BPPBusiness Plans Plus
TermsPrivacy

BPP HQ Legal

Privacy Policy

Business Plans Plus LLC operates BPP HQ, a private business reporting and operations application used by authorized BPP team members.

Effective date: August 21, 2026

This policy explains the information BPP HQ processes, why it is processed, how it is protected, and the choices available to authorized users.

1. Information BPP HQ processes

BPP HQ may process:

  • Identity information used for access control, including an authorized user's business email address and authentication metadata.
  • QuickBooks Online financial reports, including Profit and Loss, Balance Sheet, Cash Flow, and Aged Receivables data.
  • Operational data from approved BPP systems, including HubSpot, Monday.com, GitHub, and BPP's private workspace.
  • Connection credentials and tokens required to retrieve approved data from those systems.
  • Refresh history, timestamps, source-health information, and technical logs used to operate and secure the application.

BPP HQ does not use the QuickBooks Payments API and is not designed to collect payment card numbers, card security codes, or online banking passwords.

2. How information is used

BPP uses this information to:

  • Produce internal financial and operating reports.
  • Monitor business performance, client delivery, sales activity, and source freshness.
  • Preserve point-in-time reporting history.
  • Troubleshoot failed refreshes and protect the accuracy of the most recent successful snapshot.
  • Secure the application and restrict access to approved individuals.

BPP does not sell information processed through BPP HQ or use it for third-party advertising.

3. QuickBooks Online access

BPP HQ requests the com.intuit.quickbooks.accounting scope to retrieve accounting reports for BPP's own QuickBooks Online company. BPP HQ's application boundary is read-only. It does not expose a route that creates, changes, or deletes QuickBooks accounting transactions.

The QuickBooks connection may be revoked through Intuit or disconnected by BPP. Disconnecting stops future retrieval. BPP may retain historical financial reports when required for internal business records, accounting support, security, or legal obligations.

4. How information is stored and protected

BPP HQ is hosted using Cloudflare services. Access to the application is protected by Cloudflare Access and Microsoft identity authentication. Authorized identities are individually approved.

Source snapshots and refresh metadata may be stored in Cloudflare R2 and D1. Rotating QuickBooks refresh tokens are encrypted before storage. Credentials are stored as protected Cloudflare secrets or encrypted records and are not committed to BPP's source repositories.

BPP applies access controls, encrypted transmission, private source repositories, and separation between staging and production environments. No system can be guaranteed completely secure, but BPP uses controls appropriate for the sensitivity and limited internal purpose of the application.

5. Sharing and service providers

BPP may share information with service providers only as needed to operate BPP HQ, including:

  • Intuit, for QuickBooks Online authorization and report retrieval.
  • Cloudflare, for hosting, access protection, encrypted secret storage, databases, object storage, and scheduled processing.
  • Microsoft, for authorized-user authentication.
  • Other approved source-system providers when BPP enables their connectors.

BPP does not authorize these providers to use BPP HQ data for BPP's advertising purposes. Each provider's handling of information is also governed by its own terms and privacy practices.

6. Retention and deletion

BPP retains connection information, report snapshots, and technical logs only for internal operating history, security, accounting support, legal obligations, and troubleshooting. Retention periods may differ by record type.

An authorized user may request disconnection or deletion of information that is not required for accounting, legal, security, or recordkeeping obligations. BPP will revoke or remove active connection credentials when the integration is permanently discontinued. Some information may remain in protected backups or historical business records until the applicable retention period ends.

7. Authorized-user choices

Authorized users may:

  • Ask what information BPP HQ processes about them.
  • Request correction of inaccurate identity or access information.
  • Request removal of their BPP HQ access.
  • Request disconnection of an approved source integration.
  • Request deletion where BPP has no legal or operational reason to retain the information.

8. Changes to this policy

BPP may update this policy as BPP HQ, its data sources, or applicable requirements change. The effective date will be updated when a revised policy is published.

9. Contact

Business Plans Plus LLC
Temple Terrace, Florida, United States
Email: admin@businessplansplus.co
© 2026 Business Plans Plus LLCTerms   Privacy