Privacy Policy

Effective Date: June 1, 2026  |  Last Updated: June 1, 2026

Introduction

SMB Strategy Consultants LLC ("Company," "we," "us," or "our") operates The SMB BOSS — The SMB Business Operations System Suite — available at www.thesmbboss.com. This Privacy Policy explains how we collect, use, store, protect, and share information when you use our platform, including information accessed through your QuickBooks Online account.

By using The SMB BOSS, you agree to the practices described in this Privacy Policy. If you do not agree, do not use the platform.

If you have questions, contact us at support@thesmbboss.com.

Information We Collect

Account Information

When you register, we collect your name, email address, business name, and any other information you provide during the sign-up or onboarding process.

QuickBooks Online Financial Data

With your explicit authorization through the QuickBooks Online OAuth 2.0 process, we access the following financial data from your QuickBooks Online account to power The SMB BOSS tools:

We access only the data necessary to deliver the specific tools you have activated in your account. We do not access payroll records, employee data, vendor payment details, or any data not required to power your active tools.

Usage Data

We collect standard technical information when you use the platform, including browser type, IP address, pages visited, features used, and session duration. This information is used to improve the platform and diagnose technical issues.

Communications

If you contact us by email or through the platform, we retain a record of that correspondence.

How We Use Your Information

We use the information we collect for the following purposes:

We do not use your QuickBooks financial data to train machine learning models, create aggregate datasets for sale, or for any purpose other than delivering your SMB BOSS tools.

How We Do NOT Use Your Information

We are explicit about what we will never do with your data:

QuickBooks Online Authorization and Access

The SMB BOSS connects to QuickBooks Online through Intuit's official OAuth 2.0 authorization framework. When you authorize the connection, Intuit issues us a secure access token tied to your specific QuickBooks company (realmId). We use this token to retrieve your financial data via the QuickBooks Online API.

Scope of access: We request access to your accounting data using the com.intuit.quickbooks.accounting scope, which covers the financial report and transaction data listed above. We never request access to payroll, payments, or other QuickBooks products outside this scope.

Token storage: Access tokens and refresh tokens are stored using encrypted secret management infrastructure. Tokens are never stored in plaintext, logged to application logs, or stored in any location accessible outside the authorized service layer.

How to revoke access: You can revoke The SMB BOSS's access to your QuickBooks Online account at any time by:

Upon revocation, we will immediately invalidate your stored tokens and cease all data retrieval from your QuickBooks account. Previously retrieved data may be retained for up to 30 days before permanent deletion.

Service Providers

We use a limited number of third-party service providers to operate the platform. These providers process data only as necessary to deliver services on our behalf and are contractually prohibited from using your data for their own purposes:

We do not share your financial data with any other third parties without your explicit consent.

Data Security

We implement industry-standard security measures to protect your data:

No security system is impenetrable. If we become aware of a security breach that affects your data, we will notify you as required by applicable law.

Data Retention

We retain your account information and financial data for as long as you maintain an active account with The SMB BOSS. If you close your account or revoke QuickBooks access:

Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at support@thesmbboss.com. We will respond within 30 days.

Children's Privacy

The SMB BOSS is a business platform intended for adults operating businesses. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected information from a minor, we will delete it immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and, for material changes, notify you by email or prominent notice within the platform. Your continued use of The SMB BOSS after changes take effect constitutes your acceptance of the revised policy.

Contact Us

If you have any questions about this Privacy Policy, your data, or our practices, please contact us:

SMB Strategy Consultants LLC
Email: support@thesmbboss.com
Website: www.thesmbboss.com