Effective July 25, 2026 · Last updated August 28, 2026
Privacy Policy
This Privacy Policy explains how Sourcebook ("Sourcebook," "we," "us," or "our") collects, uses, discloses, and protects information when you access or use the Sourcebook website, application, and related services (collectively, the "Service"), including when you connect QuickBooks Online or other third-party software to the Service.
By using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service. Capitalized terms not defined here have the meanings in our Terms of Use.
Intuit Inc. and QuickBooks are not affiliated with Sourcebook and do not endorse this Privacy Policy. QuickBooks Online data accessed through our integration is also subject to Intuit's own terms and privacy practices.
1. Scope and roles
This Policy applies to personal information and customer business data processed in connection with the Service. It does not apply to third-party websites, products, or services that we do not control (including Intuit / QuickBooks Online, Google, Nango, or your identity provider), which have their own privacy policies.
- Account holders / Authorized Users: individuals who create or access a Sourcebook account.
- Customer / Organization: the business that owns a workspace and the Customer Data uploaded or synced into it. For Customer Data, we act as a service provider / processor on behalf of the Customer; the Customer is the controller / business.
- Customer Data: files, spreadsheets, import rows, mappings, matches, organization master data, and data pulled from connected systems (including QuickBooks Online and Shopify), stored in a Customer's workspace.
2. Information we collect
2.1 Information you provide
- Account information: email address, password (hashed by our auth provider), display name, and authentication preferences (including email one-time codes / 2FA).
- Organization profile: company name, optional legal name, and workspace settings.
- Customer Data you upload or enter: CSV/Excel and other files, import notes, column mappings, match decisions, entity records (e.g. locations, employees, vendors, customers, products, accounts), and related metadata.
- Communications: messages you send to support or legal contacts, and feedback.
2.2 Information from Google sign-in
If you choose Google OAuth, we receive identifiers and profile information necessary to create or authenticate your account (typically email and basic profile attributes), as permitted by Google and your settings. We do not receive your Google password.
2.3 QuickBooks Online and other integrations
When an Authorized User connects QuickBooks Online, we use a third-party integration platform (currently Nango) to facilitate OAuth with Intuit. OAuth access and refresh tokens are held by that integration platform; we store connection metadata needed to operate the integration (for example connection id, integration id, QuickBooks company / realm id, and display name).
With your authorization under Intuit's OAuth consent (scope typically com.intuit.quickbooks.accounting), we may retrieve QuickBooks Online accounting data that you choose to pull into the Service, which may include:
- Chart of accounts and account metadata
- Purchases / expenses / checks
- Deposits
- Transfers
- Customer payments
- Bill payments
- Related fields such as dates, amounts, account names, counterparty names, memos, payment types, currency, and QuickBooks record identifiers
We pull data into import workflows you initiate (or that Authorized Users of your Organization initiate). We do not use QuickBooks Online data to market to end consumers, sell it, or share one Customer's QuickBooks data with another Customer.
You may disconnect QuickBooks at any time in the Service (or revoke access in your Intuit account). Disconnecting stops new API access; previously imported copies may remain in your workspace until you delete them or request deletion as described below.
2.4 Automatically collected information
- Device and log data: IP address, browser type, approximate location derived from IP, referring URLs, and timestamps.
- Usage data: pages and features used, import/processing events, error diagnostics, and performance metrics.
- Cookies and similar technologies: session and authentication cookies necessary to keep you signed in and secure the Service. We do not use third-party advertising cookies for cross-site ads.
3. How we use information
We use information to:
- Provide, operate, maintain, and improve the Service (parse imports, map columns, match records, sync authorized QuickBooks data, and store your company database).
- Authenticate users, enforce access controls, and protect against fraud, abuse, and security incidents.
- Communicate about the Service (transactional emails, security alerts, and—where permitted—product updates).
- Comply with law, enforce our Terms, and protect rights, safety, and property.
- Create aggregated or de-identified statistics that do not identify you or your Organization, for improving the Service. We do not re-identify such data.
We do not sell personal information or Customer Data. We do not share personal information for cross-context behavioral advertising. We do not use QuickBooks Online customer data for purposes other than providing the Service as described here and in our Terms, or as otherwise authorized by the Customer or required by law.
5. Retention
We retain account information and Customer Data for as long as the Organization's account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. You may delete imports, disconnect integrations, or request account/workspace deletion. Residual copies may remain in backups for a limited period and are then deleted or anonymized in the ordinary course of business.
6. Security
We implement administrative, technical, and organizational measures designed to protect information, including access controls, encryption in transit (TLS), encryption at rest on our database host, and least-privilege practices for production systems. OAuth credentials for connected systems (including QuickBooks and Shopify) are handled via our integration provider rather than stored as raw secrets in our application database. We log reads of Customer Data in the Service (acting user, organization, resource, and time) so access to personal data can be reviewed. How we handle security incidents is described in our Security Incident Response Policy. No method of transmission or storage is 100% secure; you use the Service at your own risk subject to our Terms. Promptly notify us at sourcebooksupport@gmail.com if you believe your account or a connection has been compromised.
7. Your choices and privacy rights
7.1 Account and integration controls
- Update profile information in the Service or via your identity provider.
- Disconnect QuickBooks or other integrations in the Service and/or revoke access in the third-party product.
- Delete imports and Customer Data you control, subject to Organization policies and technical limitations.
- Close your account by contacting us (Organization owners may need to delete or transfer the workspace).
7.2 U.S. state privacy rights (including CCPA/CPRA)
If you are a resident of California or another U.S. state with similar laws, you may have rights to know/access, correct, delete, and obtain a portable copy of certain personal information, and to opt out of “sale” or “sharing” of personal information. We do not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, beyond what is necessary to provide the Service. To exercise rights, email sourcebooksupport@gmail.com. We will verify your request and respond as required by law. You may use an authorized agent where permitted. We will not discriminate against you for exercising privacy rights.
If we process personal information solely as a service provider to a Customer (business), please direct privacy requests to that Customer; we will assist them as required by our agreement and applicable law.
7.3 EEA/UK/Switzerland (GDPR)
Where GDPR or UK GDPR applies, our legal bases include: performance of a contract (providing the Service), legitimate interests (securing and improving the Service, preventing abuse—balanced against your rights), consent (where required, e.g. certain cookies or optional marketing), and legal obligation. You may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You may lodge a complaint with a supervisory authority. Contact sourcebooksupport@gmail.com.
8. International transfers
We and our subprocessors may process information in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) for transfers from the EEA/UK/Switzerland. By using the Service, you understand that your information may be transferred to jurisdictions with different data-protection laws than your own.
9. Children
The Service is for business use and is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have, contact us and we will take appropriate steps to delete it.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated Policy with a revised “Last updated” date and, where required by law or Intuit platform rules, provide additional notice. Continued use of the Service after the effective date of changes constitutes acceptance of the updated Policy, except where applicable law requires a different standard.
11. Contact
Privacy questions and requests: sourcebooksupport@gmail.com
Security incidents: sourcebooksupport@gmail.com
Legal notices: legal@sourcebook.me
Controller / operator: Sourcebook, operating the Sourcebook Service.