Accounting connections: privacy
1. Scope
This policy covers the optional accounting connections of RKP POS (EnAffaire for Restaurants and MulliganOS): QuickBooks Online, Sage Accounting, and the bookkeeper’s files. We handle personal information under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). It applies in addition to the privacy policy of the product you use.
2. What we send to your books
One journal entry per business day, containing totals only: sales by category, GST/HST, tips, amounts by payment type, refunds, the day’s total of house-account (member) charges, gift cards sold and redeemed, golf online booking payments, deposits and fees, the total of prepaid online orders, and card processing fees. Each entry is numbered RKP-YYYYMMDD.
No customer, guest, golfer or member names, phone numbers, email addresses or card details are sent to QuickBooks, to Sage or in the files.
3. What we read
QuickBooks Online: your company name and country; your chart of accounts and tax codes (to find accounts such as Undeposited Funds and GST/HST Payable); the journal entries RKP POS itself created (to update a day that changed).
Sage Accounting: the list of businesses your Sage login can reach (once, so you can choose one); your ledger accounts; the journals RKP POS itself created.
We do not read your customers, vendors, invoices, bills, bank data, payroll or reports.
4. What we store, and for how long
| Item | Why | Kept |
|---|---|---|
| QuickBooks company ID, Sage business ID, company name, country | Use and show the right company | While connected, then with the disconnected record |
| Access and refresh tokens | Post on your behalf | While connected; deleted on disconnect, when the provider revokes them, or when you connect another company |
| Each day’s totals as your till sent them | Post or update the day; your bookkeeper’s files | While your RKP POS account is active |
| Per posted day: date, entry ID, a fingerprint (hash) of the totals, status, any error | Never post a day twice; update a changed day; the sync log | While your RKP POS account is active |
| Account mapping (our line → your account ID, number or name) | Post each line where you chose | While your RKP POS account is active |
5. Where it is stored
On our servers rented from Hetzner Online GmbH in Germany, reached through Cloudflare. Information stored outside Canada may be accessible to the authorities of that country under its laws; we protect it with the safeguards described here.
6. Who can see it
Only the people who operate RKP POS at 687441 N.B. Inc., for support and to keep the service running, and anyone you give the bookkeeper link to (daily totals only, until it expires). We do not sell, rent or share your accounting data, and we do not use it for advertising or to train AI models.
7. Security
Access and refresh tokens are encrypted with AES-256-GCM, under a separate key for each provider, kept outside the public web folder and readable only by the application. Application credentials are kept the same way and never in source code. All traffic uses TLS. Tokens and accounting data are never written to logs. A connection can only be started from your own authenticated till.
8. Security incidents
If we learn of unauthorised access to accounting data or tokens, we revoke the affected tokens, notify the affected businesses promptly, report to the Privacy Commissioner of Canada where PIPEDA requires it, and notify Intuit within 24 hours (and Sage as its terms require).
9. Your choices
You can disconnect at any time (till: Back office → Accounting → Disconnect, or from inside QuickBooks or Sage). You can ask us for a copy of what we hold about your connections, or to delete it, at [email protected].
10. Contact
Privacy questions: [email protected] · 687441 N.B. Inc., operating as RKP Atlantic Business Services, 105-69 Cap Bimet Blvd., Grand-Barachois, NB E4P 6X5, Canada.