Missing Toolkit: Templates logo
Missing Toolkit Templates

Privacy Policy

Effective Date: August 17, 2026

This Privacy Policy describes how Missing Toolkit: Templates ("we," "us," or "our") collects, uses, and protects your information when you use the Missing Toolkit: Templates application, our browser extension, and related services (the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Information You Provide

  • Account Information: Name, email address, and password when you create an account. If you sign in with Intuit, we receive your name, email address, and an Intuit user identifier from Intuit instead of a password.
  • Team Information: Team name and member details when you set up your workspace.
  • Template Data: Document templates, placeholder mappings, and generated documents you create within the Service.
  • Payment Information: Billing details if you subscribe to a paid plan. Card details are collected and stored by our payment provider, not by us.

Information Collected Automatically

  • Usage Data: Pages visited, features used, and actions taken within the Service.
  • Device Information: Browser type, operating system, and device identifiers.
  • Log Data: IP address, access times, and referring URLs.

Information from Third-Party Integrations

When you connect Intuit QuickBooks Online, we access your QuickBooks data using Intuit's official API, under the authorization you grant to your QuickBooks company. We only ever read from your QuickBooks account: we never create, modify, or delete records in it.

We read the records needed to produce the documents you ask for — invoices, estimates, credit memos, purchase orders, bill payments, customer statements and related entities — including customer and vendor names, contact and address details, line items, dates and amounts.

We do not cache your QuickBooks records. Data retrieved for a document run is held in memory for the duration of that run only. The QuickBooks information we retain afterwards exists inside the finished Word or PDF document you generated. Our records of a generated document store only the record type, record identifier, a display label, and the file location.

We also store, on your connection: your Intuit access and refresh tokens (encrypted), your QuickBooks company identifier and company name, and a cached copy of your custom field definitions, refreshed at least every 24 hours.

Your Company Website

If your QuickBooks company profile lists a website, we retrieve its public homepage once, when you first connect, to suggest a logo and brand color for your document templates. We fetch only the address your QuickBooks record provides, we store only the logo image and color you are shown (the logo is deleted if you decline it), and we do not monitor or revisit your site.

2. Browser Extension

We publish a Chrome extension that lets you generate a document from the QuickBooks Online record you are viewing.

What it reads. On QuickBooks Online pages only, the extension reads the record type and record identifier from the page address, and your QuickBooks company identifier from the page's session cookie so it can select the matching connection in your account and prevent a document being generated against the wrong company. It reads no other content from the page.

What it stores. After you sign in, the extension stores an authentication token for our API, along with the list of record types it supports, in Chrome's extension storage, which is isolated from web pages and from other extensions. Your password is sent to us over HTTPS to obtain that token and is never stored by the extension. The token is scoped to the extension's functions, expires automatically, and can be revoked at any time from Settings → Security in your account.

What it does not do. The extension holds no Intuit credentials, does not modify the QuickBooks Online interface, does not perform any action inside QuickBooks Online on your behalf, and is not active on any site other than QuickBooks Online. All QuickBooks data used to build your document is retrieved by our servers through Intuit's API, and the finished document is downloaded to your computer.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service.
  • Create and manage your account.
  • Process transactions and send related information.
  • Improve and personalize the Service.
  • Communicate with you about updates, security alerts, and support.
  • Detect, prevent, and address technical issues and security threats.
  • Comply with legal obligations.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: With the vendors who operate our infrastructure on our behalf, each under a written agreement limiting them to that purpose:
    • Amazon Web Services — application hosting, storage of your templates and generated documents, PDF conversion, and delivery of transactional email (Amazon SES).
    • Anthropic — template design. When you use the template designer, or we design starter templates for you, Anthropic processes your template's layout, the names of the data fields it uses, and — for the design of your starter templates — your company name and public website content. Your QuickBooks record contents (customer names, amounts, line items) are never sent to Anthropic; documents are filled in entirely on our servers.
    • Stripe — subscription billing and payment processing.
  • Intuit: When you authorize a connection to QuickBooks Online, we exchange data with Intuit as necessary to provide the integration.
  • Legal Requirements: When required by law, regulation, or legal process.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

A small number of accounts created before August 2026 have PDF conversion performed by Microsoft, which receives the finished document and returns it as a PDF. New accounts do not, and these accounts are being migrated.

5. Data Security

We implement industry-standard security measures to protect your information, including encryption in transit and at rest. Intuit access and refresh tokens are encrypted at rest, and access to your data is scoped to your team. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.

6. Data Retention

We retain account and team information for as long as your account is active. Data we generate or cache while providing the Service is retained as follows:

Data Retention
Generated documents (Word and PDF files) 90 days from creation
Batch download bundles (ZIP and merged PDF) 7 days
Document previews Deleted daily, once more than 24 hours old
QuickBooks API request logs 12 months
Cached reference data (customer types, payment terms, custom field definitions) 24 hours
QuickBooks records retrieved for a document run Not retained — held in memory for the run only

QuickBooks API request logs record the request method, URL, response status, Intuit's transaction identifier and the request duration. The URL identifies which record was requested; the logs hold no record contents — no names, amounts, or line items. We keep them to diagnose problems and, where necessary, to support an Intuit investigation.

You may delete your generated documents at any time. See "Deleting Your Data."

7. Disconnecting QuickBooks

You can disconnect a QuickBooks company at any time, from within our application or from the Apps area of QuickBooks Online. Either way:

  • We revoke our access token with Intuit.
  • We delete your access token, refresh token, QuickBooks company identifier, company name and cached custom field definitions.
  • Any scheduled document runs for that company are paused, with the reason recorded and visible to you.

Documents you have already generated are not deleted when you disconnect. A generated invoice or statement is your own business record, and disconnecting is not the same as asking us to erase your work — you may be re-authorizing, switching QuickBooks accounts, or changing accountants. Those documents remain available to you and are deleted on the retention schedule above, or immediately if you ask us to delete them.

8. Deleting Your Data

  • Individual documents can be deleted from within the application at any time.
  • All QuickBooks-derived data can be deleted by a team owner at Team → Integrations → "Delete QuickBooks data." This deletes every generated document and its stored file, clears batch download bundles, and removes stored QuickBooks credentials and company data from every connection, including ones disconnected previously. Your templates, team and subscription are not affected.
  • Your entire account can be closed by a team owner at Team → Billing → "Delete team," which deletes your generated documents and their stored files along with the account.
  • You may also contact us at support@missingtoolkit.com to request deletion.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your personal information.
  • Object to or restrict certain processing of your information.
  • Export your data in a portable format.

To exercise any of these rights, contact us at support@missingtoolkit.com.

10. Cookies and Analytics

The Service uses cookies and similar technologies to maintain your session and remember your preferences. You can control cookie settings through your browser preferences.

11. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will take steps to delete it.

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.

13. Changes to This Policy

We will post any changes to this page and update the effective date. Material changes affecting how we handle your data will also be notified by email.

Previous versions: March 25, 2026.

14. Contact

If you have questions about this Privacy Policy, contact us at support@missingtoolkit.com.