ECS FINEK · LEGAL
Privacy Policy
How information is collected, used and handled when you use ECS Finek.
Effective October 6, 2026 · Last updated October 6, 2026
1. Operator and scope
Serghei Caijbirna operates ECS Finek in California, United States. Contact eco.company.solutions@gmail.com for privacy questions and requests. This policy covers the ECS Finek website and application. A company that gives employees or contractors access also controls what it uploads and how it uses its workspace; its own policies may apply to those activities.
2. Information we collect
- Account and company information: names, email addresses, company details, password hashes, account roles, invitations, permissions and access schedules.
- Business content: projects, estimates, budgets, contacts, employee records, time records, costs, invoices, purchase orders, proposals, forms, attachments and other information users enter or import. Content may contain contact details, pay rates or other personal information supplied by your company.
- Subscription records: selected plans, subscription status, payment identifiers, invoice or receipt information and payment results. Square processes payment-card information. ECS Finek does not store full card numbers or card security codes.
- Connection information: for an authorized QuickBooks connection, the company identifier and name, environment, encrypted access and refresh tokens, connection status and verification timestamps. We do not receive your Intuit password.
- Usage and technical information: sign-ins, last activity, audit events, request and error logs, and technical information such as IP addresses and browser information processed by our hosting or security providers.
- Communications: support requests and emails, recipient addresses, delivery status, and document content sent through the service.
Information comes from you, your company administrators and other authorized users, connected providers and use of the service.
3. How we use information
We use information to run company workspaces, authenticate users, apply permissions, generate requested documents and reports, process subscriptions, deliver messages, maintain authorized connections, provide support, investigate errors and abuse, and meet applicable obligations. Internal platform analytics include registrations, subscription and payment status, user counts and recent activity to understand adoption and operate the service.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use customer business records or QuickBooks data to train general-purpose AI models.
AI-assisted document extraction
When this optional feature is configured and an authorized user chooses to scan a purchase order, vendor bill or change order, the selected document is sent to OpenAI through its API to extract structured fields. Documents may contain business and personal information, including names, contact details and amounts. The interface discloses this transfer before scanning. You can enter information manually without using AI scanning.
Extracted information is returned as a draft for human review before saving. AI scanning does not approve documents, initiate payments or automatically post transactions to QuickBooks. The current QuickBooks integration does not send data retrieved through the QuickBooks API to OpenAI. ECS Finek does not train or fine-tune AI models using these documents. Provider processing and retention are subject to the applicable service terms and account settings; this feature does not promise zero retention.
4. Who receives information
- Your company and chosen recipients: authorized workspace users receive information according to their access. Documents sent or exported by a user are shared with the recipients that user selects.
- Service providers: Render provides application hosting, database and file infrastructure; Square processes subscription payments; Resend handles transactional email; OpenAI processes selected documents when an authorized user initiates optional AI extraction. When a user asks Help / Ask ECS a question with AI enabled, OpenAI also receives the question, recent chat messages, screen name, role and the ECS help guide. The help assistant does not receive workspace records automatically and cannot change transactions. Chat messages are held in the current browser view and are not stored as support tickets by ECS; provider processing remains subject to its applicable terms and settings. These providers receive information needed for their functions. Email support is handled through our Gmail contact address.
- Connected services: Intuit receives authorization and company-verification requests when you connect QuickBooks. When your company enables supported integrations, Intuit also receives and returns selected directory entries, financial documents, payment records and queued payment attachments according to your sync settings and confirmed actions.
- Operational access: the operator and authorized support personnel may access information when needed to operate, secure or support the service. Platform administration includes company account, billing and usage information.
- Legal and organizational needs: information may be disclosed when required by law, to address fraud or security incidents, protect lawful rights, or in a business transfer subject to applicable privacy obligations.
Third-party services have their own privacy policies. Review the policies of Intuit, Square, Render, Resend OpenAI and Google when using those services.
5. QuickBooks data and disconnecting
The integration supports authorized company connections and configured directory imports, paid-expense imports, financial-document synchronization and payment records. Confirmed outgoing actions can create or update supported QBO records, delete supported financial documents or attach queued payment scans. Excluding a document stops future sync while retaining both copies. Company sync settings and role permissions control these workflows. QuickBooks credentials are encrypted on the server and associated with the authorizing company workspace.
A company owner can use Disconnect on the QuickBooks connection page to revoke the connection and remove stored connection credentials after successful revocation. Disconnecting does not delete your workspace, its audit records, or records in QuickBooks. Contact us separately to request deletion of retained information. We will update this policy when the integration's data handling materially changes.
6. Cookies and browser storage
We use a session cookie to keep you signed in and browser storage for preferences such as saved scheduling views. Blocking these may prevent features from working. We do not deploy advertising pixels for cross-site profiling. The application does not currently change its essential operation in response to a browser Do Not Track signal. Our no-sale and no-advertising-sharing practice applies regardless of that signal. Payment and linked third-party services may use their own cookies and security technologies under their policies.
7. Retention and deletion
We retain account and workspace information to provide the service and maintain business records. An expired trial, canceled subscription or inactive employee account does not automatically erase data. You may request account closure or deletion by email. We will verify your authority and explain any information that must be retained for billing, legal obligations, security or dispute resolution. Backup copies may remain until the provider's normal backup cycle removes them; retained copies are not used to resume ordinary processing of deleted information.
There is no single automatic deletion deadline for all categories. Retention depends on the information's purpose, your request, applicable obligations and provider backup schedules. We can clarify the handling of a specific request before proceeding.
8. Your choices and requests
You can review and update information available to your role in the application. For access, correction, export or deletion requests, email eco.company.solutions@gmail.com with your company name and request. Do not include passwords, card details or secret keys. We may ask for information needed to verify identity and authority. Employees should also contact their company administrator for company-controlled records.
Depending on applicable law, you may have additional rights concerning your personal information. We will handle requests within the applicable legal requirements and will not deny legally protected rights because you exercise them. Disabling a user, canceling billing, disconnecting QuickBooks and deleting data are separate actions.
9. Security and processing location
We use HTTPS, hashed passwords, server-side access checks, company-scoped records and encryption of stored QuickBooks tokens. No system can guarantee absolute security. Protect your credentials and notify us promptly about suspected misuse. The application is hosted in the United States; service providers may process information in other locations under their own arrangements.
10. Children and policy updates
ECS Finek is a business service for adults and is not directed to children under 13. Contact us if you believe a child has provided personal information. We will publish policy revisions here with the updated date and provide notice of material changes through the service or account email as appropriate and required by law.