Legal
Security
Effective July 27, 2026 · Last updated July 27, 2026
Balance Sheep holds a connection to two of the most sensitive systems a small business runs: its shop and its accounting file. This page sets out how that connection is protected. It expands on Section 7 of our Privacy Policy, which remains the governing document.
1. How we connect to your accounts
Connections to Etsy and QuickBooks Online are made through each platform's official API using OAuth. You authorise Balance Sheep on their site, not ours.
- We never see or store your Etsy password.
- We never see or store your Intuit password.
- We hold an access token instead, and that token is stored encrypted at rest.
- You can revoke our access at any time from your Etsy account settings or your Intuit account. Revoking access stops all further syncing.
- When you cancel, we revoke our own access tokens to Etsy and Intuit.
Entries we have already written into your QuickBooks company are yours and stay there.
2. Encryption
- All traffic is encrypted in transit (TLS/HTTPS).
- Etsy and Intuit access tokens are stored encrypted at rest.
- Account passwords are stored as salted hashes — we never store your password in readable form, and we cannot recover it, only reset it.
3. Account access
- Sign-in is limited to one active session per account.
- Access to production systems is restricted to authorised personnel.
- You are responsible for keeping your credentials confidential and for activity under your account. Tell us promptly if you suspect unauthorised access.
4. What we access, and what we don't
We request only the data the sync actually needs: your shop details, listings and order or receipt data; the buyer information attached to those orders where your bookkeeping requires it; and payment account ledger entries so payouts can be reconciled. In QuickBooks we create and update the sales receipts, customers, items and accounts needed to post that activity.
We do not see or store full card numbers — billing details are collected and held by our payment processor. We do not contact your buyers, and we do not use their information for any independent purpose.
We do not sell your data. We do not use your data — or your buyers' data — for advertising, profiling, or training. We do not use Etsy data for any purpose other than providing the Service to you, as required by the Etsy API Terms of Use.
5. Where your data is held
We share data only with the providers needed to run the Service:
| Provider | Purpose | Data involved |
|---|---|---|
| InMotion Hosting (USA) | Application and database hosting, and transactional email (password resets, alerts) | All Service data |
| Stripe | Subscription billing | Name, email, payment details (held by them, not us) |
Some providers store data in the United States. Where data leaves Canada, it remains subject to our Privacy Policy and to contracts with those providers, but may be accessible to authorities under the laws of those jurisdictions.
6. Retention and deletion
- While your account is active we keep the data needed to run the sync and its audit trail. Etsy data is cached only as permitted by the Etsy API Terms of Use.
- When you cancel, we delete your synced data and connections within 30 days.
- Backups are purged on a rolling basis within 35 days.
- You can email us to request deletion sooner, or a copy of the personal information we hold about you. We respond within 30 days as required by PIPEDA.
- We may retain minimal records, such as invoices, where tax and legal compliance requires it.
7. Cookies
We use only the cookies necessary to operate the Service (session and sign-in). We do not use third-party advertising or tracking cookies.
8. If something goes wrong
No system is perfectly secure. If a breach creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
Because the Service depends on Etsy's and Intuit's APIs, outages or changes on their side can affect syncing. Those platforms remain governed by their own terms.
9. Reporting a security issue
If you believe you have found a vulnerability, email support@balancesheep.net with enough detail to reproduce it. Please give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly. We will acknowledge your report and keep you updated.
10. Your responsibilities
Security is shared. The Service automates data entry based on the rules you configure, so you (or your accountant) remain responsible for reviewing the results and for the accuracy of your financial records, tax filings and remittances. Keep your Balance Sheep, Etsy and Intuit credentials secure, and verify your account mappings and tax settings — especially in your first billing periods.
11. Contact
Balance Sheep is operated by Cygnova, a general partnership registered in Ontario, Canada (BIN 1001690173).
- Mail: 1366 Fribourg Street, Embrun, Ontario K0A 1W0, Canada
- Email: support@balancesheep.net
The term 'Etsy' is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy. QuickBooks and Intuit are trademarks of Intuit Inc. Balance Sheep is not affiliated with, or endorsed by, Etsy, Inc. or Intuit Inc.