Effective date
September 22, 2026
Overview
This notice covers the Enroute QuickBooks Connector, a local tool operated by Enroute Running Inc. and, if separately connected, Enroute Cycling Inc. It does not replace Enroute’s retail website privacy policies.
Data accessed
After a QuickBooks Online company administrator authorizes access, the Connector receives the company’s Intuit realm ID and OAuth access and refresh tokens. Its current read function requests company information and chart-of-accounts data, including account identifiers, names, types, and currency references where provided. Account names or company information may contain personal information if entered that way in QuickBooks. The Accounting permission technically authorizes more than these read functions; the current code makes no accounting write requests.
Purpose and handling
These data verify the selected company and test chart-of-accounts access for internal accounting and reporting setup. Credentials and tokens are stored locally on the operator’s computer, excluded from Git, and are not printed by the Connector. Read results appear in the operator’s terminal. During sign-in, Intuit’s one-time authorization code, realm ID, and state pass through an Enroute-controlled HTTPS relay hosted on Cloudflare, which immediately redirects them to the operator’s local callback. The relay does not exchange or store access or refresh tokens. The current Connector has no hosted database and does not send QuickBooks accounting data to a separate analytics or advertising service. It communicates with Intuit for authorization and read access.
Access and retention
Access is limited to authorized Enroute operators and anyone with access to the protected local files. OAuth tokens remain locally until removed or replaced. Terminal output and operator-made copies are subject to Enroute’s internal handling practices. QuickBooks remains the accounting system of record.
Disconnecting and deletion
A QuickBooks administrator can revoke the app connection in QuickBooks or Intuit. Enroute can remove the local token entry and retained output. Revocation stops future access; it does not delete data held by Intuit. Requests about accounting records should be handled through the applicable company and Intuit.
Changes and contact
This notice should be reviewed before any change to the Connector’s data use or hosting. Questions or requests may be sent to run@enroute.run.