Privacy Policy
Effective date: September 24, 2026
Last updated: September 25, 2026
ScaleUp Solutions LLC, doing business as ScaleUp Solutions ("ScaleUp," "we," "us," or "our"), provides business software for accounting, financial reporting, account reconciliation, and related analysis. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit our website at https://scaleupsolutions.com, use our application at https://app.scaleupsolutions.com, connect a third-party platform, or communicate with us (collectively, the "Services").
"Personal information" means information that identifies, relates to, or can reasonably be linked to an individual, as defined by applicable law. "Customer Data" means information that a business customer or its authorized users submit to the Services, authorize us to retrieve from connected platforms, or generate from that information through the Services. Customer Data may include personal information and confidential business information.
1. Our role and the scope of this policy
Our Services are intended for businesses, finance teams, accountants, fractional CFOs, and other professional users.
For account administration, website operations, communications, security, and similar activities where we determine why and how personal information is processed, ScaleUp generally acts as a controller or business under applicable privacy law.
When we process personal information within Customer Data to provide the Services on a customer's instructions, we generally act as a processor or service provider. If the customer itself processes information for another organization, we may act as a subprocessor. The applicable customer agreement and any data processing agreement govern that processing. This policy does not expand the rights granted to us under those agreements.
If your information appears in the accounting records of a business that uses ScaleUp, that business is generally responsible for deciding how its records are used and responding to your privacy requests. You may contact that business directly. If you contact us, we will help direct your request and provide assistance as required by applicable law and our agreements.
This policy describes ScaleUp's practices. Intuit and other connected platforms have their own privacy policies covering their independent handling of information.
2. Information you provide
Depending on how you use the Services, you or your organization may provide:
- Account and business information: your name, work email address, organization, job title, contact details, account identifiers, and information needed to establish or administer access.
- Customer Data: accounting records, financial statements, transaction details, account balances, reconciliation records, invoices, bills, payments, journal entries, customer and vendor records, and related files or information submitted for supported features.
- Instructions and work product: report settings, account mappings, classifications, reconciliation decisions, comments, and other inputs or outputs associated with your use of the Services.
- Communications: information included in support requests, emails, feedback, demonstrations, or other communications with us.
You should provide information about other individuals only when you have the authority and lawful basis to do so. Avoid including sensitive information in support messages or uploads unless it is necessary for the requested service.
ScaleUp does not currently use a payment processor for this application. Financial transactions obtained from connected platforms are processed as Customer Data for the requested accounting and reporting functions.
3. Information collected automatically
When you visit or use the Services, we may collect information about your device and interactions, including:
- IP address, browser type and version, operating system, device type, and technical identifiers used by the Services or analytics tools.
- Pages and features accessed, referring pages, event timestamps, session information, and interactions with the application.
- Application logs, API request metadata, connection and synchronization status, error messages, performance measurements, and diagnostic information.
- Approximate location inferred from an IP address, if enabled in the relevant analytics configuration.
- Cookie, local storage, and similar technology information, as described in Section 6.
Technical information may become personal information when linked to a person or account. Diagnostic records describe the operation that encountered a problem. Our logging and analytics rules prohibit capturing Intuit OAuth credentials or the contents of QuickBooks records. Operational telemetry must be limited to information needed to identify and troubleshoot the technical event without those contents.
[CONFIRM THE AUTOMATICALLY COLLECTED FIELDS, ANALYTICS EVENTS, DIAGNOSTIC PAYLOADS, AND WHETHER APPROXIMATE LOCATION OR SESSION REPLAY IS COLLECTED.]
4. Connected platforms, including QuickBooks Online
Authorization and information accessed
The Services can receive information from third-party accounting, financial, payroll, CRM, banking, and other business platforms when a supported integration is available and an authorized user connects it. The information received depends on the platform, its available permissions, the permissions you grant, and the features you use. Naming a platform category does not mean that an integration with every provider in that category is currently available.
For QuickBooks Online, you authorize access through Intuit's OAuth process. We access QuickBooks information only within the permissions and scopes granted through that authorization. The OAuth process allows an authorized connection without requiring you to give ScaleUp your Intuit password.
