Skip to content
Privacy policy

How anfa handles your data.

Plain language about what we collect, why, and how to make it stop. Last updated September 17, 2026.

Who we are

anfa (“getanfa”, “we”) provides finance operations support and QuickConnect, a service that gives you a read-only link between your QuickBooks Online company and the tools you choose, such as spreadsheets and AI assistants. This policy covers the getanfa.com website and the QuickConnect service. Contact: adnan@getanfa.com.

What we collect

Information you send us

When you email us, book a call, or request early access, we receive what you choose to share: typically your name, work email, company and a description of your needs. We use it to respond and to run the engagement you asked about.

QuickConnect connection data

When you connect a QuickBooks Online company, Intuit sends us an access token and a refresh token for that company together with its QuickBooks company identifier. We store the tokens encrypted, the company identifier, the company name, a hashed copy of the API key we issue to you, and timestamps of when the connection was created, refreshed and last used. We never see or store your Intuit password.

Report data

Reports and records are retrieved from QuickBooks only when you, or a tool acting with your API key, ask for them. They are passed through to that request and are not stored by QuickConnect.

Website and service logs

The website is static and sets no tracking cookies. QuickConnect uses one short-lived cookie during the connect flow to protect against forged requests; it expires within ten minutes. Our hosting provider records aggregate request metrics. We have disabled per-request logs that would retain request URLs.

How we use it

  • To operate QuickConnect: refreshing tokens, retrieving the reports you request, and keeping the connection working.
  • To deliver the finance services you engage us for.
  • To secure the service, for example detecting misuse of an API key.
  • To communicate with you about the service or your engagement.

We do not sell your data and we do not use your financial data for advertising.

Who else is involved

  • Intuit operates QuickBooks Online and the sign-in you use to authorise the connection, under Intuit’s own terms and privacy policy.
  • Cloudflare hosts the website and QuickConnect, including the encrypted connection store.
  • Tools you connect. When you point a spreadsheet, an AI assistant or another application at your QuickConnect key, the report data you request is delivered to that tool and becomes subject to that provider’s terms. You decide which tools to connect.
  • Our team. People working for anfa, including contractors, may handle your information under confidentiality obligations to deliver the services you engage us for.

We may also disclose information where the law requires it or to protect the rights and safety of anfa, our clients or others.

Security

QuickBooks tokens are encrypted at rest with a key held separately from the database. API keys are stored only as one-way hashes. All traffic uses HTTPS. QuickConnect only ever reads from QuickBooks; it contains no code path that creates, changes or deletes records in your books. Treat your API key like a password: anyone holding it can read the connected company’s reports.

Retention and deletion

Connection data is kept for as long as the connection is active. When you disconnect, whether from inside QuickBooks or through the service, the tokens are revoked with Intuit and the connection record is deleted. Correspondence and engagement records are kept for as long as needed to serve you and to meet our legal and accounting obligations. You can ask us to delete information we hold about you by emailing adnan@getanfa.com.

Your choices

  • Disconnect at any time from QuickBooks (Apps → My apps) or by asking us. The link stops working immediately.
  • Reconnect to replace your API key if you believe it has been exposed.
  • Ask us what we hold about you, to correct it, or to delete it. We honour the rights available to you under applicable law.

Children

Our services are for businesses and are not directed at children under 16. We do not knowingly collect information from them.

Changes

We will post any changes to this policy on this page and update the date at the top. Material changes affecting connected companies will also be communicated by email where we have an address for you.

Contact

Questions or requests: adnan@getanfa.com.