Portal Privacy Policy
Effective 7/28/2026
DeCypher Financials Portal Privacy Policy
This policy explains how DeCypher Financials (“DeCypher”, “we”, “us”) handles information in the DeCypher client portal — the internal application our staff use to manage client work, including the Creator Finances tool that reads accounting data from QuickBooks Online, and related client communication tools such as SMS reminders.
It covers the portal and the client communications it generates (including email and SMS). Our public marketing website is governed by the separate policy published at wedecypher.co/privacy-policy. Where the two overlap, this policy governs the portal and service-related communications.
This policy describes our own practices and is provided for general information only. It is not legal, tax, or accounting advice to you.
Who this policy is about
The portal is not a consumer product and is not open to the public. It is used by authorised DeCypher personnel. Two groups of people are affected by it:
- Our staff, who hold portal accounts.
- Our clients, whose business financial records we process on their behalf as part of the bookkeeping and accounting services they have engaged us to provide.
For client accounting records we act as a service provider to the client. We process those records to deliver the services they have engaged us for, and for no independent purpose of our own.
Information we handle
Staff account information. Name, work email address, the role and tool permissions assigned to the account, and authentication records. Sessions are maintained with a signed, HTTP-only cookie.
Client accounting data from QuickBooks Online. Where a client’s books are connected, we read their profit and loss report and their chart of accounts. In practice this means account names, account classifications, and the monetary totals posted to each account by month. We store the resulting summary so the portal does not have to query QuickBooks on every page view.
Client contact details and communication preferences. Contact information clients provide to us (such as name, email address, phone number, and business details), together with records of their communication preferences and consents (for example, whether they have opted in to receive SMS messages from us).
Enquiries and submissions. Information people voluntarily send us through our website — such as contact details and the figures entered into our tax estimator, consultation bookings, and job applications including any documents attached to them.
We do not use cookies or similar technologies in the portal for advertising, tracking, or profiling. The only cookie the portal sets is the one that keeps a signed-in staff member signed in.
How we use QuickBooks data
This section is deliberately specific, because it is the sensitive part.
We request read-only accounting access. The application does not create, alter, or delete anything in a client’s QuickBooks company file.
We use the data to present each client’s profit and loss — revenue streams, expense categories, operating profit and net profit — to our own staff, and to produce aggregate figures across our client base.
We do not sell, rent, or license QuickBooks data. We do not use it for advertising or marketing. We do not use it to train machine-learning models. We do not disclose one client’s financial information to another client.
Aggregate figures shown in the portal are visible only to authorized DeCypher staff and are never published or shared externally in a form that identifies an individual client.
Access credentials issued by Intuit are encrypted before they are stored and are never exposed to a web browser.
SMS text messaging and related data
We offer optional SMS (text message) communications to clients and prospective clients who consent to receive them.
What we send. We use SMS to send:
- Appointment and meeting reminders
- Document and information requests
- Tax and filing deadline reminders
- Service notifications and occasional updates about our bookkeeping and tax services
Message frequency will vary, with higher activity during tax season.
How you opt in. Clients may opt in to SMS when they:
- Sign our engagement letter and check the SMS consent box, and/or
- Submit another DeCypher form that includes explicit SMS consent text.
By providing a mobile number and giving this consent, the client authorizes us to send SMS messages to that number. Consent is not a condition of receiving services from DeCypher.
What we collect for SMS. For SMS we record:
- The mobile number provided
- The fact and date of consent or opt-out
- Basic information about delivery and replies (for example, that you texted STOP)
Opt-out and support. Clients can opt out at any time by replying STOP to any message we send. They may text HELP for help, or contact us at otavio@wedecypher.co or +1 617 981 4764.
No sensitive information by SMS. We do not request or require Social Security numbers, full bank account numbers, or other highly sensitive financial information via SMS. Clients should not send confidential or sensitive information to us by text.
We do not sell or rent SMS opt-in data or consent records, and we do not share them with third parties for their own marketing purposes. We may share SMS-related data only with service providers that help us send and manage messages, or as required by law or professional standards.
Service providers
We use a small number of third-party providers to operate the portal and related communications. They process information only on our instructions and only to provide their service to us. They are not permitted to use it for their own purposes.
- Vercel — application hosting (United States).
- Google Firebase / Cloud Firestore — authentication and data storage (United States).
- Intuit — the source of the accounting data, accessed with the client company’s authorisation.
- Resend — transactional email.
- Slack — internal notifications to our own team.
- Calendly — consultation scheduling.
- [Your SMS platform] — delivery and management of SMS text messages.
We may also disclose information where we are required to by law, or where it is necessary to establish or defend legal claims.
How we protect it
All traffic to and from the portal is encrypted in transit.
QuickBooks access credentials are encrypted at rest with AES‑256‑GCM, using a key held outside the database.
The database rejects all direct access from browsers. Every read and write goes through our server, which authenticates the request first.
Portal access is per-person and per-tool: a staff member can only open the tools they have been granted. Sessions expire and can be revoked immediately.
The QuickBooks connection holds read-only scope, so a compromise of the portal could not be used to alter a client’s books.
No system is perfectly secure, and we do not claim otherwise. We aim to apply protections appropriate to the sensitivity of financial records.
How long we keep it
We retain client accounting summaries for as long as the client relationship continues and thereafter for as long as we are required to keep records under applicable law and professional standards. Staff account records are kept while the account is active and removed when it is closed.
When a QuickBooks connection is disconnected, we revoke our access credentials with Intuit and delete our copy of them. Previously retrieved summaries are retained under the schedule above unless deletion is requested.
SMS consent records may be retained as long as reasonably necessary to demonstrate compliance with communication and telemarketing laws, even after a client opts out.
Your choices
A client may disconnect our access to their QuickBooks company at any time, either by asking us to do so or from within their own QuickBooks account. Disconnecting stops any further access immediately.
You may ask us what information we hold about you, ask us to correct it, or ask us to delete it. Some information must be retained where law or professional obligations require it, and we will tell you if that applies. Contact us at otavio@wedecypher.co.
Depending on where you live you may have additional rights under laws such as the California Consumer Privacy Act. We do not sell personal information or share it for cross-context behavioral advertising.
Children
The portal is a business tool and is not directed to children. We do not knowingly collect information from anyone under 18 through it.
Changes
If we change this policy we will update the effective date above. Material changes affecting client data will be communicated directly rather than only posted here.
Contact
DeCypher Financials
975 Chestnut Street
otavio@wedecypher.co
+1 617 981 4764
See also our Portal Terms of Use.
