Effective date: October 1, 2026
Ledgerlink MCP is operated by Infinity Financial Inc, operator of Ledgerlink MCP ("Ledgerlink MCP," "we," "us," or "our"). This policy explains how Ledgerlink MCP handles information when bookkeeping firms and their staff use Ledgerlink MCP to connect authorized QuickBooks Online companies to AI tools.
We collect and process:
Ledgerlink MCP requests the QuickBooks Online accounting scope. The current product is read-only. Ledgerlink MCP retrieves authorized accounting data from QuickBooks when a user invokes a tool. The application does not intentionally store QuickBooks API response bodies in its application database. It does store the connection, permission, and audit information described above.
We use information to:
We do not sell personal information or use QuickBooks data for advertising.
We share information only as needed with:
Each customer is responsible for deciding which staff and AI clients may access its connected companies.
Ledgerlink MCP uses encrypted HTTPS connections. QuickBooks refresh tokens are encrypted at rest using AES-256-GCM, and application credentials are stored as protected deployment secrets. Access is checked against firm and company grants on every tool request. Audit records do not intentionally contain QuickBooks response bodies or OAuth tokens.
No system is completely secure. Customers must protect their access codes, accounts, devices, and AI-client credentials and notify us promptly of suspected unauthorized access.
OAuth access tokens are cached temporarily and normally expire from the cache within 45 minutes. Single-use QuickBooks connection links expire after 30 minutes and are invalidated when used. We retain account, company-connection and permission information while the customer account is active. When a QuickBooks company is disconnected, we delete its stored OAuth tokens and clear cached access tokens; the company can no longer be reached until it is connected again. Audit records are kept for 12 months and then deleted automatically. When a customer closes their account, we delete its stored OAuth tokens and account data within 30 days, except audit records, which follow the 12-month schedule.
You can disconnect Ledgerlink MCP from a QuickBooks company through QuickBooks or ask the firm administrator to disable access. You may also ask us to access, correct, export, or delete personal information, subject to legal and security limits. Disconnecting stops future access but may not remove audit records or information we must retain.
Ledgerlink MCP's application runs on Cloudflare's distributed network. Stored application data is hosted in the United States (AWS us-east-1). Information may be processed where our providers operate, subject to their contractual and legal safeguards.
Ledgerlink MCP is a business service and is not directed to children under 13. We do not knowingly collect their personal information.
We may update this policy. We will post the revised policy with a new effective date and give additional notice when required.
Infinity Financial Inc (operator of Ledgerlink MCP)
123 Tice Blvd, Woodcliff Lake, NJ
Email: info@infinityfinancialny.com