Privacy Policy

Effective date: August 5, 2026 · Last updated: August 16, 2026 · Acore Technology (“Acore”, “we”, “us”)

What Acore Business Check does

Acore Business Check is a financial and operational assessment service for small businesses. With your authorization, it reads sales and expense transactions and financial statements from your accounting system (such as QuickBooks Online), then builds a private financial workspace and business-check report.

Information we collect

  • Account information you provide when you sign up, including your name and email address. Supabase Auth processes your password, confirmation and recovery tokens, session identifiers, and related security metadata to create and protect your account. Acore does not store your plaintext password.
  • Intake information you provide on a call: company name, contact name and email, industry, team size, the tools your team uses, and business priorities.
  • Accounting data, only after you explicitly connect your accounting system through its own sign-in (for QuickBooks Online, Intuit’s OAuth flow). We request the QuickBooks Online Accounting API scope. That permission is broader than a read-only OAuth scope, but Acore Business Check uses it only to send read requests. For this financial import, we retrieve sales and expense transactions plus monthly Income Statement, detailed Income Statement, and monthly Cash Flow reports for the three prior complete calendar years and the current year-to-date, plus monthly Balance Sheet positions across that period. We also retrieve Total-form Cash Flow companions used to reconcile opening and ending cash, the active and inactive chart of accounts, and current receivables and payables aging summaries. We read the company country and state/province from QuickBooks CompanyInfo to select geographically relevant business-sale comparisons. We immediately reduce that location to normalized country and state/province codes plus a source label; we do not save the company street address, city, or postal code. These saved statement periods and reconciliation records support summary, monthly, and year-over-year views in the private financial workspace. For larger company files, the import stores bounded private batches while the remaining date ranges are collected. Incomplete batches are not shown as financial reports, are deleted after a fatal failure, and expire within 24 hours if the import is abandoned. A completed import is published only after every batch has been validated and reconciled. The separate monthly valuation export (VOP) retrieves 36 monthly periods (about 109 requests). The annual export covers 37–48 months for three complete fiscal years plus current YTD using roughly 19–21 direct report requests, with flow reports split into chunks of no more than six months. We never see your accounting password. We do not create, edit, or delete accounting records, retrieve banking login credentials, or use payroll or payments APIs.
  • Saved financial snapshots are created when you successfully generate a VOP export. We store the mapped monthly or annual values and the generated CSV in the private company profile so an authorized user can review or download the same export again without presenting it as current accounting data.
  • Optional AI seller-guide processing occurs only when you select “Explain my estimate.” We send OpenAI a limited summary of calculated values, data-availability flags, and aggregate buyer-risk scores. We do not send raw transactions, customer or vendor names, account names or identifiers, documents, adjustment evidence, free-text notes, contact details, or raw comparable-sale records. We also send a pseudonymous safety identifier derived from your user ID for abuse prevention; it does not reveal the underlying user ID. The AI explanation cannot change the valuation or save an adjustment. We do not save the prompt or AI response in the Acore database; we keep only minimal request metadata needed to enforce usage limits.
  • Optional AI account-classification processing occurs only when you ask Acore to review unclear QuickBooks accounts. We send OpenAI a limited account-level summary: a temporary candidate key, a sanitized account label, QuickBooks account type, subtype and classification, its location in the Income Statement, and coarse activity, sign and materiality bands. We do not separately supply exact account balances, raw transactions, customer or vendor lists, memos, documents, contact records, company identity fields, or stable QuickBooks account identifiers. We also send a pseudonymous safety identifier derived from your user ID for abuse prevention; it does not reveal the underlying user ID. Account labels are user-authored bookkeeping text and can themselves contain a person, company, or lender name; we truncate them and redact obvious contact and long-number patterns before processing, but cannot guarantee that every embedded name is removed. The model returns only a suggested accounting category, confidence, and bounded reason code; application code performs every financial calculation. We save the suggestion, model and policy versions, input fingerprint, and your accept/reject decision for auditability, but not the raw prompt or model response. An unconfirmed suggestion may support a clearly labelled preliminary range, but it does not become a reviewed account mapping unless you confirm it.

How we use it

  • To create, authenticate, secure, and administer your account.
  • To generate your tech-spend assessment and findings report.
  • At your request, to explain an existing calculated business-value estimate in plain language and suggest a short list of facts worth confirming. The AI explanation is not an appraisal, offer, or professional legal, tax, accounting, or transaction opinion.
  • At your request, to suggest how an unclear Income Statement account may affect the earnings bridge and present a preliminary range until you or an advisor confirms it.
  • To discuss the findings with you and, if you choose, scope an implementation.
  • Vendor names from transactions may be added to our internal vendor-classification catalog (the vendor name only — never amounts, dates, or anything identifying your business).

We do not sell your data. We do not share it with third parties except the infrastructure providers below, and we do not use it for advertising.

Where it lives

Data is stored with our infrastructure providers, including Supabase for the database and authentication, Vercel for application hosting, Resend for account-email delivery, and OpenAI for the optional AI seller guide and account classifier, in the regions configured for those services. Resend processes your email address and message delivery metadata when sending confirmation and password-recovery messages. Access tokens for your accounting connection and its QuickBooks company identifier are stored server-side using application-layer encryption. They are used only to retrieve data for your assessment during the engagement.

AI seller-guide and account-classification requests use OpenAI’s API with response storage disabled. OpenAI does not use API inputs or outputs to train its models by default, but may retain limited abuse- monitoring logs under its API data-control terms. Acore does not provide the AI model with direct access to QuickBooks, the database, files, web browsing, or application tools.

Retention and deletion

We keep account information while your account is active and assessment data for the duration of the engagement. You may request deletion at any time by emailing us. Subject to security, legal, and backup-retention requirements, we will delete your account, profile, transactions, connection tokens, saved financial snapshots, and reports within 30 days. Disconnecting the app from within your accounting system (for QuickBooks: My Apps → disconnect) immediately stops our access.

Contact

Questions or deletion requests: aiden@aidenhooper.com