We may collect and store:
- OAuth access tokens and refresh tokens used to establish and maintain authorized connections.
- Integration identifiers and metadata, including QuickBooks company or realm IDs, authorized scopes, token expiration information, connection status, and synchronization records.
- Authorized accounting and financial information, including transactions, account balances, financial statements, customers, vendors, invoices, bills, payments, journal entries, and related records needed for the functions you request.
- Data returned by other supported platforms, which may include business contact, employment, payroll, banking, or similar records when relevant to an enabled integration and authorized feature.
How connected information is used
We use connected-platform information to provide the Services to the customer that authorized access, including preparing reports, supporting reconciliation and transaction analysis, displaying account information, maintaining integrations, diagnosing problems, and carrying out customer instructions. Tokens are used to maintain the authorized connection and perform authorized integration operations.
If a supported feature can send information back to a connected platform, we process and transmit information as directed through that feature and within the authorization granted. An integration's availability does not itself authorize us to initiate unrelated transactions or actions.
Customers retain their rights in their QuickBooks and other Customer Data. Connecting an account does not transfer ownership of that data to ScaleUp. We do not sell Customer Data. Our access to and use of information supplied through Intuit APIs is subject to applicable Intuit developer and API requirements, in addition to applicable law and our customer agreements.
We do not process this information on Intuit's behalf. Our role for business customers is described in Section 1. We do not make one customer's identifiable QuickBooks records available to unrelated customers.
Disconnecting and revoking access
You may revoke ScaleUp's access using the connected platform's available controls. For QuickBooks Online, you may disconnect the application through Intuit's connected-app controls or the disconnect control within ScaleUp at the Connections page, in the menu beside the QuickBooks connection (available to your organization's administrators). You may also request assistance from support@scaleupsolutions.com.
Disconnecting within ScaleUp discards the connection's stored tokens and, where it can, asks Intuit to revoke our authorization for that QuickBooks company. It does not ask while another ScaleUp connection to the same company still relies on that authorization, such as one in another organization or one your organization has archived, and it cannot ask when the stored authorization cannot be used from ScaleUp. When you disconnect, we tell you whether the authorization was revoked, kept for another connection, or could not be revoked from within ScaleUp. Removing ScaleUp through Intuit's connected-app controls ends our authorization for every connection to that company.
When authorization is revoked or a disconnection is completed, we stop using that authorization to access the platform. Disconnecting also stops updates from that connection and hides the information already imported through it; Section 8 describes this and the additional rules for stopping processing of Intuit data. It does not itself delete records in your QuickBooks account or another connected platform.
Treatment of information already imported into ScaleUp is described in Section 8. A disconnection, an account closure, and a request to delete previously imported data are distinct actions. Applicable platform requirements may require deletion or other handling following disconnection, and those requirements take precedence over any more permissive general retention practice described here.
5. How we use information
Subject to the roles and integration limits described above, we use information to:
- Create and administer accounts and provide the features requested by customers.
- Retrieve, organize, analyze, reconcile, transmit, and display authorized Customer Data.
- Generate reports, calculations, proposed classifications, and other requested outputs.
- Maintain integrations, investigate synchronization problems, and provide customer support.
- Send service messages, respond to inquiries, and communicate changes affecting the Services.
- Understand use of the website and application, evaluate performance, and improve usability and reliability.
- Detect misuse, investigate suspicious activity, protect information, and enforce our agreements.
- Maintain necessary business records, meet legal obligations, and establish or defend legal claims.
- Send business or product updates where permitted by law, subject to your communication preferences.
Identifiable connected-platform data is used to deliver and support the customer's authorized functions. General references to improving the Services do not authorize unrelated advertising, independent reuse of customer financial records, or uses prohibited by customer agreements or platform requirements.
If an enabled feature uses artificial intelligence or other automated analysis, information necessary for that feature may be processed to produce the requested output. [CONFIRM WHETHER AI FEATURES ARE ENABLED; IF SO, DESCRIBE THE DATA PROCESSED, ANY ADDITIONAL PROVIDERS, THEIR RETENTION AND TRAINING USE, AND AVAILABLE CONTROLS. OTHERWISE REMOVE THIS PARAGRAPH.]
