Off-nav resource · Legal
Foes Conduit Privacy Policy
What Conduit reads out of your accounting system, where it puts it, what Foes keeps afterwards, and how you make it stop. Written to be read, not to be survived.
Scope of this policy
This policy covers Foes Conduit, the connector service operated by Foes Inc. It covers data Foes handles while operating Conduit for a client. It does not cover the Foes marketing website, which has its own privacy policy, and it does not cover what a client does with data once that data sits in the client's own systems.
Conduit moves a client's accounting data from QuickBooks Online into a data warehouse the client owns. It is built so that client business data comes to rest only in that client-owned warehouse and not inside Foes.
Who is responsible for the information
Foes Inc., 36 Toronto Street, Suite 960, Toronto, Ontario, Canada, operates Conduit and is responsible for the operational state described in this policy.
For the accounting data that passes through Conduit, the client is the organization that decides what is collected and why. Foes handles that data on the client's instructions, for the purpose set out in the engagement, and for nothing else.
What Conduit accesses
When you authorize Conduit against a QuickBooks Online company, it is granted read access to that company's accounting data. Access is granted by you, on Intuit's own OAuth consent screen, which shows what is being requested before you approve it. That grant is the legal basis on which Foes reads anything, alongside your engagement with Foes.
Records Conduit reads
The company profile, chart of accounts, customers, vendors, employees as they appear in accounting records, items and services, invoices, estimates, sales receipts, credit memos, bills, bill payments, purchases, payments, deposits, journal entries, and the change data capture feed Intuit provides so that deletions in QuickBooks can be reflected downstream.
Personal information inside those records
Those records contain personal information, because accounting records do. Customer and vendor entries typically carry a name, a billing address, an email address and a phone number. Transactions carry amounts, dates, descriptions and memo text that a person typed. Foes does not seek that information for its own sake and does not use it for anything beyond moving it to your warehouse, but it is inside the data being moved and this policy treats it as personal information.
What Conduit does not access
Conduit does not request write access, and cannot create, alter or delete anything in your books. It does not request payroll scopes or payments scopes. It never receives your QuickBooks or Intuit sign-in credentials, because authorization happens on Intuit's own sign-in screen and returns a token, not a password.
Why Conduit accesses it
To deliver the service the client engaged Foes for: landing that client's own accounting data in that client's own warehouse on a schedule, so the client can report on it, model it, or combine it with other systems using tools Foes has nothing to do with. There is no secondary purpose.
Foes does not use client accounting data to build products, to benchmark one client against another, to train machine learning or AI models, for advertising, or for any analysis Foes performs for itself. Foes does not sell client data and does not share it for anyone else's marketing.
Where the data goes
Into a data warehouse the client owns. That is a Supabase project or a Microsoft Azure database, in an account belonging to the client, under a contract between the client and that provider. Foes writes to it and, where the engagement says so, administers it, but the account and the data in it are the client's.
On the way, records pass through the Conduit runner in memory over encrypted connections. They are not written to disk on Foes infrastructure, not queued in a Foes datastore, and not copied into any Foes-owned analytics system. Traffic to Intuit and to destination warehouses is over TLS.
What Foes retains
Foes retains no client business data at rest. The only state Conduit keeps on the Foes side is operational, and it is deliberately narrow.
- Connection records. The QuickBooks company identifier, the realm ID, which client it belongs to, and when it was connected.
- Sync cursors. Timestamps and change tokens marking how far each entity type has been synced, so the next run reads only what changed.
- Entity mappings. Source record identifiers mapped to landed rows, so re-running a window updates rather than duplicates. These are identifiers, not field values.
- Run logs. Start and end times, which entity types ran, how many records were read and written, and any error codes or messages returned by the source or the destination. Where a specific record fails, the log holds its identifier so the failure can be investigated. Logs are written to hold identifiers and counts rather than accounting field values, and Foes treats a field value appearing in a third-party error message as a defect to be fixed.
