Privacy Policy
Last updated: September 21, 2026
Account-Flow is operated by Montero and Viera LLC, a Delaware limited liability company. Account-Flow provides connector apps, reconciliation, reporting, and accounting workflow software for ecommerce and service businesses. This policy explains how we collect, use, protect, retain, and delete data when a client authorizes Account-Flow to connect systems such as Amazon Selling Partner API, Meta Ads, Shopify, or QuickBooks Online and other accounting platforms. This policy covers our website, client services, and Account-Flow Invoice Sync app.
Information we collect
- Client and connection metadata: business/client name, internal client key, platform name, account/store/ad account identifiers, marketplace identifiers, authorized scopes or roles, connection status, authorization timestamps, and audit events.
- Amazon Selling Partner data: data a seller authorizes through Amazon SP-API, such as orders, settlements, payouts, fees, reimbursements, inventory, catalog/report data, and related financial or operational records needed for reconciliation and reporting. We request only the Amazon roles and data needed for the approved service.
- Meta Platform data: data a business authorizes through Meta, such as ad account identifiers, campaign/ad set/ad names, spend, impressions, clicks, dates, delivery/performance metrics, and related reporting fields. Our Meta Ads connector is intended for read-only reporting and reconciliation.
- Other connected-source data: ecommerce, payment, banking, accounting, fulfillment, or file-import data authorized by the client for Account-Flow services.
- Credentials and tokens: OAuth tokens, refresh tokens, app authorization grants, or similar secrets required to keep a client-authorized connection active. These are stored in encrypted vault storage and are not displayed in client-facing pages.
- Operational logs: security, debugging, synchronization, error, and audit logs. Logs are minimized where practical and are used to operate and protect the service.
- Website analytics and advertising data: page views, campaign parameters, referral source, approximate device/browser information, button clicks, form/contact clicks, and similar marketing-site activity collected through analytics or advertising pixels. We do not intentionally collect raw passwords, payment-card numbers, bank credentials, or client platform data through marketing-site tracking.
Shopify and QuickBooks Invoice Sync
When a merchant connects a Shopify store and a QuickBooks Online company, we process the connected data to provide the synchronization features the merchant enables. The merchant controls its customer relationship and instructs us how to process store data through its authorizations, settings, and account mappings.
- Shopify order data: store and order identifiers, order numbers and dates, customer email addresses, billing and shipping country/province codes, products and SKUs, quantities, prices, discounts, shipping charges, taxes, payment status, payment-provider identifiers, and related refund and transaction information.
- Shopify Payments data: payout identifiers, dates, amounts, currencies, processing fees, refunds, adjustments, and the transactions included in a payout. We use these to prepare and record payout entries using the merchant's account mappings.
- QuickBooks data: company identifiers, customer records (including display names and email addresses), products, inventory information, accounts, tax codes, invoices, received payments, deposits, and related balances and transaction history used for matching, validation, and synchronization.
- App records: connection authorizations, saved mappings and preferences, import dates, sync status, exception details, source and destination record identifiers, and diagnostic/audit information needed to operate the app and prevent duplicate posting.
Customer email addresses are used to match an order to a QuickBooks customer or create a customer when the merchant's rules allow it. Location codes support tax handling. Order and payout details support invoice, payment, fee, refund-deduction, and deposit recording. The app does not need customers' full payment-card numbers, card security codes, or online-banking passwords.
Enabling synchronization authorizes the app to send the required order and transaction information to the connected QuickBooks company and create accounting records according to the merchant's settings. These can include customers, products or tax-recording items, invoices, received payments, and deposits. Inventory mappings can affect QuickBooks inventory. Recording a payment or deposit in the books does not itself charge a customer's card or transfer money.
We use connected-store customer data for these merchant-authorized functions, support, security, and applicable legal obligations. We do not sell this data or use it for unrelated advertising. Marketing-site analytics are separate from the app's connected-store data.