Aggregated and de-identified information
Where permitted by applicable law, customer agreements, and relevant platform requirements, we may produce aggregated or de-identified statistics to evaluate performance and improve the Services. Such information must not reasonably identify a customer or individual. We will maintain information treated as de-identified in that form, will not attempt to re-identify it except where permitted by law to evaluate de-identification safeguards, and will require any recipient of de-identified information to comply with applicable restrictions on re-identification.
This general permission excludes data obtained through Intuit APIs. Such data remains limited to the customer's authorized functionality and is not reused for separate benchmarking, cross-customer datasets, or independent model training under this policy.
6. Cookies, analytics, and communication choices
Cookies are small files stored by a browser. Similar technologies can store preferences, maintain sessions, or record interactions with a website or application.
We use these technologies, as configured, for functions such as authentication, security, remembering preferences, and understanding use of the Services. Mixpanel and Google Analytics support product and usage analytics. The specific information they receive depends on the events, identifiers, and settings enabled for our Services.
[INSERT THE ACTUAL COOKIE/ANALYTICS DISCLOSURE, INCLUDING TECHNOLOGY CATEGORIES, PURPOSES, PROVIDERS, LIFETIMES OR RETENTION CRITERIA, AND A WORKING CONSENT OR PREFERENCE CONTROL WHERE REQUIRED.]
Where applicable law requires consent for nonessential technologies, we obtain that consent before using them. You may also use browser controls to block or remove cookies, although some features may then stop working. Browser controls do not necessarily manage every analytics technology or apply across different devices.
Our handling of browser Do Not Track signals is: [CONFIRM DO NOT TRACK RESPONSE]. Legally recognized opt-out preference signals, including Global Privacy Control where applicable, are addressed in Section 12.
You may opt out of marketing emails by using the unsubscribe option in the message or contacting support@scaleupsolutions.com. Essential account, security, support, and service communications may continue while needed to provide the Services.
7. When we disclose information
We may disclose information in the following circumstances, subject to applicable law and any restrictions in customer agreements or platform requirements.
Service providers and subprocessors
We use providers to operate and support the Services. The confirmed providers and their general functions are:
| Provider | Function |
|---|---|
| Render.com | Application hosting, infrastructure, and related cloud services. |
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, storage, and related services. |
| Mixpanel | Product usage measurement and analytics. |
| Google Analytics | Website and application usage analytics. |
| Sentry | Error monitoring and diagnostics. |
| Datadog | Logging, observability, diagnostics, and operational monitoring. |
| Better Stack | Logging, uptime, observability, diagnostics, and operational monitoring. |
| Email and business communications. | |
| Postmark | Email delivery and related delivery diagnostics. |
A provider's inclusion does not mean it receives every category of information or all Customer Data. Hosting providers may process information stored or handled by the application; analytics providers receive configured usage information; diagnostic providers receive configured logs and error information; email providers process the information needed for communications and delivery. Actual access depends on the provider's role and configuration.
Providers processing personal information on our behalf are required to handle it for the authorized service and subject to appropriate confidentiality, security, and data protection terms. Intuit data requires written provider protections matching applicable Intuit requirements and law, which we enforce. A provider's own privacy disclosures do not expand its permitted use of Intuit data. Changes in providers or their uses will be reflected in this policy or other notices where required.
Your organization and authorized recipients
An organization that manages your account may administer access and request information associated with its use of the Services. We may disclose Customer Data to users, advisors, client organizations, or other recipients that the customer authorizes, including through requested exports, reports, or integrations. Customers are responsible for choosing authorized recipients and handling information after they export or share it.
Connected platforms
We exchange information with a platform as needed to establish an authorized connection and perform supported functions the customer requests. A provider's independent processing is governed by its own terms and privacy policy.
Professional assistance and legal purposes
Information may be disclosed to professional advisors where needed for legal, accounting, insurance, or business advice and subject to appropriate confidentiality obligations. We may also disclose information when legally required, to respond to valid legal process, to investigate misconduct, or to protect rights, safety, or the security of the Services, as permitted by law.
