Privacy Policy
Bindery is a Salesforce to QuickBooks Online integration published by Kshiprex Private Limited ("Kshiprex", "we", "us"), a company incorporated in India, CIN [CIN], registered office [registered address], India.
This policy explains what data Bindery handles, where it is processed, how long it is retained and the choices available to you. It covers three things: the Bindery managed package installed in your Salesforce org, the Bindery relay service operated by Kshiprex on Amazon Web Services, and this website.
1. Our role and yours
You, the subscribing organisation, are the controller (data fiduciary) of the business records Bindery synchronises. Kshiprex acts as a processor, handling those records only on your instructions and only as needed to run the syncs you configure and approve. For your account, billing and support data, Kshiprex acts as controller.
2. What Bindery handles
2.1 Business records in transit
Bindery reads and writes customers, invoices, estimates, payments, credit memos and refund receipts, together with the fields you map. These records pass through the relay in memory for the duration of an API call. They are not written to any Kshiprex database, queue or object store, and no copy is retained after the call completes. Bindery does not hold your CRM or accounting records.
2.2 Credentials
The OAuth access and refresh tokens that authorise calls to QuickBooks Online are stored inside your own Salesforce org, using Salesforce Named Credentials and External Credentials. Kshiprex does not hold or have access to your tokens. The relay holds only Kshiprex's own Intuit application client credentials, kept in AWS Secrets Manager and encrypted with keys managed in AWS KMS.
2.3 Operational telemetry
The relay records request metadata for monitoring and troubleshooting: timestamp, Salesforce organisation ID, QuickBooks Online company (realm) ID, entity type, record identifiers, HTTP status, latency and error codes. Diagnostics are scrubbed of record payloads before they are written, so amounts, names, addresses and line item detail are not logged.
2.4 Sync history and audit trail
Dry run previews, approval records and before and after snapshots are stored as records in your own Salesforce org. They stay under your control and follow your org's own retention settings. Kshiprex holds no copy.
2.5 Account, billing and support data
Name, business email address, company name, the Salesforce org and QuickBooks Online companies covered by your subscription, billing records, and the content of any support request you send us.
2.6 This website
bindery.in serves static pages. It sets no cookies, runs no analytics, advertising or session recording scripts, and loads no third party resources. Standard web server logs record IP address, request path and user agent, and are retained for 30 days.
3. QuickBooks Online permissions we request
Bindery requests the com.intuit.quickbooks.accounting scope, which is the minimum needed to read
and write the entities listed above. Bindery does not request payroll or payments scopes, and does not
access data outside the QuickBooks Online companies you connect.
4. How we use data
Only to operate, support, secure and maintain the service. In practice that means running the syncs you have configured and approved, diagnosing failures, monitoring service health and capacity, billing your subscription, and meeting our legal obligations.
We do not sell data. We do not share it for advertising. We do not use your business records, or any data derived from them, to train machine learning or artificial intelligence models.
5. How long we keep it
| Business records in transit | Not retained. Held in memory only for the duration of the API call. |
|---|---|
| Operational telemetry | 30 days, then deleted automatically. |
| OAuth tokens | Held in your Salesforce org. Revoked at Intuit when you disconnect, and removed from the org when the managed package is uninstalled. |
| Sync history and snapshots | Held in your Salesforce org under your own retention settings. |
| Support correspondence | 24 months from the close of the request. |
| Account and billing records | For the life of the subscription, then as long as required by Indian tax and company law. |
| Website server logs | 30 days. |
6. Disconnecting, and asking us to delete data
You can disconnect a QuickBooks Online company at any time, from either side:
- In Bindery: Bindery Setup, then Connections, then Disconnect against the company. This calls Intuit's token revocation endpoint and the connection stops immediately.
- In QuickBooks Online: the Apps tab, then My Apps, then Disconnect. Access tokens are invalidated and Bindery can no longer make calls for that company.
Uninstalling the managed package removes Bindery's objects and stored credentials from your Salesforce org. Records Bindery has already written into QuickBooks Online or Salesforce belong to you and are left untouched.
To ask us to delete the account, billing or support data Kshiprex holds, write to aman@kshiprex.com. We respond within 30 days, and will tell you if law requires us to keep any part of it.
7. Sub-processors
| Amazon Web Services | Relay hosting (Lambda, API Gateway, DynamoDB), secret storage and key management. Region: [AWS region]. |
|---|---|
| [Payment processor] | Subscription billing. Handles billing contact and payment details; no business records. |
| [Email and helpdesk provider] | Support correspondence and service notifications. |
We will post notice on this page before adding a sub-processor that handles subscriber data, and will email subscribers at the same time.
8. International transfers
Kshiprex operates from India and the relay runs in the [AWS region] region. Where the data involved includes personal data of residents of the European Economic Area, the United Kingdom or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses and, for the United Kingdom, the International Data Transfer Addendum. Both form part of our Data Processing Addendum, available on request from aman@kshiprex.com.
9. Security
- All traffic between Salesforce, the relay and QuickBooks Online uses TLS 1.2 or higher.
- The relay is stateless and holds no subscriber financial data at rest.
- Application secrets are held in AWS Secrets Manager and encrypted with AWS KMS managed keys.
- Access to production is limited to named personnel, over multi-factor authentication, on a least-privilege basis.
- The relay is subject to periodic dynamic application security testing, and the managed package is reviewed under the Salesforce AppExchange security review process.
10. If something goes wrong
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours, telling you what we know, what is affected and what we are doing about it, and will support any notification you are required to make.
If you believe you have found a vulnerability in Bindery or the relay, please write to aman@kshiprex.com. Please do not run intrusive tests against production without written agreement.
11. Your rights
Depending on where you are, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, and complain to a supervisory authority. Residents of India have equivalent rights under the Digital Personal Data Protection Act, 2023. Residents of California may ask what personal information we collect and disclose, and may request its deletion; we do not sell personal information.
Write to aman@kshiprex.com to exercise any of these. Where Kshiprex acts as processor, requests from your own customers and employees should come to you, and we will help you answer them.
12. Grievance Officer (India)
For the purposes of the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules:
[Name], Grievance Officer
Kshiprex Private Limited, [registered address], India
aman@kshiprex.com
13. Children
Bindery is a business application sold to organisations. It is not directed at individuals under 18 and we do not knowingly collect their personal data.
14. Changes to this policy
We will post any change here with a new version number and effective date. For a material change affecting how subscriber data is handled, we will email subscribers at least 30 days before it takes effect.
15. Contact
Kshiprex Private Limited, [registered address], India.
aman@kshiprex.com