Advisacor

PRIVACY POLICY

Privacy Policy

Last updated: July 19, 2026 · Effective: July 19, 2026

Wiseman Financial Technologies, LLC, a Virginia limited liability company ("Advisacor," "we," "our," or "us"), operates the Advisacor™ platform available at www.advisacor.com (the "Platform"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights and choices available to you.

By using the Platform you consent to the practices described in this Privacy Policy. If you do not agree, do not use the Platform. This Privacy Policy is incorporated by reference into our Terms of Service.

1. Who This Policy Covers

This Privacy Policy applies to (a) visitors to our public website, (b) users who sign up for the Platform, (c) authorized users of a subscribing organization (accounting firms, bookkeeping firms, business owners, and their invited team members), and (d) individuals whose data is contained in accounting records connected to the Platform by a subscribing organization.

2. Information We Collect

2.1 Information you provide directly

  • Account information: name, email address, password (hashed), organization name, role, phone number (optional).
  • Billing information: handled by Stripe, Inc. We do not store payment card numbers on our systems. We retain billing metadata (subscription tier, invoice history, billing address) provided by Stripe.
  • Support communications: content of support tickets, chat messages, and emails sent to us.
  • Marketing communications: email address and name you submit through waitlist or contact forms.

2.2 Information collected from connected accounting systems

When an authorized user of your organization connects a QuickBooks Online ("QBO") company to Advisacor, we request read-only access via Intuit's OAuth 2.0 authorization flow. With that access we retrieve, on your organization's behalf:

  • Trial balance and general ledger entries
  • Chart of accounts
  • Company profile (legal name, EIN, address, fiscal year end, currency)
  • Customers, vendors, and employees list (names and identifiers only; not payroll)
  • Invoices, bills, journal entries, deposits, and other accounting transactions necessary to generate financial reviews

We use the com.intuit.quickbooks.accounting scope only. We do not request the payroll, payments, or OpenID scopes. We do not modify data in your QBO company through the standard Review Assist and Continuous Intelligence tiers. Write-back automation, if enabled under a higher-tier subscription, is performed only with explicit user approval on a per-action basis.

2.3 Information collected automatically

  • Usage data: pages viewed, features used, timestamps, actions taken. Used to operate, secure, and improve the Platform.
  • Device and log data: IP address, browser type, operating system, device identifiers, referring URLs, and error logs.
  • Cookies and similar technologies: see Section 8 (Cookies).

3. How We Use Information

  • Provide the Platform: generate financial reviews, findings memos, executive briefings, and other outputs requested by your organization.
  • AI-generated outputs: we use large language models (currently Anthropic Claude via AWS Bedrock) to analyze accounting data and produce human-readable narratives. See Section 7 (AI and Automated Processing).
  • Operate and secure: authenticate users, enforce entitlements, detect fraud, prevent abuse, monitor performance, and respond to security incidents.
  • Support and communicate: respond to inquiries, deliver service notifications, send transactional emails, and — with your consent — send marketing emails.
  • Billing: process subscriptions, invoices, refunds, and tax reporting.
  • Legal and compliance: comply with law, respond to lawful requests, protect rights, enforce our Terms.
  • Improve the Platform: aggregate usage patterns to improve reliability, add features, and correct defects. See Section 4 for our commitment on your data.

4. What We Do NOT Do With Your Data

  • We do not sell, rent, or lease personal information.
  • We do not use your QuickBooks Online data to train machine learning models — ours or any third party's.
  • We do not share individually identifiable QBO data with any third party except the sub-processors listed in Section 6 and only to the extent necessary to deliver the Platform.
  • We do not advertise on the Platform and do not share data with advertising networks.

5. When We Share Information

We share information only in these circumstances:

  • With sub-processors that perform services on our behalf (Section 6). Sub-processors are contractually bound to confidentiality and to use data only as instructed by us.
  • With your organization: if you are an invited team member of a subscribing organization, your activity within the Platform is visible to your organization's administrator.
  • For legal reasons: to comply with law, valid legal process, government requests; to enforce our Terms; to detect or prevent fraud or security incidents; to protect our or others' rights, property, or safety.
  • Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to the acquirer honoring this Privacy Policy.
  • With your consent for any other purpose.

6. Sub-processors

We rely on the following sub-processors. This list is current as of the "Last updated" date above. Material changes will be announced in-app or by email at least thirty (30) days before they take effect.

  • Supabase Inc. — application database (PostgreSQL), authentication, and storage. Hosted in the United States. Encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Vercel Inc. — application hosting, CDN, and edge network. United States regions.
  • Stripe, Inc. — subscription billing and payment processing. PCI DSS Level 1 certified.
  • Amazon Web Services, Inc. (AWS Bedrock) — AI/LLM inference (Anthropic Claude models). Content is not used to train foundation models per AWS Bedrock's data usage terms.
  • Intuit Inc. — QuickBooks Online API provider. Governed by your separate agreement with Intuit and Intuit's privacy policy.
  • Resend, Inc. — transactional email delivery.
  • GitHub, Inc. (Microsoft Corporation) — source-code and internal engineering artifacts. No customer QBO data.

