 30 days unless a lawful exception applies. Residual backups are isolated from ordinary use and expire under backup schedules.
10. Security
We use administrative, technical, and organizational safeguards designed for financial information, including encrypted transport, provider-managed encryption at rest, organization-aware access controls, authenticated sessions, managed secrets, logging, backups, deployment controls, and incident procedures. No system is completely secure. Users must protect their accounts, assign minimum necessary access, review exports and recipients, and promptly report suspected compromise. See Security at Backline.
11. Your choices and rights
You may update profile information, manage communications, disconnect integrations, and request access, correction, export, restriction, objection, or deletion. Depending on your residence, you may also have rights to know categories and sources, obtain a portable copy, opt out of sale, sharing, targeted advertising, or qualifying profiling, limit certain sensitive-information uses, and appeal a denied request. Backline does not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined.
We verify requests and may ask for information necessary to protect the account. Authorized agents must provide proof of authority. Some information may be exempt or retained where law permits. We will not discriminate for exercising applicable rights. If Backline processes the information for a customer, we may refer the request to that customer.
12. State-specific notices
Residents of California and other states with comprehensive privacy laws may exercise applicable rights through the contact below. In the preceding 12 months, the categories collected and disclosed for business purposes correspond to the categories in Section 2 and the recipients in Section 7. We do not knowingly sell or share personal information of consumers under 16. Backline does not offer a financial incentive for personal information.
13. International processing
Backline and providers may process information in the United States and other countries with different laws. Where required, we use appropriate contractual or legal transfer mechanisms and supplementary safeguards. Customers with specific residency or transfer requirements should address them in a signed agreement before submitting restricted data.
14. Children
The Service is for businesses and is not directed to children under 13. We do not knowingly collect personal information directly from children. Customers must not submit children’s information unless legally authorized and covered by an appropriate agreement.
15. Third-party sites
The Service may link to or integrate with services we do not control. Their privacy and security practices govern their processing, and this Policy does not apply to them.
16. Changes
We may update this Policy to reflect product, provider, or legal changes. We will post the revised effective date and provide additional notice when required. Material changes generally apply prospectively.
17. Contact and appeals
Submit privacy requests or appeals to admin@backlinebusinesssolutions.com, +1 937.591.1828, or Backline Business Solutions, PO Box 254, Urbana, OH 43078. Do not email passwords, government identifiers, OAuth tokens, or live financial records.