Who receives information
We share information with the platforms the merchant connects, including Shopify and Intuit QuickBooks Online, as needed to provide the requested integration. We also use service providers for hosting, data storage, security, and support, subject to the platform-data commitments below. Authorized support personnel may access information needed to investigate a merchant's request. We may disclose information when required by law or as directed by the merchant.
Connected platforms process information under their own privacy terms. Disconnecting Account-Flow does not remove records already sent to those platforms.
How we use information
- To connect to platforms that the client has authorized and import the data needed for the agreed service.
- To normalize, reconcile, classify, and report ecommerce, advertising, payout, inventory, and accounting activity.
- To identify missing, duplicated, unreconciled, or misclassified transactions and support month-end close or management reporting workflows.
- To maintain security, prevent unauthorized access, troubleshoot integrations, support clients, and preserve audit history.
- To comply with applicable laws, platform requirements, accounting obligations, and written client instructions.
- To understand marketing-site performance, measure campaign effectiveness, improve page experience, and retarget or follow up with visitors who interact with Account-Flow marketing pages.
Website analytics and advertising pixels
Account-Flow may use tools such as Google Analytics/Google Ads tags, Meta Pixel, Microsoft Clarity, LinkedIn Insight Tag, or similar services to measure traffic, conversions, ad performance, and website usability. These services may set cookies or similar identifiers and may receive event data such as page path, campaign parameters, click type, package selected, and estimated conversion value. Marketing-site tracking is separate from client-authorized platform connectors and is not used to sell client platform data.
Visitors can limit tracking by using browser privacy controls, ad-platform opt-out tools, or Do Not Track/browser-level blocking where supported.
Platform data commitments
- We do not sell Amazon, Meta, or client platform data.
- We do not use platform data to build unrelated advertising profiles or for unrelated marketing.
- We do not share platform data with third parties except as needed to provide Account-Flow, as directed by the client, as required by law, or with service providers bound to protect the data.
- We do not request or use write-level, ads-management, payment, banking, or account-administration permissions unless separately approved for a specific client workflow.
- We do not ask clients to send raw access tokens, refresh tokens, app secrets, or security codes through chat, email, screenshots, spreadsheets, or workbook tabs.
Security
- Connector secrets and OAuth tokens are stored in encrypted vault storage and transmitted over HTTPS.
- Access to client data is limited to authorized operations and support needs.
- We use least-privilege permissions, environment-based secret storage, audit logging, and separation between client connection records.
- Where sensitive data is not needed for reporting or reconciliation, we avoid collecting it or minimize/mask it where practical.
Retention
We retain data only as long as needed to provide services, maintain security and audit records, comply with legal/accounting obligations, resolve disputes, or follow written client instructions. When data is no longer needed for those purposes, we delete it or de-identify it where practical.
Deletion and revocation
Clients may revoke access directly in the connected platform at any time, including Amazon Seller Central app authorizations, Meta Business integrations/settings, Shopify app settings, or accounting platform app settings. Clients may also request export, correction, disconnection, or deletion by emailing info@account-flow.com. Additional instructions are available at /data-deletion.
Your privacy requests
Depending on applicable law, you may have rights to access, correct, export, or delete personal information, or to object to or restrict certain processing. Contact info@account-flow.com to make a request. We verify the requester's authority and respond under applicable legal and platform requirements. Please do not send passwords, access tokens, or full payment-card details.
If you are a customer of a store using Account-Flow, contact that store first about your order or customer information. We support the merchant in responding to requests concerning data processed on its behalf. You can also contact us to help route a request.
Uninstalling the Shopify app or disconnecting QuickBooks revokes the relevant connection; it does not by itself delete invoices, payments, deposits, or customer records already held in the merchant's QuickBooks company. Those records remain under the merchant's control. Requests to delete Account-Flow's stored data are handled separately, subject to the retention grounds above. Any information that must be retained for a legal obligation is limited to that purpose.
Children's data
Account-Flow is a business-to-business service and is not intended for children or consumer social use.
Changes to this policy
We may update this policy as the service, platform requirements, or applicable law changes. The updated date above shows the latest version.
Contact
Privacy, security, or data handling questions can be sent to info@account-flow.com.