990 Books is a service of Omnia Ventures LLC (“we,” “us,” or “our”). This privacy policy describes how we collect, use, and protect information when you visit our website at 990books.com, engage us for bookkeeping or Form 990 preparation services, or use our software tools, including the 990 Books Donor Receipt Generator (the “App”).
Information we collect
Website visitors
When you visit 990books.com, we may collect standard analytics data such as pages viewed, time on site, referring URL, browser type, and approximate location. This information is collected in aggregate and is not used to identify individual visitors. We may use third-party analytics services for this purpose.
Bookkeeping and Form 990 clients
When you engage us for bookkeeping or Form 990 preparation services, we collect the information necessary to perform those services, including your name, email address, organization name, EIN, and any financial records you provide or grant us access to through your accounting platform. We access your accounting data only through authorized user credentials you provision for us, with role-level permissions appropriate to the engagement.
App users
When you connect the App to your QuickBooks Online account, we collect and store the following:
- Organization information. Your QuickBooks company name, QuickBooks company ID (realm ID), and the email address associated with your QuickBooks account.
- OAuth tokens. The access and refresh tokens that authorize the App to read data from your QuickBooks account. These tokens are encrypted at rest using Fernet symmetric encryption before being written to our database.
- Donation transaction data. The App reads donation and deposit transactions from your QuickBooks account in order to generate donor acknowledgment letters. Transaction data retrieved from QuickBooks — including donor names, dates, amounts, and descriptions — may be stored in our database to support the receipt generation workflow and your historical records within the App.
- Receipt records. Information you enter or confirm during the receipt review process, including donor salutation, donation type classifications, and fair market value disclosures, is stored alongside the corresponding transaction data.
The App does not read or access payroll data, payment processing data, employee information, or any QuickBooks data outside the scope of the Accounting API read permissions you authorize.
How we use your information
We use the information we collect to:
- Provide bookkeeping, Form 990 preparation, and related accounting services.
- Operate the App, including connecting to your QuickBooks account, retrieving donation data, and generating donor acknowledgment letters.
- Communicate with you about our services or your account.
- Improve our website and services.
- Comply with legal obligations.
We do not sell, rent, or share your information with third parties for their marketing purposes.
Third-party services
We use the following categories of third-party services in the operation of our business and the App:
- Cloud hosting. Our App and database are hosted on Google Cloud (United States) and Neon (United States). Your data is stored on servers located in the United States.
- QuickBooks Online. The App connects to QuickBooks Online through Intuit's OAuth 2.0 API. Your use of QuickBooks Online is governed by Intuit's own terms and privacy policy.
- Analytics. We may use third-party analytics tools to understand how visitors use our website and App. These tools may collect anonymized usage data.
- Payment processing. If you subscribe to the App, your payment is processed by a third-party payment processor. We do not store your credit card number or payment account details on our systems. Payment processing is handled entirely by the processor's hosted payment page.
Data security
We take reasonable measures to protect your information, including:
- Encryption of OAuth tokens at rest.
- Storage of application secrets in environment variables, not in source code.
- Use of HTTPS for all data transmission.
- Access controls limiting who can access production systems and data.
No method of electronic storage or transmission is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
Data retention
Bookkeeping and Form 990 clients. We retain client records for the duration of the engagement and for a reasonable period afterward consistent with professional standards and applicable law.
App users. We retain your data for as long as your account is active. If your subscription lapses, we retain your stored data for a limited period to allow you to reactivate and access your records. After that period, your data may be deleted. You may request deletion of your data at any time by contacting us.
OAuth tokens. QuickBooks refresh tokens expire automatically after 100 days of non-use. When a token expires, the App can no longer access your QuickBooks data unless you reconnect.
Disconnecting and data deletion
You can disconnect the App from your QuickBooks account at any time from within the App or from within your QuickBooks account settings. Disconnecting revokes the App's access to your QuickBooks data. To request deletion of data already stored in our systems, contact us at [email protected].
Your rights
You may contact us at any time to:
- Request a summary of the information we hold about your organization.
- Request correction of inaccurate information.
- Request deletion of your data.
- Withdraw authorization for the App to access your QuickBooks account.
We will respond to requests within 30 days.
Children's privacy
Our services and App are intended for use by organizations and their authorized representatives. We do not knowingly collect information from individuals under the age of 18.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date. Your continued use of our website, services, or App after changes are posted constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy, contact us at:
Email: [email protected]