Privacy Policy
themassis (themassis.com) provides Shopify payout reconciliation into QuickBooks Online, with an optional bank feed through Plaid. This policy describes what we collect, why, who we share it with, how long we keep it, how we secure it, and how you can have it deleted. It is written to sit alongside our Information Security Policy and Data Retention and Disposal Policy, which control the operational detail Plaid and other partners expect.
Questions: privacy@themassis.com. Security incidents: security@themassis.com. Support: support@themassis.com.
1. Who we are
Controller / operator: themassis, themassis.com. We process your information to run the product you signed up for. We are not a bank, not Plaid, not Shopify, and not Intuit. Those parties have their own notices. When you connect them, you also agree to their terms.
2. What we collect
We collect only what is required to run your account and prepare books:
- Account data — email, name, role (merchant or accountant), password hash, store domain, session identifiers.
- Shopify payout data — settlements and the components we split (gross, fees, refunds, shipping, tax, adjustments) so we can draft journal entries.
- QuickBooks Online connection tokens — OAuth access and refresh tokens that authorize themassis to read your chart of accounts and post journal entries an accountant approves. Tokens are stored encrypted at rest.
- Optional Plaid bank feed — if you connect a bank, Plaid returns an access token and item id after you authenticate at your institution inside Plaid Link. We store those values encrypted, plus transaction data for the deposit account you selected, solely to match Shopify payouts. We never collect or store your bank username, password, PIN, or MFA codes. Those stay with Plaid and your bank.
- Workpapers — draft and posted journal lines, account mappings, exception tasks, and an audit log of who approved or posted.
- Billing — plan and Stripe customer/subscription ids. Card numbers are handled by Stripe, not stored by themassis.
- Technical logs — IP address, user agent, and auth events, used to secure the service.
3. How we use it
Data is used to authenticate you, connect the services you authorize, prepare balanced journal entries, surface exceptions for accountant review, match deposits when a bank feed is enabled, bill for the product, provide support, and secure the service (fraud, abuse, and incident response).
We do not use your books, payouts, or Plaid End User Data to train unrelated models, to advertise to you, or to build a data product for anyone else. We do not sell personal information, nonpublic personal information, or End User Data.
4. Legal bases (where that concept applies)
- Contract — to provide the service you requested.
- Legitimate interests — to secure the product, keep an audit trail of posting, and improve reliability, balanced against your rights. This is not a basis to keep Plaid tokens after you disconnect.
- Legal obligation — tax, accounting, and lawful requests, and books-and-records retention as described below.
- Consent — optional connections (Plaid) and any cookie that is not strictly necessary.
5. Sharing
We share data only with the services you connect and with processors who host the product under contract:
- Shopify — payout source you connect.
- Intuit QuickBooks Online — ledger you connect; journals post only after human approval.
- Plaid — optional bank connection. Plaid's notices apply to the Link session. We receive tokens and selected-account transactions, not your bank password.
- Stripe — subscription billing.
- Cloud infrastructure and email — hosting, database, backups, transactional mail.
We disclose information if required by law, to prevent fraud or a security incident, or in a merger or sale of the business under confidentiality, with this policy continuing to apply. We do not share data with other merchants. We do not share End User Data with data brokers.
6. Security
We maintain a written information security program approved by senior management. In short:
- TLS 1.2+ in transit; OAuth and Plaid tokens encrypted at rest.
- Role-based access: merchants cannot post; accountants review and post; tenants are isolated.
- HttpOnly sessions, password hashing (scrypt), CSRF protection, login rate limits.
- Passkey (WebAuthn) or authenticator TOTP required on the themassis account before a bank is linked or a Plaid item is disconnected.
- Bank credentials never stored. Plaid items are removed and tokens deleted within 24 hours of disconnect.
- Security Breach involving Plaid data is notified to Plaid within 12 hours at security@plaid.com, and to affected customers without unreasonable delay.
Details: Information Security Policy and the PDF.
7. Retention and disposal
We keep data only for a documented purpose. The schedule (full table in the retention policy):
| Data | Kept | Then |
|---|---|---|
| Bank login credentials | Never stored | — |
| Plaid / Shopify / QBO tokens | While connected | Revoked and deleted within 24 hours of disconnect |
| Plaid transactions used to match deposits | Until match, max 90 days after match (12 months if unmatched) | Secure delete; backups expire within 90 days |
| Payouts, journals, mappings | Account lifetime, then 7 years for books/tax unless you ask us to erase sooner | Secure delete (QuickBooks copies stay in your QBO company) |
| Posting audit log | 7 years | Secure delete |
| Account profile | Account lifetime | Deleted within 30 days of a verified erasure request |
Deletion from production starts a backup-expiry clock of not more than 90 days. Informal “keep it just in case” retention is not allowed. The only reasons to keep data past this schedule are the closed list in the retention policy (legal requirement, dispute, security investigation, or your written request to preserve).
Details: Data Retention and Disposal Policy and the PDF.
8. Your rights and how to delete
Subject to applicable law, you may request access, correction, deletion, a copy of your data, and to opt out of sale or sharing. themassis does not sell or share personal information for cross-context behavioral advertising. We will not deny service, charge a different price, or degrade quality for exercising these rights.
Send a written request to privacy@themassis.com. We will verify it is you, then delete account data and disconnect Shopify, QuickBooks Online, and Plaid so stored tokens are revoked and removed. You can also disconnect those integrations in the app. We will confirm or explain any legally required keep within 30 days of verification.
California residents may also contact us at that address. We do not sell personal information as defined by the CCPA. Authorized agents must provide proof of authority.
9. International transfers
Production systems are hosted in the United States. If you access the service from elsewhere, you understand your information is processed in the US. Processors are bound by contract to protect it.
10. Children
The product is for businesses and their accountants. It is not directed at children under 16. We do not knowingly collect their data.
11. Cookies
Essential cookies run the session (HttpOnly session id and CSRF). We do not use third-party advertising cookies on the app. The marketing site may use only what is needed to serve the pages.
12. Changes
Material changes will be posted on this page with a new effective date. Continued use after the effective date means you accept the update. The current security and retention PDFs are always the versions linked above.
13. Contact
themassis
themassis.com
privacy@themassis.com
security@themassis.com
support@themassis.com
themassis