Legal

Privacy Policy

What financial information CountCore accesses, why it is processed, who else receives it, and how the Client withdraws access.

Last updated 28 August 2026

1. Scope and controller

This policy describes how CountCore LLC (“CountCore”) collects, processes and retains information in connection with countcore.com and the CountCore application. It applies to the firms and entities that subscribe to the service (each a “Client”) and to the individuals authorised to use a Client’s workspace.

In respect of a Client’s financial records, CountCore acts as a processor on the Client’s instructions. In respect of account and billing information, CountCore acts as a controller.

2. Information accessed from connected systems

CountCore accesses financial records only through connections the Client grants and may withdraw. CountCore does not request or hold the Client’s passwords to any third-party system.

  • QuickBooks Online. The Client authorises access and separately invites CountCore as an accountant user. CountCore accesses the chart of accounts, transactions, bank and credit card registers, invoices, bills, customers, vendors and reports. Accountant access additionally permits the posting of corrections; no correction is posted without a person approving it.
  • Other systems the Client connects.Where the Client operates a card or bill-payment system, a practice system holding money on behalf of its own clients, or a payroll system, CountCore accesses the transactions, balances and payroll entries required to reconcile those systems against the Client’s books. Each is connected by the Client and may be disconnected by the Client.

3. Information collected directly

CountCore collects the Client’s firm name, and the name and business e-mail address of each individual authorised to use the workspace, together with a password which is stored only as a cryptographic hash. Payment is processed by Stripe; CountCore does not receive or store card numbers.

The application records the actions taken within it, and by whom, including synchronisations, corrections, reviews and approvals. This record forms part of the service.

4. Purpose and basis of processing

Information is processed to provide the accounting and reporting services described in the Terms of Service, to operate and secure the application, and to administer billing. Processing of a Client’s financial records is carried out on the Client’s instructions under that agreement. Information is not sold, and is not used for advertising or for profiling unrelated to the service.

5. Automated processing

The service is substantially automated. Transactions are categorised, records are reconciled against one another, and exceptions are identified by software rather than by a person reading every line. This is the service the Client is buying and not a hidden practice.

Automated processing produces findings; it does not make decisions about a Client and it does not alter a Client’s records on its own. Every correction is queued for a licensed Certified Public Accountant to review and for the Client to approve. No decision producing a legal or similarly significant effect on any individual is made by automated means alone.

Client Data is not used to train models made available to any other party.

6. Processors

CountCore engages the following processors, each for a defined purpose:

  • Intuit — the source of the accounting records accessed by the service
  • Stripe — payment and subscription processing
  • Vercel — application hosting, and page-view measurement on the public site
  • Neon — database hosting, in the United States

Page-view measurement is limited to the public marketing pages. It sets no cookies, does not track individuals between sites, and is not operated on any page within the application. Information is otherwise disclosed only to personnel of the Client, or where disclosure is required by law or by an order of a competent authority.

7. No sale or sharing of personal information

CountCore does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are used in United States state privacy laws. CountCore does not disclose personal information to any party for that party’s own marketing purposes.

A Client’s financial records are treated as sensitive information and are processed only for the purposes described in clause 4.

8. Retention

Information is retained for the duration of the engagement and for seven years thereafter, reflecting the retention obligations applicable to accounting records. A Client may request earlier deletion, and CountCore will delete what it is not required by law to retain.

9. Withdrawal of access

Access may be withdrawn by the Client at any time. It does not require CountCore’s cooperation and no notice period applies.

  • In QuickBooks Online: Settings, then Manage users, then Accountants, then remove CountCore.
  • In any other connected system: remove the CountCore user from that system’s people or permissions settings.
  • In the application: disconnect the source under Settings, then Connections.

The Client’s records remain in the Client’s own accounting systems, which CountCore reads from and does not replace. A Client may request deletion of its CountCore workspace, subject to clause 8.

10. Security

The handling of connections, credentials and access is described on the security page.

11. Rights and requests

A Client, or an individual whose information CountCore holds, may request access to that information, its correction, or its deletion, and may object to or restrict its processing, to the extent provided by applicable law. Requests may be submitted through the contact form, which requires no account, and are acknowledged within the period required by the applicable law.

CountCore will take reasonable steps to verify the identity of a person making a request, and the authority of anyone making one on another’s behalf, before acting on it. A request to delete or disclose information is refused where identity cannot be established, because acting on an unverified request is itself a disclosure to whoever sent it.

Where CountCore acts as a processor on a Client’s instructions, a request received from that Client’s own customer is referred to the Client.

12. Where information is processed

Information is processed and stored in the United States. CountCore does not transfer Client Data outside the United States, and does not engage a processor that does so for the purposes of this service.

13. Children

The service is provided to businesses and is not directed to children. CountCore does not knowingly collect information from anyone under the age of sixteen. Where CountCore becomes aware that it holds such information, it will delete it.

14. Amendments

Where this policy is amended in a manner that affects what CountCore accesses or to whom it is disclosed, CountCore shall notify the users of the Client’s workspace before the amendment takes effect.