Business transactions
Information may be disclosed during a proposed or completed merger, financing, acquisition, reorganization, insolvency proceeding, or transfer of business assets. Disclosures remain subject to applicable confidentiality and legal protections. A successor's use of information remains subject to applicable law and the privacy commitments governing the information, unless lawfully changed with required notice or consent.
Other disclosures you authorize
We may disclose information for another purpose when you direct us to do so or provide legally valid consent. We do not sell Customer Data to any of the providers listed above. Additional disclosures about state-law definitions of sale and sharing appear in Section 12.
8. Retention, account closure, and deletion
Specific rule for Intuit data: When a QuickBooks connection is disconnected within ScaleUp, we immediately stop accessing QuickBooks through it and stop using the Intuit-provided data it imported: that data is no longer synchronized, displayed, or included in reports or other outputs. A page already open elsewhere stops showing it the next time it checks with ScaleUp, which it does at least every 30 seconds while it is in view and online. The connection itself stays listed, with its name and the company's home currency, so that it can be reconnected or deleted. If you revoke our access through Intuit's controls instead, the same applies as soon as Intuit confirms the revocation to us. If Intuit does not confirm a revocation to us, for example because the authorization had already expired, you can disconnect the connection within ScaleUp or ask us to do so, with the same effect. When we close an organization's account, at its request or under our Terms, we disconnect or delete its QuickBooks connections as part of closing it.
Intuit-provided data hidden this way is kept, without being used, until the connection is reconnected, which restores it, or until the data is deleted on your request or as described below. On a deletion request from you, including one conveyed through Intuit, we securely delete that data, except records that applicable law requires us to keep and a record of the deletion itself, such as the connection's name (for QuickBooks, the company's name unless the connection was renamed), its organization, who deleted it, and when. Any required retention is restricted to that legal purpose, and the deletion record is used only to account for the deletion. This rule overrides the general retention language below.
We retain information for the time reasonably needed for the purposes described in this policy, subject to customer instructions, contractual commitments, applicable platform requirements, and legal obligations. Relevant considerations include:
| Information | Retention considerations |
|---|---|
| Account and organization information | Whether the account remains active and whether limited records are needed afterward for administration, legal obligations, security, or disputes. |
| Customer Data and generated reports | The requested service, customer instructions, applicable contracts, platform restrictions, and any legally required retention. |
| OAuth tokens and integration metadata | Whether authorization remains valid and the connection is needed; tokens are not used to continue accessing a platform after disconnection or revocation. |
| Logs, diagnostics, and usage information | The period needed to investigate issues, protect the Services, evaluate performance, and satisfy applicable retention limits. |
| Support messages and business communications | The duration of the inquiry or relationship and any limited period needed for follow-up, legal obligations, or disputes. |
| Backups, where maintained | The applicable backup lifecycle and whether limited retention is needed for recovery or legal obligations. |
A connection's stored tokens are deleted as soon as it is disconnected. Disconnecting does not itself delete imported data, which is kept as described above. The operational timeframes for deletion after account closure or an approved deletion request are: [INSERT CUSTOMER DATA DELETION TIMEFRAMES, BACKUP EXPIRATION, AND LIMITED RETENTION EXCEPTIONS].
Once information is no longer needed and retention is not otherwise required or permitted, we delete it or de-identify it in accordance with applicable requirements. Retained copies remain subject to protections and use restrictions. Where immediate removal from a backup is not practical, information is protected from ordinary use until removed through the applicable backup process, subject to legal requirements.
You may request account closure or deletion by contacting support@scaleupsolutions.com. We may need to verify your identity and authority over an organization's data. A deletion request does not necessarily require deletion of records that we must lawfully retain, but it does limit continued use as required by law. If we act on a customer's instructions, we will coordinate with that customer as appropriate. Deletion from ScaleUp does not delete the customer's source records held by a connected platform.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and loss. Safeguards take account of the nature of the information and the risks associated with its processing.
No online service or method of storage can guarantee complete security. You are responsible for safeguarding your account access, managing authorized users, and promptly reporting suspected unauthorized use to support@scaleupsolutions.com.
If a security incident triggers notification obligations under applicable law, a binding customer agreement, or an applicable integration-provider agreement, we will provide the required notifications.
