Effective date: June 24, 2026
Publisher: Monarch Wave (“we,” “us,” “our”)
Contact: [email protected]
Website: https://monarchwave.com/
This Privacy Policy explains how the MFS QuickBooks Sync application (“the Application,” “the plugin”) handles information when it is used to connect a WooCommerce/WordPress store to a QuickBooks Online company.
- ABOUT THE APPLICATION (SELF-HOSTED MODEL)
MFS QuickBooks Sync is a WordPress plugin that you install and run on your own web server, alongside your own WooCommerce store. It is not a hosted (“software-as-a-service”) product. All processing happens on your own server, and all data the Application reads or stores remains in your own WordPress database and your own QuickBooks Online company.
We do not operate a cloud service that receives, stores, or has access to your store data or your QuickBooks data. Except where you contract with us to operate your store on your behalf, your data is never transmitted to Monarch Wave’s servers. The only external service the Application communicates with is Intuit/QuickBooks Online, using credentials you supply and an account you authorize.
- INFORMATION THE APPLICATION ACCESSES
2.1 From your QuickBooks Online company (via the Intuit API)
- Your QuickBooks company identifier (“realm ID”) and company name, for display and to confirm the correct company is connected.
- Your chart of accounts (account names, IDs, types, and balances), used to let you map accounts and to display reconciliation/clearing-account drift.
- References to existing vendors and previously created entries, used solely to avoid creating duplicate records.
The Application writes the following into your QuickBooks company:
- Aggregate daily journal entries (sales, tax, tender, and cost-of-goods totals) — no per-customer or per-order detail.
- Purchase orders and bills for your inventory purchases.
- Vendor records and payout checks/journal entries, which include the business name of the distributor or the name of the consignment payee.
The Application requests only the QuickBooks “Accounting” (com.intuit.quickbooks.accounting) permission scope. It does not request or access your Intuit identity/profile (OpenID), payroll, or payments-processing data.
2.2 From your WooCommerce/WordPress store
To build the aggregate accounting entries, the Application reads order, payment, refund, purchase-order, inventory-cost, gift-card, and cash-drawer records already stored in your WordPress database. This data stays on your server.
2.3 What the Application does NOT send to QuickBooks
The Application is designed for data minimization. It never transmits to QuickBooks:
- Customer names, email addresses, phone numbers, or postal addresses;
- Payment-card or other payment-instrument data;
- Product serial numbers, firearm descriptions, or any regulatory/FFL records;
- Individual order line detail or product catalog detail.
QuickBooks receives only aggregated financial totals plus the vendor and consignment-payee business records described in Section 2.1.
- HOW INFORMATION IS USED
Information is used solely to keep your QuickBooks Online books in sync with your store’s sales, purchasing, and inventory activity. It is not used for advertising, profiling, resale, or any purpose unrelated to that synchronization, and it is not sold or shared with any third party.
- STORAGE AND SECURITY
- Your QuickBooks OAuth access token, refresh token, and client secret are stored only in your own WordPress database, encrypted at rest (libsodium authenticated encryption, with an AES-256-GCM fallback).
- These secrets are never displayed back in the interface, never written to logs, and never included in diagnostic exports; logging routines redact all credentials and tokens.
- The Application communicates with Intuit only over encrypted HTTPS/TLS connections.
- The Application exposes no public webhooks and no public web endpoints; the only inbound request it handles is Intuit’s OAuth redirect, which is restricted to authenticated administrators and protected against cross-site request forgery.
- Access to the Application’s settings and data within WordPress is restricted to administrators holding the “manage WooCommerce” capability.
Because the Application is self-hosted, the overall security of the data also depends on the security of the server and WordPress installation it runs on, which is controlled by you (or your hosting provider).
- THIRD PARTIES
The only third party to which the Application connects is Intuit Inc. (QuickBooks Online), and only the data described in Section 2.1 is exchanged with it, under your authorization. Intuit’s handling of that data is governed by Intuit’s own privacy policy. The Application integrates no analytics, advertising, or tracking services.
- DATA RETENTION AND DELETION
- Synchronization logs are automatically purged after 30 days.
- The Application’s accounting ledger tables (the records of which entries were posted) are retained for as long as the Application is installed, because they are what prevent duplicate postings into QuickBooks.
- You can disconnect from QuickBooks at any time from the Application’s settings; disconnecting revokes the token with Intuit and permanently deletes the stored tokens and client secret from your database.
- Uninstalling the Application always deletes the stored QuickBooks tokens and secret. An explicit “delete all data on uninstall” option is provided if you also wish to remove the Application’s local ledger and settings.
- Uninstalling or disconnecting never deletes, voids, or alters anything inside your QuickBooks company.
- YOUR CHOICES
You control the connection. You choose whether to connect, which QuickBooks company to authorize, when to pause synchronization, and when to disconnect. You may revoke the Application’s access at any time from within QuickBooks Online (Apps) or from the Application’s settings.
- CHILDREN’S PRIVACY
The Application is a business accounting tool and is not directed to children under 13, and it does not knowingly process any data from children.
- CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Effective date” above and posting the revised policy at this URL.
- CONTACT
Questions about this Privacy Policy or the Application’s data handling:
Monarch Wave — [email protected]