Heesab Privacy Policy
Effective: June 16, 2026
Heesab is operated by Basha Holdings LLC d/b/a Heesab ("Heesab," "we," "us," or "our"). This Privacy Policy explains how we collect, use, share, and protect information when a business uses Heesab to receive invoice emails, parse invoice documents, train vendor and account mappings, and post approved or trusted routine invoices to QuickBooks Online.
Heesab is intended for United States business use only. It is not intended for consumer, household, children's, or international use.
Contact
Privacy requests: [email protected]
Support requests: [email protected]
Security or incident reports: [email protected]
Mailing address:
Basha Holdings LLC d/b/a Heesab
P.O. Box 39
Nashville, NC 27856
Information We Collect
We collect the information needed to provide the service, including:
- Account and login information, such as user name, email address, password hash, role, tenant access, session metadata, IP address, user agent, and login activity.
- Customer business information, such as business name, tenant slug, inbound email alias, QuickBooks company realm id, workflow settings, vendor mappings, account mappings, auto-post rules, and tenant status.
- Inbound invoice information, such as sender, recipient, subject, message id, received time, email body, invoice attachments, parsed invoice fields, invoice totals, line items, parser confidence, deduplication hashes, and posting status.
- QuickBooks Online information authorized by the customer, such as company information, vendors, chart of accounts, Bill posting data, QuickBooks transaction ids, and related metadata.
- Audit and operational information, such as queue events, approval events, mapping changes, QuickBooks connection events, posting events, errors, support diagnostics, and security logs.
We do not ask customers to send documents unrelated to the agreed invoice workflow. Customers should not forward unrelated sensitive documents unless we have agreed in writing to process that workflow.
How We Use Information
We use information to:
- Receive invoice emails forwarded to Heesab.
- Parse invoices into structured fields.
- Match vendors and accounts.
- Help operators review exceptions and train mappings.
- Decide whether an invoice should stay in review or may auto-post under trusted rules.
- Post approved or trusted routine invoices to QuickBooks Online as Bills.
- Prevent duplicate invoice creation and duplicate QuickBooks posting.
- Maintain audit history for actions taken in customer books.
- Provide support, troubleshoot errors, secure the service, and improve workflow reliability.
QuickBooks Online Authorization
When a customer connects QuickBooks Online, the customer authorizes Heesab through Intuit's OAuth consent flow. For the v1 invoice-to-Bill workflow, Heesab is intended to use the QuickBooks Online Accounting scope. We store QuickBooks OAuth access and refresh tokens encrypted at rest and use them only to provide the connected workflow.
Customers may revoke Heesab's QuickBooks access through Intuit or QuickBooks settings, or by asking Heesab to disconnect the tenant.
AI Processing
Heesab uses AI services, including Anthropic, to parse invoice documents and suggest mappings. We send only the content reasonably needed for the task, such as invoice text or attachment content and relevant QuickBooks vendor or account options.
AI output may be incorrect. Heesab uses review queues, trust settings, amount limits, confidence checks, duplicate checks, pause controls, and audit logs to reduce risk, but customers remain responsible for verifying their QuickBooks records.
How We Share Information
We share information only as needed to provide, secure, support, or legally operate Heesab, including with:
- Intuit and QuickBooks Online, when the customer authorizes a connection.
- Anthropic, for invoice parsing and mapping assistance.
- Infrastructure providers such as Railway, Supabase, and Cloudflare for hosting, database, email routing, and related operations.
- Service providers that help us operate, secure, maintain, or support Heesab.
- Legal, regulatory, or security parties when required by law, legal process, or to protect rights, safety, security, or service integrity.
- A successor entity if Heesab is involved in a merger, acquisition, reorganization, financing, or sale of assets, subject to reasonable confidentiality protections.
We do not sell customer invoice data.
Data Retention
Our current pilot retention targets are:
- Raw invoice attachments and email bodies: generally up to 90 days.
- Parsed invoice records: generally up to 90 days.
- Audit logs: generally at least 90 days and potentially longer when needed to preserve accounting integrity, investigate issues, comply with law, resolve disputes, or maintain immutable accountability records.
- App and server logs: generally up to 90 days.
- QuickBooks tokens: deleted when the account is closed or the QuickBooks connection is disconnected, unless retention is required for legal, security, or dispute reasons.
Backups, provider logs, security records, and immutable audit records may persist longer than the ordinary targets where necessary for security, legal, operational, accounting, or disaster-recovery purposes.
Security
We use technical and organizational safeguards designed for a pilot accounting automation service, including encrypted QuickBooks tokens, password hashes instead of plaintext passwords, HttpOnly session cookies, tenant-scoped access patterns, one-time OAuth state, duplicate prevention, auto-post guardrails, tenant pause controls, and database-enforced audit immutability.
No system can guarantee absolute security. Customers should promptly report suspected unauthorized access, misdirected invoice forwarding, incorrect posting, or token exposure to [email protected].
Customer Controls
Customers may request help to:
- Pause or disable a tenant.
- Disconnect QuickBooks Online authorization.
- Stop forwarding invoice emails to Heesab.
- Correct inaccurate parsed invoice or mapping data.
- Review available invoice and audit history.
- Delete or archive operational data where deletion is appropriate and legally permissible.
Because audit records are designed to preserve accountability for actions taken in customer books, we may retain audit records even after other operational data is deleted or disabled.
Children's Privacy
Heesab is not directed to children and does not knowingly collect personal information from children.
Changes
We may update this Privacy Policy as Heesab changes, as providers change, or as legal requirements change. Material changes will be communicated to active customers when appropriate.