No invoice amounts, customer names, addresses, memo text or other accounting content is stored in that operational state.
Credentials
The OAuth refresh token for each client connection is held in Foes' 1Password vaults, scoped per client, and is resolved into the connector process at the moment a run executes. It is not stored in Conduit's database, not written into configuration files, not committed to source control, and not printed into logs. Tokens are referenced by name in code and in logs, never by value. A run for one client physically holds no credential that can reach another client's data.
Who else is involved
Operating Conduit means data touches a small number of other providers.
- Intuit Inc. The source of the data, under your own agreement with Intuit.
- The client's warehouse provider, Supabase or Microsoft Azure, in the client's own account and under the client's own contract with that provider.
- 1Password, for custody of the OAuth refresh tokens described above.
- The infrastructure provider hosting the Conduit runner and its operational state store, which holds cursors, mappings and run logs, and no client business data.
These are the providers involved in Conduit. They are not the same as the sub-processors listed in the Foes website privacy policy, which covers a marketing site rather than this service. Foes does not give client accounting data to anyone else, and does not disclose it except where required by law, in which case Foes will tell the affected client unless legally prohibited from doing so.
Where processing happens
Foes operates from Canada. Client warehouses are hosted in the region the client selects with their own provider, which for some clients is inside Canada and for others is the United States or elsewhere. Some providers involved in operating the service process data in the United States. Data held by a provider in another country is subject to that country's laws, including lawful access by its authorities.
How long we keep it
Client business data is not kept by Foes at all, so there is nothing to age out. What the client keeps in the client's own warehouse is the client's to retain or delete on whatever schedule the client decides.
Operational state, meaning cursors, mappings, connection records and run logs, is kept for the life of the engagement because the service cannot run correctly without it, and for a limited period after the engagement ends so that questions about past runs can be answered. It is deleted on written request, subject to any record retention obligation that applies to Foes.
Security
Access to Conduit's infrastructure and to client credentials is limited to the Foes personnel who operate the service. QuickBooks access is read only and scoped to accounting data, so the worst case for a client's books is disclosure, not alteration. Credentials are held in 1Password and resolved at execution time rather than sitting in the environment. Client connections are isolated from each other by credential scope. Secret scanning runs in the code pipeline to keep credentials out of source control. Connections to source systems and destinations use TLS.
No arrangement removes risk entirely. Foes makes no certification claim on this page.
Security incidents
If Foes becomes aware of a security incident affecting a client's data handled through Conduit, Foes will notify that client without undue delay, describe what is known, and say what is being done about it.
Your choices and rights
You can revoke Conduit's access to your QuickBooks company at any time, from inside QuickBooks Online, without asking Foes. That stops all further reading immediately, the next scheduled run cannot authenticate, and nothing further is written to your warehouse from that source. See disconnecting for what stops and what stays.
You can ask Foes what operational state exists for your connections, ask for it to be corrected, or ask for it to be deleted, by writing to hello@foes.co.
Where an individual whose personal information appears inside a client's accounting records wants access, correction or deletion, the right place to go is the client organization whose books those are, because they hold the record and Foes holds no copy. If such a request reaches Foes directly, Foes will pass it to the relevant client rather than acting on it alone, and will tell the individual that it has done so.
Children
Conduit is a business service. It is not offered to individuals and is not directed at children.
Changes to this policy
Foes may update this policy. Material changes will be communicated to clients with an active connection by email to the contact on the engagement, before they take effect. The effective date at the top of this page shows when it last changed.
Contact us
Privacy questions, data requests and complaints go to hello@foes.co. A partner reads it. If you are not satisfied with how Foes has handled a privacy matter, you may also raise it with the Office of the Privacy Commissioner of Canada.
Foes Inc., 36 Toronto Street, Suite 960, Toronto, Ontario, Canada.
Foes Inc. is not affiliated with, endorsed by, or sponsored by Intuit Inc. QuickBooks and QuickBooks Online are trademarks of Intuit Inc.