VantaSoftVantaSoft

Legal

Privacy Policy

How VantaSoft handles website, service, and connected-account data, including data authorized through QuickBooks Online.

Effective July 21, 2026

1. Scope and who we are

This Privacy Policy explains how VantaSoft, Inc., a California corporation ("VantaSoft," "we," "us," or "our"), collects, uses, discloses, protects, retains, and deletes information through vantasoft.com, VantaSoft Agent Service ("VAS"), and other services that link to this policy (collectively, the "Services").

For website, account, contracting, billing, and direct support data, VantaSoft generally determines why and how the information is used. For business data that a customer connects to VAS or asks us to process, the customer generally determines the purposes of processing and VantaSoft acts as its service provider or processor. Individual users should also review the privacy notices of the business that authorized their use of VAS.

2. Information we collect

The information we collect depends on how you use the Services.

  • Contact and account information: name, business name, role, email address, telephone number, account identifiers, authorized users, preferences, and support communications.
  • Contracting and billing information: order forms, service selections, transaction records, and billing status. A payment processor may collect payment-card details directly. We do not need the full card number to operate VAS.
  • Website and device information: IP address, browser and device attributes, pages viewed, referral information, cookie identifiers, and interaction or diagnostic data.
  • Customer-provided content: prompts, instructions, files, messages, workflow inputs, agent outputs, action history, and other information a customer submits or asks VAS to process.
  • Connected-service data: information and authorization credentials received from services a customer chooses to connect, such as Google Workspace, Salesforce, QuickBooks Online, or other approved systems.

3. Intuit and QuickBooks Online data

If an authorized user connects a QuickBooks Online company, Intuit provides VantaSoft with OAuth authorization tokens, a company identifier, and the QuickBooks data required for the customer-approved VAS workflows. Depending on the approved workflow and permissions, this may include company profile and accounting information; chart of accounts; customers, vendors, and employees; products and services; invoices, bills, payments, and other transactions; reports, balances, and financial summaries; attachments; and related metadata. We refer to this information and information derived from it as "Intuit Data."

VantaSoft does not ask for or store an end user's Intuit password. We access Intuit Data only through Intuit's authorized interfaces and only within the permissions granted by the user.

4. How we use information

We use information to:

  • provide, configure, host, maintain, secure, and support the Services;
  • authenticate connections and carry out customer-approved workflows;
  • retrieve, organize, summarize, reconcile, analyze, or present connected-service data as requested by the customer;
  • create or update records only when the customer has approved that capability and the applicable integration permits it;
  • investigate incidents, prevent fraud or misuse, enforce agreements, and maintain service reliability;
  • respond to support requests and communicate about the Services; and
  • comply with applicable law and valid legal process.

We use Intuit Data only for the functional use of VAS requested by the applicable customer. We do not sell Intuit Data, use it for advertising, share it with another VantaSoft customer, use it for cross-customer benchmarking, or use it to train generalized artificial intelligence or machine-learning models.

5. Artificial intelligence processing

VAS uses artificial intelligence to interpret instructions, select approved tools, and produce requested outputs. When a customer-approved workflow requires it, the minimum information reasonably needed for that workflow may be processed by contracted AI model providers acting on VantaSoft's behalf. VantaSoft does not authorize those providers to use Intuit Data for their own purposes or to train generalized models.

AI output can be incomplete or inaccurate. Customers are responsible for appropriate human review before relying on output or approving actions that affect financial records, legal rights, employment, payments, taxes, or other consequential matters.

6. How we disclose information

We may disclose information only as described below:

  • Service providers: contracted providers that support cloud hosting, storage, AI model processing, security, monitoring, communications, customer support, or payment processing. They may process information only to perform services for VantaSoft and are not permitted to use Intuit Data for their own purposes.
  • Customer-authorized destinations: systems, users, or recipients that the customer directs VAS to interact with as part of an approved workflow.
  • Legal and safety reasons: when reasonably necessary to comply with law or valid legal process, protect rights or safety, investigate fraud or abuse, or enforce our agreements.
  • Business transactions: in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and use restrictions.

We do not give another customer access to a customer's Intuit Data. We do not make Intuit OAuth tokens available to other customers or independent third parties.

7. QuickBooks authorization, disconnection, and deletion

A QuickBooks connection begins only after an authorized user completes Intuit's OAuth authorization flow. The user can disconnect VantaSoft through QuickBooks Online's connected-app settings or can ask us to disconnect the company by emailing hello@vantasoft.com.

After we receive or detect a valid disconnection or deletion request, we revoke or remove active Intuit OAuth credentials promptly and no later than seven days. Unless a shorter period is required, we delete or de-identify Intuit Data from active VAS systems within 30 days after the QuickBooks connection or applicable VAS service ends. Residual copies in protected backups age out under our backup schedule, normally within 90 days.

We may retain limited information longer when required by law, needed to establish or defend legal claims, or necessary for documented security and fraud-prevention purposes. Any retained information remains restricted and is not used for ordinary product operation, advertising, or model training.

8. Other retention

We retain other personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Services, honor customer instructions, maintain business and security records, comply with law, and resolve disputes. Retention periods vary based on the type of information, the customer agreement, operational need, and legal requirements.

9. Security

We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. Safeguards include access controls, encrypted network transport, encryption at rest for production storage, restricted credential handling, software and infrastructure maintenance, and security monitoring appropriate to the Services.

No system can be guaranteed completely secure. Customers must protect their own accounts, credentials, endpoints, and authorized-user access, and should notify us promptly of suspected unauthorized use.

10. Website cookies and analytics

Our public website uses cookies and similar technologies for essential functions, analytics, performance, visitor identification, and marketing. These technologies may be provided by analytics and advertising partners and may associate website activity with device, contact, or professional-profile information. Browser settings, supported opt-out tools, and Global Privacy Control signals can limit some of this activity.

Website advertising and visitor-identification technologies do not receive Intuit Data from VAS, and we do not use Intuit Data for targeted or cross-context behavioral advertising.

11. Privacy rights and choices

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, or to withdraw consent. You may also opt out of marketing email by using the unsubscribe link in the message.

VantaSoft does not sell personal information for money. We do not sell or share Intuit Data for targeted advertising. To submit a privacy request, email hello@vantasoft.com. We may need to verify your identity and authority before completing a request. If VantaSoft processes information on behalf of your employer or another customer, we may direct the request to that customer.

12. International processing

VantaSoft is based in the United States, and information may be processed in the United States and other countries where approved service providers operate. Where required, we use contractual or other lawful safeguards for international transfers.

13. Children

The Services are intended for businesses and authorized adult users. They are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the Services.

14. Changes to this policy

We may update this policy to reflect changes to the Services, law, or our practices. We will post the revised policy here and update the effective date. If a change materially affects how we use connected customer data, we will provide additional notice when reasonably required.

15. Contact us

Questions, privacy requests, and QuickBooks disconnection or deletion requests can be sent to hello@vantasoft.com.

VantaSoft, Inc.
Irvine, California, United States