Privacy Policy
This Privacy Policy explains how Avahi Inc. ("we", "us") handles information in connection with the Restaurant Reporting application (the "Application"), a private reporting tool operated on behalf of The Kitchen CPAs.
The Application connects to QuickBooks Online to prepare financial reports and KPI dashboards for restaurant businesses. This policy covers the data accessed through that connection.
1. Who we are
The Application is operated by Avahi Inc., with its principal place of business at 1390 Market St, San Francisco, California 94103, United States, on behalf of The Kitchen CPAs.
The Kitchen CPAs is the accounting firm that engages us to prepare these reports and holds the client relationship with each restaurant business. Data accessed through the Application is held within cloud infrastructure controlled by The Kitchen CPAs, as described in section 4.
For any question about this policy or about data held in the Application, contact dev.tarun@avahi.ai.
2. What data we access
With your authorization, the Application reads accounting data from your QuickBooks Online company file. Depending on the reports being prepared, this may include:
- Company profile information, including business name, address and fiscal year settings
- Chart of accounts and account balances
- Invoices, bills, payments, credit memos and journal entries
- Customer and vendor records associated with those transactions
- Items, classes, departments and locations used to categorize transactions
- Profit and loss, balance sheet and other standard report data
We also record technical information necessary to operate the connection, such as the QuickBooks company identifier, authorization tokens, and timestamps of data refreshes.
What we do not access
- We do not request or store your QuickBooks username or password. Authorization happens through Intuit's own sign-in process.
- We do not access payroll detail, banking credentials, or payment card numbers.
- We do not collect personal information about your customers beyond what already appears on accounting records in your books.
3. How we obtain access, and how you control it
Access is granted by you through Intuit's OAuth 2.0 authorization process. You sign in to QuickBooks directly with Intuit and choose to connect the Application. We receive an authorization token, not your credentials.
The Application requests read access to accounting data. It does not create, modify or delete records in your QuickBooks company file.
You may withdraw access at any time. See section 9.
4. Where data is stored
Data read from QuickBooks is stored in a private Amazon Web Services (AWS) environment controlled by The Kitchen CPAs, located in the United States.
| Control | Measure |
|---|---|
| Encryption in transit | TLS 1.2 or higher for all connections, including to the Intuit API |
| Encryption at rest | AWS-managed encryption using AWS Key Management Service |
| Credential storage | Authorization tokens held in AWS Secrets Manager, never in application code or configuration files |
| Access control | Least-privilege AWS identity policies; access limited to named personnel who need it to operate the service |
| Separation | Data is stored separately per QuickBooks company, so one client's records are not combined with another's |
| Logging | Access to the environment is logged and retained for review |
5. How we use the data
We use QuickBooks data only to deliver the reporting service. Specifically, to:
- Calculate the KPIs and report sections agreed with The Kitchen CPAs
- Display those results in a dashboard, by client and reporting period
- Generate downloadable CSV and XLSX report files
- Produce plain-language written summaries of the calculated figures
- Maintain the QuickBooks connection and notify us when it needs to be renewed
- Diagnose errors and verify the accuracy of calculated results
We do not use your data for advertising, for profiling, or for any purpose unrelated to preparing your reports.
6. Automated summaries
The Application produces short written explanations of the figures in your reports. These are generated using Amazon Bedrock, an Amazon Web Services offering invoked from the same AWS account and region described in section 4.
- Your data is processed by AWS within that region and is not shared with the providers of the underlying models.
- Your data is not used to train or improve any machine learning model.
- Summaries are based only on figures already calculated from your QuickBooks data.
These summaries describe what the numbers show. They are informational only and are not accounting, tax, or financial advice. Section 6 of the Terms of Service covers this in more detail.
7. Who can see your data
Access is limited to:
- Authorized staff at The Kitchen CPAs, who prepare and review your reports
- A small number of named technical personnel at Avahi Inc. who operate and maintain the Application
- Amazon Web Services, as the infrastructure provider hosting the environment
- Intuit, as the source system you have authorized us to connect to
We do not sell your data. We do not share it with advertisers, data brokers, or any other third party. We may disclose data if required to do so by law, or to protect against fraud or a security incident.
8. How long we keep it
We retain QuickBooks data for as long as the Application is in use for your business, so that historical reporting periods remain available.
If the connection is disconnected, or the engagement ends, we delete the stored data within 90 days unless a longer period is required by law or has been separately agreed with The Kitchen CPAs. Authorization tokens are revoked and deleted promptly on disconnection.
Routine system backups may persist for a short additional period and are deleted on their normal cycle.
9. Disconnecting and deleting your data
You can end the connection at any time:
- In QuickBooks Online, open the Apps section, find this Application, and select Disconnect
- Or email dev.tarun@avahi.ai and ask us to disconnect it for you
Disconnecting stops all further access to your QuickBooks data immediately.
To have stored data deleted sooner than the period in section 8, email dev.tarun@avahi.ai. We will confirm the request, complete deletion within 30 days, and write to confirm when it is done.
10. Your rights
Depending on where you are located, you may have the right to request a copy of the data we hold about your business, ask for corrections, ask for deletion, or object to certain processing.
To exercise any of these, email dev.tarun@avahi.ai. We will respond within 30 days. We may need to verify your authority over the QuickBooks company file before acting on a request.
11. Children
The Application is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18.
12. Security incidents
If we become aware of unauthorized access to data held in the Application, we will notify The Kitchen CPAs and any affected business without undue delay, and will describe what happened and what we are doing about it.
13. Changes to this policy
We may update this policy as the Application changes. The effective date at the top will be updated. Where a change materially affects how your data is handled, we will notify The Kitchen CPAs before it takes effect.
14. Contact
Avahi Inc.
1390 Market St
San Francisco, California 94103
United States
Email: dev.tarun@avahi.ai or shruti.parate@avahi.ai