Legal
Privacy policy
Last updated July 29, 2026
This policy explains how Vatteo collects, uses, shares, stores and deletes personal data when merchants, accountants and bookkeepers use the Vatteo service. Vatteo operates from the United Kingdom and is the controller of the account and service data described below. Vatteo is an independent service and does not process data on Intuit’s behalf.
Information Vatteo processes
Account and access data. Vatteo processes business contact details supplied through Shopify or WorkOS, including name, email address, firm or merchant membership, role, invitation status and authentication identifiers.
Shopify accounting evidence. Vatteo processes payout, order, refund, payment, dispute, payment-method, gift-card, store-credit, product-cost and tax evidence required to prepare and verify accounting entries. It stores financial amounts, timestamps, currencies and provider identifiers such as payout, order and transaction IDs. The accounting workflow does not require or intentionally retain customer names, customer email addresses, phone numbers or street addresses.
QuickBooks data. When a company is connected, Vatteo processes its company identifier and name, home currency, subscription and accounting preferences, chart of accounts, tax codes, closing-date controls, journal-entry identifiers and posting or reconciliation status. OAuth access and refresh tokens are encrypted and are never displayed to users.
Operational data. Vatteo records limited request metadata, timestamps, import and job status, security events, support correspondence and an audit trail of material access, approval, connection and financial actions. Payment and subscription status may be received through Shopify; Vatteo does not collect card details.
How information is used
Vatteo uses this information to authenticate users, connect authorized Shopify and QuickBooks companies, reconstruct and reconcile commerce payouts, prepare and post user-approved accounting entries, investigate variances, provide reports and notifications, administer subscriptions, prevent abuse, secure and troubleshoot the service, meet legal obligations and respond to support or privacy requests.
Where applicable under UK or European data-protection law, processing is based on performing the service contract, the user’s authorized connection of provider accounts, Vatteo’s legitimate interests in operating and securing the service, and compliance with legal obligations. Vatteo does not sell personal data, use it for third-party advertising or use connected Shopify or QuickBooks data to train general-purpose artificial-intelligence models.
Connected services and disclosures
Shopify and Intuit provide data at the direction of an authorized user. Vatteo sends data back to QuickBooks only to perform the accounting actions the user requests. Vatteo uses service providers only where needed to operate the service: Amazon Web Services for application, database and secret hosting; Cloudflare for DNS, traffic protection and delivery; Upstash for managed job-queue infrastructure; WorkOS for accountant authentication; and Resend for transactional email. These providers process information under their own contractual and security obligations. Vatteo may also disclose information when required by law, to protect the service or its users, or in connection with a business reorganization subject to appropriate confidentiality safeguards.
Vatteo is operated from the United Kingdom and uses infrastructure and providers that may process information in the United States or other countries. Where data-protection law requires it, Vatteo relies on recognized transfer safeguards or the provider’s lawful transfer mechanism.
Security and access
Access is isolated by merchant organization and role. QuickBooks tokens are encrypted at rest using a dedicated encryption key. Network traffic uses HTTPS, provider webhooks are authenticated, and material financial actions are recorded in an audit trail.
Retention and deletion
Account, accounting evidence and audit records are retained while a merchant workspace is active because they provide the reconciliation and correction history requested by the merchant. When QuickBooks is disconnected, Vatteo stops new API access, attempts provider revocation and destroys the locally stored OAuth credentials. Existing accounting evidence and identifiers remain available until the merchant requests workspace deletion or Shopify sends its mandatory shop-redaction request, so that prior entries can still be explained and corrected.
After Shopify uninstall, Shopify sessions are removed immediately. The merchant workspace and its remaining provider connections are deleted when the authenticated shop-redaction request is received. Verified customer-redaction requests remove linkable order and payment references while retaining only non-personal accounting amounts and integrity fingerprints. Deletion propagates to live systems promptly; residual encrypted backup copies are isolated from ordinary use and expire under the applicable backup lifecycle. Vatteo may retain limited records where required for security, fraud prevention, dispute resolution, tax, accounting or other legal obligations.
Your choices and rights
Authorized users can disconnect QuickBooks or revoke team access in Vatteo. Merchants can request access, export, correction or deletion by emailing [email protected]. Shopify customer data requests are processed through Shopify’s authenticated privacy webhooks. Depending on location, individuals may also have rights to object, restrict processing, receive a portable copy or complain to a data-protection regulator. Vatteo will verify the requester’s authority before acting on a request.
Cookies and children
Vatteo uses strictly necessary authentication, security and session cookies. It does not use the service for interest-based advertising. Vatteo is a business accounting service, is not directed to children and is not intended for anyone under 18.
Changes and contact
Vatteo may update this policy as the service or legal requirements change. Material changes will be identified by a new effective date and communicated through the service or account email where appropriate. Questions, privacy requests and complaints can be sent to [email protected].