Privacy Policy
Last updated: 2026-06-23
Myrqvist Finance MCP (QuickBooks connector) ("the Service") is operated by Vensar AB, operating on behalf of the Myrqvist group (including Myrqvist Inc and Myrqvist Madison Retail Inc) ("we", "us"). The Service
is an internal integration used only by authorized employees and contractors of
the Myrqvist group to access the group's own QuickBooks Online company data. It
is not offered to the public.
What we access
- Identity. When you sign in, we receive your name and
email from the group's identity provider (Google via Supabase). Access is
restricted to
@myrqvist.com accounts.
- QuickBooks data. With your authorization, the Service
reads accounting data from the QuickBooks Online company you connect — chart
of accounts and balances, customers, vendors, invoices, bills, payments,
journal entries, and financial reports. The Service is read-only;
it cannot create, modify, or delete data in QuickBooks.
What we store
- Connection tokens. The QuickBooks OAuth refresh
token for each connected company, the company id (realmId), company name,
and your email — stored in our database. Refresh tokens are encrypted at rest
using AES-256-GCM. Short-lived access tokens are held in memory only and are
never written to storage.
- Audit log. For security and troubleshooting we record a
log of requests: the user's email, the operation requested and its parameters
(truncated), timestamp, response status, latency, IP address, and user agent.
Tokens and QuickBooks record contents are not included in the log.
- We do not store your QuickBooks financial records.
Accounting data is fetched on demand and returned to your authorized client;
it is not retained by the Service.
How we use it
Solely to provide the requested read-only access to your QuickBooks data
within the group's internal finance tooling. We do not sell, rent, or share your
data with third parties, and we do not use it for advertising or profiling.
Data sharing & sub-processors
Data is processed only by infrastructure we operate or control: our
application server, our PostgreSQL database, and our authentication provider
(Supabase) and error-monitoring provider (Sentry) for operational purposes. The
Service transmits your QuickBooks data only back to the authorized internal user
who requested it. We share data with Intuit only as required to operate the
OAuth connection.
Security
- All traffic is served over HTTPS (TLS).
- Refresh tokens are encrypted at rest (AES-256-GCM); the encryption key is
held in the server environment, never in the database or source code.
- API credentials (client id/secret) are stored as server-side environment
variables, never hardcoded in the application or exposed to the browser.
- Access is restricted to authenticated
@myrqvist.com users and
the integration requests the minimum (read-only accounting) scope.
- Logs are scrubbed of authorization headers and tokens.
Retention
Connection tokens are retained until you disconnect the company (or we revoke
access), at which point the stored token is deleted and revoked at Intuit. Audit
logs are retained for operational and security purposes and then deleted on a
rolling basis.
Your choices
You can disconnect a company at any time from your client (which deletes and
revokes its stored token), or contact us to remove your data. Because this is an
internal tool, requests are handled directly by the operator.
Contact
Questions or data requests: douglas@myrqvist.com.