10. International processing and transfers
ScaleUp and its providers may process information in countries other than the country where you are located. Personal information is stored in the United States, whose privacy laws may differ from those of the country where you are located.
Where law requires safeguards or another lawful basis for a transfer, we will make the transfer subject to those requirements. Our applicable transfer arrangements are: [INSERT THE TRANSFER MECHANISMS ACTUALLY USED, SUCH AS AN APPLICABLE ADEQUACY DECISION OR EXECUTED CONTRACTUAL SAFEGUARDS, AND HOW TO OBTAIN DETAILS OR A COPY].
Accepting our Terms or using the Services does not, by itself, substitute for a transfer mechanism required by law. Contact support@scaleupsolutions.com with questions about international transfers.
11. Privacy requests and general choices
Depending on your location, our role, and the law that applies, you may have rights to access or obtain a copy of personal information, correct inaccuracies, request deletion, restrict or object to processing, withdraw consent, or exercise the additional rights described below.
Send requests to support@scaleupsolutions.com. An additional request method, if applicable, is: [INSERT PRIVACY REQUEST FORM OR OTHER REQUIRED REQUEST METHOD]. You may also contact us by mail at the address in Section 15.
We may request information reasonably necessary to verify your identity or an agent's authority when verification is legally permitted or required. We will not require verification for opt-out requests where applicable law prohibits that requirement. We use verification information for handling and protecting the request, not unrelated purposes.
We respond within the time required by applicable law and explain any applicable extension or denial. If a right to appeal applies, you may appeal by contacting support@scaleupsolutions.com and stating that you are appealing a privacy request decision. We will respond and provide information about any further complaint options required by law. You may also complain to the relevant privacy regulator.
We will not unlawfully discriminate or retaliate against you for exercising privacy rights. Some information is necessary to provide requested features, so deleting it, withholding it, or revoking an integration may prevent those features from operating.
12. Additional information for U.S. residents
Where an applicable U.S. state privacy law covers our processing, eligible residents may have rights to know about processing, access or obtain portable copies of information, correct it, delete it, and opt out of certain activities. Depending on the law, opt-out rights may cover sales, sharing for cross-context behavioral advertising, targeted advertising, or profiling used for decisions with legal or similarly significant effects. Some laws also provide rights concerning sensitive information, recipient information, appeals, or authorized agents.
These rights are subject to the law's applicability, exceptions, and our role. A business relationship does not automatically eliminate rights available under California law.
California disclosures
The information described in Sections 2 through 4 may fall within these California categories:
| Category | Examples relevant to the Services |
|---|---|
| Identifiers | Names, email addresses, account identifiers, IP addresses, and identifiers associated with connected records. |
| Personal information in customer records | Business contact details and financial information included in authorized Customer Data. |
| Commercial information | Invoices, bills, payments, transactions, and business purchase or service records. |
| Internet or electronic network activity | Usage events, browser and device information, logs, and interactions with the Services. |
| Approximate geolocation | General location derived from an IP address, if collected under the applicable analytics configuration. |
| Professional or employment information | Job titles and business roles; employment or payroll information if included in an authorized supported feature. |
| Inferences | Classifications or analytical outputs linked to an identifiable person, if generated from authorized records or usage. |
| Sensitive personal information | Account access credentials and, where present in authorized records, financial account access information, government identifiers, or other information classified as sensitive by law. |
[CONFIRM WHICH CATEGORIES WERE ACTUALLY COLLECTED AND DISCLOSED DURING THE PRECEDING 12 MONTHS, THE RECIPIENT CATEGORIES FOR EACH, AND ANY ADDITIONAL CATEGORIES PRESENT IN CUSTOMER RECORDS. REMOVE INAPPLICABLE ROWS AND COMPLETE THE REQUIRED HISTORICAL DISCLOSURE.]
Sources include you, your organization or its authorized users, connected platforms, and your interactions with the Services. Purposes, recipient categories, and retention criteria are described in Sections 5, 7, and 8. Sensitive information is handled for authorized functions, security, and other legally permitted purposes. Where a right to limit additional uses applies, you may exercise it through our privacy request methods.
