FinOpHQ — Financial Operations HQ logo

FinOpHQ · Financial Operations HQ

Privacy Policy

Effective Date: July 12, 2026
Last Updated: August 22, 2026

Michael Crews, d/b/a Finophq (“Company,” “we,” “us,” “our”) operates Finophq (the “Service”), a read-only financial analytics application for home-service business owners. The Service works by connecting — only with your authorization — to the business platforms you already use. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

1. Information We Collect

Account information. When you create an account, we collect your email address and authentication credentials via Supabase Auth, our authentication provider. We never store your password in plain text — Supabase handles password hashing and session management on our behalf.

Billing information. If you subscribe to a paid plan, payment is processed by Stripe, Inc. (“Stripe”) on Stripe’s hosted checkout and customer-portal pages. Stripe collects your card details and billing address directly — we never receive or store your card number. We store only a Stripe customer reference and your subscription status (plan, renewal date) so the Service knows your account is active.

Connected platforms. The Service connects only to platforms you explicitly authorize, in three categories:

As the Service adds support for additional platforms in these categories (for example, other field-service CRMs, or payroll and tax platforms), every rule in this section applies to each new connection in exactly the same way.

Rules every connection follows:

Accounting data (currently QuickBooks Online). We access your accounting data through Intuit's OAuth 2.0 authorization flow, strictly under the com.intuit.quickbooks.accounting scope, and only ever with read (GET/query) requests. Depending on which features you use, this may include:

Bank account data (via Plaid). When you choose to connect a bank account, the connection is made through Plaid Inc. (“Plaid”), a regulated financial data network. You authenticate directly with Plaid and your financial institution — your bank username and password are never seen, transmitted through, or stored by us. Through Plaid we receive only:

Bank data is used solely to show you your live balances and to check your books against your actual bank activity. Plaid's own handling of your data is described in Plaid's End User Privacy Policy, and you can review or delete the data Plaid holds about you at my.plaid.com.

Field-service / CRM data (currently Jobber). When you choose to connect a field-service or CRM platform, we access your operational data through that platform's OAuth 2.0 authorization flow, read-only. Depending on which features you use and your plan with that platform, this may include client names and contact details, requests, quotes, jobs and scheduled visits, invoices and payment records, expenses, timesheets, staff lists, and related operational records.

Uploaded data. If you choose to upload data yourself (e.g., a CSV export from a platform we don't yet connect to), we store what you upload — which may include customer names, job/invoice records, and revenue figures — solely to generate the analysis and reports you request. This data is never sold or used for any purpose beyond operating the Service for your account.

How connected data is stored (your dashboard snapshot). When you sync, the Service fetches data from your connected platforms, computes your dashboard, and stores the result as your account's current dashboard snapshot — so your dashboard loads without re-contacting every platform on every visit. Each sync replaces the prior snapshot; we do not keep a history of superseded copies. A platform's data is removed from your stored snapshot when you disconnect that platform, and the entire snapshot is deleted when you delete your account. Separately, the configuration choices you make (e.g., an approved list of add-back accounts, a monthly budget target, or a “reviewed” status on a flagged transaction) are stored so they persist until you change them or delete your account.

Usage data. We may collect standard technical logs (e.g., timestamps of sign-ins, error logs) to operate, secure, and troubleshoot the Service. We do not use third-party advertising trackers or sell usage data.

Website visitors. Our public website (finophq.com) uses Cloudflare Web Analytics, a cookieless, privacy-preserving service that records aggregate page views, referrers, and approximate country. It sets no cookies and does not identify or track individual visitors across sites. This applies to the public website only; the Service itself uses no analytics beyond the technical logs described above.

2. How We Use Your Information

We use the information above solely to:

We do not sell your data, rent it to third parties, or use it for advertising purposes.

3. How We Store and Protect Your Data

No method of storage or transmission is 100% secure, and we cannot guarantee absolute security, but we design and operate the Service to follow current best practices for the categories of data above.

4. Data Sharing

We share your data only with the service providers necessary to operate the Service (our “sub-processors”), currently:

Any additional hosting or infrastructure provider used to operate the Service will be added to this list before it handles user data.

We do not share your data with any other third party except: (a) with your explicit direction, (b) to comply with a legal obligation, or (c) to protect the rights, property, or safety of the Company, our users, or the public.

5. Your Rights and Choices

6. Data Retention

We retain your account and configuration data for as long as your account remains active; each connected platform's encrypted tokens until you disconnect that platform or delete your account; and your dashboard snapshot while your connections are active (each sync replaces it, and it is deleted with your account). Our full Data Retention and Disposal Policy is published on this site. You may request deletion at any time via michael@finophq.com.

7. Children's Privacy

The Service is intended for business owners and is not directed at, and should not be used by, anyone under the age of 18.

8. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email, with the “Last Updated” date above reflecting the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.

9. Our Use of QuickBooks Online Data (Intuit Developer disclosure)

This section exists to satisfy Intuit Developer Platform's disclosure requirements for apps connecting to QuickBooks Online:

10. Contact

Questions about this Privacy Policy, or requests to access, correct, or delete your data, can be sent to michael@finophq.com.