TenkeyBridge

Privacy Policy

Effective: October 5, 2026

This Privacy Policy describes how Empire Innovations, LLC, an Idaho limited liability company ("Empire," "we," "us"), handles personal data in connection with TenkeyBridge, a QuickBooks Online–compatible REST API for QuickBooks Desktop & Enterprise. Empire is based in Nampa, Idaho, USA. This policy covers our website and the TenkeyBridge service (the developer portal and cloud gateway); it does not cover QuickBooks itself, which Intuit Inc. operates under its own privacy policy.

1. Who we are & scope

Empire Innovations, LLC builds and operates TenkeyBridge. This policy applies to anyone who visits our website, signs up for a TenkeyBridgeaccount, or connects a QuickBooks company file through our Windows agent. If you have questions about a data practice this policy doesn't answer, email privacy@tenkeybridge.com.

2. Data we collect

We collect the following categories of data:

  • Account data— your name, email address, and sign-in provider ids (if you sign in with Google or GitHub) needed to authenticate you and operate your account. If you sign in with Google or GitHub, we also store the sign-in tokens that provider returns to us, so we can verify your account with them; we don't use those tokens to access anything else in your Google or GitHub account.
  • Organization & billing data— your organization's name, its members, and the Stripe customer and subscription ids used to bill your organization. Card and payment details are handled entirely by Stripe; they never touch our servers.
  • Service metadata — the QuickBooks realms (company files) connected to your organization, and the connection status of your Windows agent (online/offline, last seen, version). Credentials TenkeyBridge issues to you — API keys, OAuth client secrets, and the access and refresh tokens your applications use to call the API — are stored as one-way hashes, never in plaintext.
  • Request logs — for every API request, we log the HTTP method, path, status code, latency, realm id, entity, error code (if any), the query text for query requests, and the IP address the request came from (used to investigate abuse and enforce rate limits). We do not log request or response bodies, and we never log the Authorization header. Request logs are kept in Axiom for 30 days and then deleted.
  • Website analytics — none. Our marketing website runs no analytics package and sets no analytics or advertising cookies.

3. Customer accounting data

The contents of your QuickBooks company file — customers, invoices, items, and everything else stored there — pass through our cloud gateway only in transit, to serve the specific API request your integration made. That data is not stored at rest by the Service: there is no cache or copy of your company-file contents in our database. We do not use it for any purpose other than serving the request it arrived with, we do not sell it, and we do not use it to train any model.

4. How we use data

We use the data described in Section 2 to operate and secure the Service: to authenticate requests, route them to the right Windows agent, bill your organization, respond to support requests, detect abuse, and maintain the reliability of the API. We do not use it for advertising, and we do not sell it.

5. Legal bases

Where the GDPR or a similar law applies, we process account, organization, and service metadata to perform our contract with you (providing the Service you signed up for), to comply with legal obligations (such as billing records), and based on our legitimate interest in operating a secure and reliable service. We rely on your consent where a specific feature asks for it.

6. Sharing & subprocessors

We share data only with the subprocessors that help us run the Service, and only the data each one needs to do its job. The current list, with what each one handles, is published at tenkeybridge.com/subprocessors. We do not sell personal data or share it for advertising purposes.

7. International transfers

The Service is hosted in the United States. If you access it from outside the US, your data will be transferred to and processed in the US, where data protection laws may differ from those of your country.

8. Retention

We keep account and organization data for as long as your account is active, and delete it within 30 days after the account or organization is closed, or sooner if you ask, by emailing privacy@tenkeybridge.com. Request logs are kept for 30 days in Axiom and then deleted. Billing records are kept as required by applicable tax and accounting law.

9. Security

All traffic to and from the Service travels over TLS. Credentials TenkeyBridge issues to you — API keys, OAuth client secrets, and the access and refresh tokens your applications use to call the API — are stored as hashes, not plaintext. Access to production systems and data is least-privilege. The Windows agent is outbound-only: it dials out to our gateway and never accepts inbound connections, so nothing on the internet can reach your QuickBooks machine directly through it.

10. Your rights

You can ask us to access, correct, delete, or export the personal data we hold about you by emailing privacy@tenkeybridge.com. We will respond within a reasonable time and verify your identity before acting on the request.

11. Cookies

The TenkeyBridge developer portal sets a single session cookie to keep you signed in. We do not set advertising or tracking cookies, and our marketing website sets no cookies at all.

12. Children

The Service is not directed to, and is not intended for use by, anyone under 18 years old. We do not knowingly collect personal data from children.

13. Changes

We may update this policy from time to time. We will post the updated policy here with a new effective date, and for material changes, we will provide notice by email.

14. Contact

For privacy requests, email privacy@tenkeybridge.com. For legal notices, email legal@tenkeybridge.com. For anything else, email hello@tenkeybridge.com.