We do not sell Customer Data. State laws may define a sale more broadly than an exchange for money, and California separately regulates sharing for cross-context behavioral advertising. Whether website or usage analytics fall within those definitions depends on the actual configuration and contractual restrictions.
[INSERT AN AFFIRMATIVE DISCLOSURE OF WHETHER PERSONAL INFORMATION IS SOLD, SHARED FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING, OR USED FOR TARGETED ADVERTISING; COVER THE PRECEDING 12 MONTHS, RELEVANT CATEGORIES AND RECIPIENTS, AND REQUIRED OPT-OUT CONTROLS.]
Where required, we honor legally recognized opt-out preference signals, including Global Privacy Control. Our applicable signal handling and available privacy controls are: [INSERT VERIFIED GLOBAL PRIVACY CONTROL BEHAVIOR AND ANY REQUIRED DO NOT SELL OR SHARE / YOUR PRIVACY CHOICES LINK].
California residents may submit applicable requests through Section 11, including requests made by an authorized agent with appropriate authority. If applicable, California residents may also request information about disclosures for another business's direct marketing under California's Shine the Light law. We do not knowingly sell or share personal information of individuals under 16.
13. Additional information for the EEA and United Kingdom
Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, the following supplements the other sections of this policy.
Legal bases
When ScaleUp acts as a controller, our legal basis depends on the activity:
- Contract: processing necessary to enter into or perform a contract with you as an individual. A contract with your employer alone does not make this the basis for all processing of your information.
- Legitimate interests: operating and securing the Services, administering business relationships, responding to inquiries, improving reliability and usability, and protecting legal rights, after considering your interests and rights. This does not replace consent where consent is required.
- Consent: optional processing for which consent is required, such as certain cookies or marketing activities. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligation: processing needed to comply with a legal obligation that applies to us.
When we act as a processor, the customer determines the applicable legal basis and provides instructions under the relevant agreement. We do not independently select a new purpose for that Customer Data through this policy.
Your rights
Subject to applicable conditions, you may request access, correction, erasure, restriction, or portability of your personal information, and may object to processing based on legitimate interests. You may object to direct marketing at any time. You may also withdraw consent and lodge a complaint with your local supervisory authority or, in the United Kingdom, the Information Commissioner's Office.
Requests can be submitted under Section 11. We respond within the period required by the applicable law. Providing information is generally voluntary, but information needed to establish an account, authorize a connection, or provide a requested feature may be necessary to supply that feature.
Automated decisions and local contacts
The Services provide analytical tools intended for review by authorized users. [CONFIRM WHETHER SCALEUP MAKES ANY SOLELY AUTOMATED DECISIONS ABOUT INDIVIDUALS WITH LEGAL OR SIMILARLY SIGNIFICANT EFFECTS. STATE THE ACTUAL PRACTICE AND, IF APPLICABLE, EXPLAIN THE LOGIC, SIGNIFICANCE, CONSEQUENCES, AND AVAILABLE RIGHTS.]
ScaleUp's contact details are in Section 15. Additional contacts, where legally required: [INSERT EEA/UK REPRESENTATIVE AND DATA PROTECTION OFFICER CONTACT DETAILS IF REQUIRED; OTHERWISE REMOVE THIS SENTENCE].
14. Children and changes to this policy
The Services are for professional users aged 18 or older and are not directed to children. We do not knowingly solicit personal information directly from children under 13. If you believe a child has provided information directly to us inappropriately, contact us so we can investigate and take appropriate action. Information about individuals under 18 that appears in a customer's authorized business records is handled under the customer's instructions and applicable law, rather than used to offer accounts to children.
We may update this policy when our practices or legal obligations change. We will revise the date above and provide additional notice for material changes where appropriate or legally required. Where a change requires consent, we will obtain it before applying the change to the relevant processing. Posting a revised policy alone does not replace required consent.
15. Contact us
ScaleUp Solutions LLC
Mailing address: 10613 Pointe View Drive, Austin, TX 78738
Privacy inquiries and requests: support@scaleupsolutions.com
Support and integration assistance: support@scaleupsolutions.com
Website: https://scaleupsolutions.com