7. AI and Automated Processing

The Platform uses generative AI models (currently Anthropic Claude, delivered via AWS Bedrock) to analyze connected accounting data and produce narratives, memos, and recommendations. Important properties of our AI usage:

  • No training on your data: we send prompts and receive completions. Inputs and outputs are not used by AWS or Anthropic to train foundation models.
  • Human review recommended: AI-generated outputs are drafts. You are responsible for reviewing and validating outputs before relying on them for financial reporting, tax, audit, or advisory decisions.
  • No automated decisions with legal effect: Advisacor does not make automated decisions that produce legal or similarly significant effects on individuals within the meaning of GDPR Article 22 or comparable laws.

8. Data Retention and Deletion

  • During your subscription: we retain your data for as long as you maintain an active Advisacor subscription.
  • After subscription cancellation: we retain your customer data for thirty (30) days as a grace period, then permanently and irrevocably delete it via automated cascade deletion across all customer-scoped tables. During this grace period you may reactivate your subscription to restore access with no data loss. Reactivation cancels the scheduled purge automatically.
  • Notification: we email the firm owner immediately upon cancellation with the exact date of scheduled deletion, and again upon reactivation to confirm restoration.
  • Customer-initiated deletion: you may request immediate permanent deletion at any time by emailing support@advisacor.com or from your account settings. Customer-initiated deletion requires multi-factor authentication step-up and email confirmation. Once confirmed, deletion begins within one hour and is complete within twenty-four (24) hours.
  • Audit trail: we retain an append-only audit log of all deletion events (schedule date, execution date, tables purged, actor) for compliance purposes. This audit log contains no customer accounting data — only deletion metadata. Retention period for the audit log is seven (7) years.
  • Legal hold: if we receive a subpoena, court order, or other lawful compulsion requiring data preservation, we will apply a legal hold that prevents automated deletion. You will be notified unless notification is legally prohibited.
  • Support and audit logs: operational logs (error records, intuit_tid, request traces) are retained for ninety (90) days for troubleshooting.
  • Backups: data may persist in encrypted backups for up to ninety (90) days after deletion from active systems.

9. Security

We use industry-standard administrative, technical, and physical safeguards, including:

  • Encryption at rest (AES-256) and in transit (TLS 1.2 or higher)
  • Row-level security in our application database
  • Multi-factor authentication for all administrative access
  • Principle of least privilege for internal access to production systems
  • Audit logging of privileged actions
  • Regular security review of dependencies and third-party sub-processors
  • OAuth 2.0 for all external system connections; we never receive or store QuickBooks Online passwords

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at mwiseman@advisacor.com.

10. Cookies and Similar Technologies

We use three categories of cookies:

  • Strictly necessary: authentication (Supabase session JWT), CSRF tokens, OAuth state for QuickBooks connection, tier and entitlement gates. These cannot be disabled; without them the Platform cannot function.
  • Functional: user interface preferences, brand mode selections, dismissed banners.
  • Analytics: we do not currently deploy analytics cookies. If we adopt them, we will update this policy and re-prompt for consent through the cookie banner.

You can manage your cookie preferences at any time through the "Cookie preferences" link in our website footer. Strictly necessary cookies cannot be disabled while you use the authenticated portions of the Platform.

11. Your Privacy Rights

11.1 California residents (CCPA / CPRA)

You have the right to (a) know what personal information we collect and how we use it, (b) request deletion of your personal information, (c) opt out of sale or sharing of personal information (we do not sell or share personal information as those terms are defined by California law), (d) correct inaccurate personal information, and (e) limit our use of sensitive personal information. To exercise these rights, email mwiseman@advisacor.com. We will verify your identity before fulfilling requests and will not discriminate against you for exercising these rights.

11.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)

If you are located in the EEA, UK, or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, portability, and objection. Where processing is based on consent, you may withdraw consent at any time. You have the right to lodge a complaint with your local supervisory authority. Our legal basis for processing is one or more of: performance of contract, legitimate interests (operating and securing the Platform), consent (marketing communications and analytics cookies where applicable), and legal obligation.

Where we transfer personal data out of the EEA, UK, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism required by law.

Important limitation: the Platform is designed for use by organizations located in the United States. We do not currently market to consumers in the EEA, UK, or Switzerland. If you are located in a jurisdiction where the Platform is not offered, do not sign up.

11.3 Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other US states with comprehensive privacy laws have similar rights. Email mwiseman@advisacor.com to exercise them.

12. Children

The Platform is not directed to children under thirteen (13). We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.

13. International Data Transfers

We are based in the United States. Data you provide is processed in the United States. If you access the Platform from outside the United States, you consent to the transfer of your information to the United States, which may have data-protection laws different from those in your jurisdiction.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by email (if we have your address on file) and by posting a notice in-app or on our website at least thirty (30) days before the change takes effect. Continued use of the Platform after the effective date constitutes acceptance of the revised Privacy Policy.

15. Contact Us

For questions, requests, or complaints regarding this Privacy Policy or our data practices, contact:

Wiseman Financial Technologies, LLC
Attn: Privacy
2023 South Stewart Ave
Covington, VA 24426
Email: mwiseman@advisacor.com