Worth Doing Well
Privacy Policy
This policy covers the private, commissioned business-intelligence applications Worth Doing Well builds for individual client businesses, including applications that connect to QuickBooks Online and Monday.com. It explains what those applications access, why, and what we do with it.
This is a policy about business data belonging to a commissioning business. It is not the privacy policy for the worthdoingwell.ca website or for coaching services, which are separate.
Who we are
Worth Doing Well, British Columbia, Canada. Contact: brad@worthdoingwell.ca
Whose data this is about
The data we access belongs to the commissioning business. It is that business's own operational record — its jobs, quotes, invoices, and the customer and supplier details attached to them. We access it as a service provider acting on that business's instructions, and the business remains responsible for it.
What we access
Only what the application needs to display. Typically:
- From QuickBooks Online — invoices, estimates, payments, credit notes, customer records, and the reference numbers that tie them to a job. This may include customer names, billing addresses, and amounts.
- From Monday.com — board items representing jobs and quotes, their stage, value, dates, assigned staff, and the free-text fields attached to them.
We do not access payroll records, bank login credentials, or card numbers. We do not request scopes beyond what the application uses.
Read-only in practice
Our applications are built to read. They issue retrieval requests and do not create, amend, or delete records in a connected accounting system.
We state this plainly because it is a limit we impose on our own software rather than one the platform imposes on us: Intuit's QuickBooks Online accounting permission is granted as a combined read-and-write permission, and does not offer a read-only variant. A client can verify our behaviour independently at any time from the audit log inside their own QuickBooks company, which records what any connected application has done.
Why we access it
Solely to present the client's own data back to them — dashboards, pipeline and funnel reporting, and reconciliation between what was quoted and what was invoiced. We do not use it for any other purpose. We do not use it to train machine-learning models. We do not sell, rent, or trade it, and we do not disclose it for advertising or profiling.
Where it is held, and who else touches it
Derived figures are rendered into a dashboard hosted for the client's own use. Access tokens for connected accounts are stored on systems we control and are not shared. The service providers necessarily involved are:
- Intuit (QuickBooks Online) — the source system, under Intuit's own terms.
- Monday.com — the source system for job and quote data, under its own terms.
- Cloudflare — hosting for the dashboard and these pages.
We add no analytics, advertising, or tracking services to client dashboards. These legal pages set no cookies and run no scripts.
How long we keep it
For as long as the engagement runs and the client wants the application working. On request, or when an engagement ends, we revoke stored access tokens and delete the client's data from our systems.
Withdrawing access
A client can disconnect us at any time, without asking us first, from within QuickBooks Online (Apps → Manage or Connected apps) or Monday.com. Access ends immediately when they do. They can also ask us to delete everything we hold, and we will confirm when it is done.
Security
Access tokens are held in configuration that is excluded from version control and never committed to a code repository. Credentials are not shared between clients or across engagements. We collect the narrowest set of data the application needs rather than everything a connection would allow.
Your rights
Canadian federal privacy law (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA) give individuals rights of access and correction over personal information held about them. Where personal information reaches us it does so inside a client business's own records, so a request is normally made to that business, which controls the record. We will assist any client in responding to such a request, and any individual who contacts us directly will be pointed to the right place and helped.
Changes
The current version of this policy is always the one published at this address, and the date above states when it last changed. Material changes are raised with affected clients directly.
Contact
Any question about this policy, or a request to delete data: brad@worthdoingwell.ca