Privacy Policy
Last updated: 20 July 2026
1. Overview
This policy explains what information Benab Invoices (the “Service”) collects, how it is used and protected, and the choices you have. The Service is operated by Neodein (Guyana) Inc. (“we”, “us”), which acts as the data controller for the information described below. The Service is business accounting software: the data inside it belongs to the organization that uses it, and we process it only to provide the Service.
2. Information we collect
- Account information — your name, email address, role, and sign-in details.
- Business data you enter — customers, vendors, invoices, bills, expenses, banking records, and other accounting data your organization records in the Service.
- Connected-service data — data you authorize us to retrieve from third-party services (see the QuickBooks Online section below).
- Operational records — audit logs of significant actions (who did what, when) kept for your organization’s security and accountability.
3. QuickBooks Online data
If your organization connects QuickBooks Online, you authorize us — through Intuit’s consent screen — to retrieve accounting data from the QuickBooks company you choose. Our access works like this:
- Read-only. The Service only retrieves data (such as your chart of accounts, customers, vendors, invoices, bills, payments, and reports). It never creates, modifies, or deletes anything in QuickBooks.
- You choose what is synced. Which data types are retrieved, and for what date range, is controlled by your organization’s administrators; nothing is retrieved automatically in the background.
- Credentials are protected. The authorization tokens Intuit issues are stored encrypted (AES-256-GCM) and are never exposed to your browser or to other organizations.
- Retrieved data is isolated per organization and stored encrypted like other sensitive fields in the Service.
- You can disconnect at any time — from the Service’s Integrations page or from within QuickBooks itself. Disconnecting revokes our access immediately; data already synced remains available to your organization until you delete it or ask us to remove it.
We do not sell QuickBooks data, use it for advertising, or share it with anyone outside the service providers needed to host the Service (section 5).
4. How we use information
- To provide, operate, and support the Service.
- To secure the Service — authentication, permission enforcement, audit logging, and abuse prevention.
- To send service email your organization has configured (for example invoices to your customers, or alert notifications to your users).
- We do not sell personal or business data, and we do not use your data for advertising.
5. Sharing and service providers
We share data only with the infrastructure providers required to run the Service — database and authentication hosting, and transactional email delivery — each acting on our instructions. When you connect a third-party service (such as QuickBooks Online), data flows to and from that service only as you direct. We may also disclose information where required by law.
6. Security
- Encryption in transit (HTTPS/TLS) and application-layer encryption at rest (AES-256-GCM) for sensitive fields and all integration credentials, with per-organization encryption keys.
- Role- and permission-based access control enforced on the server for every request.
- Audit logging of significant actions.
- Third-party credentials (such as QuickBooks tokens) are never shown to users, logged, or sent to the browser.
7. Retention and deletion
We retain your organization’s data for as long as the organization uses the Service. Administrators can delete records within the Service, disconnect integrations (which stops further retrieval), and request deletion of synced third-party data or the entire account by contacting us. Backups age out on a rolling schedule after deletion.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal information we hold. Requests can be made through your organization’s administrator or directly to us at the contact below, and we will respond within the timeframe required by applicable law.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the Service or by email, and the “Last updated” date above will change.
10. Contact
Privacy questions and requests can be sent to Neodein (Guyana) Inc. at support@benabhub.com.