Heesab
Back to dashboard

Heesab Privacy Policy

Effective: June 16, 2026

Heesab is operated by Basha Holdings LLC d/b/a Heesab ("Heesab," "we," "us," or "our"). This Privacy Policy explains how we collect, use, share, and protect information when a business uses Heesab to receive invoice emails, parse invoice documents, train vendor and account mappings, and post approved or trusted routine invoices to QuickBooks Online.

Heesab is intended for United States business use only. It is not intended for consumer, household, children's, or international use.

Contact

Privacy requests: [email protected]

Support requests: [email protected]

Security or incident reports: [email protected]

Mailing address:

Basha Holdings LLC d/b/a Heesab

P.O. Box 39

Nashville, NC 27856

Information We Collect

We collect the information needed to provide the service, including:

We do not ask customers to send documents unrelated to the agreed invoice workflow. Customers should not forward unrelated sensitive documents unless we have agreed in writing to process that workflow.

How We Use Information

We use information to:

QuickBooks Online Authorization

When a customer connects QuickBooks Online, the customer authorizes Heesab through Intuit's OAuth consent flow. For the v1 invoice-to-Bill workflow, Heesab is intended to use the QuickBooks Online Accounting scope. We store QuickBooks OAuth access and refresh tokens encrypted at rest and use them only to provide the connected workflow.

Customers may revoke Heesab's QuickBooks access through Intuit or QuickBooks settings, or by asking Heesab to disconnect the tenant.

AI Processing

Heesab uses AI services, including Anthropic, to parse invoice documents and suggest mappings. We send only the content reasonably needed for the task, such as invoice text or attachment content and relevant QuickBooks vendor or account options.

AI output may be incorrect. Heesab uses review queues, trust settings, amount limits, confidence checks, duplicate checks, pause controls, and audit logs to reduce risk, but customers remain responsible for verifying their QuickBooks records.

How We Share Information

We share information only as needed to provide, secure, support, or legally operate Heesab, including with:

We do not sell customer invoice data.

Data Retention

Our current pilot retention targets are:

Backups, provider logs, security records, and immutable audit records may persist longer than the ordinary targets where necessary for security, legal, operational, accounting, or disaster-recovery purposes.

Security

We use technical and organizational safeguards designed for a pilot accounting automation service, including encrypted QuickBooks tokens, password hashes instead of plaintext passwords, HttpOnly session cookies, tenant-scoped access patterns, one-time OAuth state, duplicate prevention, auto-post guardrails, tenant pause controls, and database-enforced audit immutability.

No system can guarantee absolute security. Customers should promptly report suspected unauthorized access, misdirected invoice forwarding, incorrect posting, or token exposure to [email protected].

Customer Controls

Customers may request help to:

Because audit records are designed to preserve accountability for actions taken in customer books, we may retain audit records even after other operational data is deleted or disabled.

Children's Privacy

Heesab is not directed to children and does not knowingly collect personal information from children.

Changes

We may update this Privacy Policy as Heesab changes, as providers change, or as legal requirements change. Material changes will be communicated to active customers when appropriate.