Privacy Policy
Paradise Financial Services, LLC
Effective Date: August 14, 2026 | Last Updated: August 14, 2026
Paradise Financial Services, LLC ("PFS," "we," "us," or "our") respects your privacy and is committed to protecting the information you share with us. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. It applies to our website at www.paradisefs.com, to the bookkeeping, financial planning and analysis, CFO, and tax preparation services we provide, and to the internal reporting software we operate in connection with those services.
1. Who This Policy Covers
This Policy applies to:
-
Visitors to our website;
-
Prospective clients who contact us or request information;
-
Clients who engage us for bookkeeping, FP&A, CFO, or tax preparation services; and
-
Individuals whose information appears in records our clients provide to us, such as their customers, vendors, and employees.
The professional services we provide are governed by a separate written engagement letter. Where this Policy and an engagement letter conflict on a matter of confidentiality or data handling, the engagement letter controls.
2. Information We Collect
2.1 Information you provide to us
-
Contact and business details: name, email address, telephone number, business name, mailing address.
-
Financial and tax records: books and records, bank and credit card statements, invoices, receipts, payroll records, prior-year tax returns, and supporting documentation you provide so we can perform our services.
-
Identifiers required for tax filing: Social Security numbers, Employer Identification Numbers, and similar identifiers, collected only where required to prepare or file a return.
-
Billing information: the details needed to invoice you. We do not accept card payments and do not collect or store payment card numbers.
2.2 Information collected automatically from our website
-
IP address, browser type, device type, operating system, referring page, pages visited, and time spent on the site, collected through cookies and similar technologies.
2.3 Information from third parties
-
Accounting data retrieved from QuickBooks Online with your authorization, as described in Section 4.
-
Information from banks, payment processors, and financial data aggregators where you have connected those accounts to your accounting file.
3. How We Use Information
We use information to:
-
Provide bookkeeping, accounting, financial planning and analysis, CFO advisory, and tax preparation services;
-
Prepare financial statements, management reports, forecasts, dashboards, and tax filings;
-
Respond to inquiries, schedule consultations, and communicate with you about your engagement;
-
Issue invoices and process payments;
-
Operate, maintain, secure, and improve our website and internal systems; and
-
Comply with legal, tax, regulatory, and professional obligations.
We do not sell, rent, or license your personal information or your accounting data. We do not use client accounting data for advertising or marketing, and we do not use it to train machine learning or artificial intelligence models.
4. QuickBooks Online Integration
PFS operates an internal financial reporting application (referred to internally as "Beacon") that connects to QuickBooks Online through Intuit’s official published API in order to produce client reporting and analysis. This section describes that integration in detail.
4.1 Authorization
A connection to a QuickBooks Online company file is established only after an authorized representative of the client, or PFS acting under the client’s written authorization as its accountant, completes Intuit’s OAuth 2.0 consent flow and expressly approves the connection. We never ask for, receive, or store QuickBooks usernames or passwords.
4.2 What we access
The integration requests read-only accounting scope. Within that scope we retrieve:
-
Transaction-level detail, including date, transaction type, document number, memo, and amount;
-
Chart of accounts and account classifications;
-
Customer, vendor, and employee names as they appear on transactions;
-
Class, location, and product or service designations where the client uses them; and
-
Company profile information such as company name, fiscal year, and reporting currency.
4.3 Read-only operation
The integration does not create, modify, or delete any record in your QuickBooks company file. It reads data only. Any changes to your books are made by us or by you through QuickBooks directly, in the ordinary course of the engagement.
4.4 What we store
-
Encrypted OAuth access and refresh tokens, which allow the application to reconnect on a schedule without repeated sign-in. These are encrypted at rest using AES-256-GCM. Encryption keys are held separately from the database.
-
Report outputs and derived analyses prepared for the client, and the intermediate data used to generate them.
We do not store your QuickBooks credentials. Tokens can be revoked at any time, as described in Section 4.7.
4.5 Where the data is processed
The application runs on cloud infrastructure located in the United States. See the sub-processor table in Section 5.
4.6 What we will not do with QuickBooks data
-
We will not sell, rent, or license it.
-
We will not share it with advertisers, data brokers, or marketing platforms.
-
We will not use it to train machine learning or artificial intelligence models.
-
We will not use it for any purpose other than providing services to the client to whom the data belongs, or as required by law.
-
We will not combine one client’s data with another client’s data except in aggregated, de-identified form that cannot reasonably be used to identify any client.
4.7 Revoking access
A client may disconnect the integration at any time, either from within QuickBooks Online (Settings → Apps → Connected apps → Disconnect) or by contacting us using the details in Section 14. On disconnection we revoke and delete the stored tokens. Report outputs and working papers already produced are retained in accordance with Section 8 and our professional records-retention obligations.
5. How We Share Information
We share information only as follows:
-
With service providers who process data on our behalf under contract, listed below;
-
With other professional advisors (for example, your attorney or a specialist tax adviser) where you direct or consent to it;
-
With legal, tax, or regulatory authorities where required by law, subpoena, or professional obligation; and
-
In connection with a sale or reorganization of our practice, subject to the acquirer honoring this Policy.
We currently use the following service providers:
Intuit Inc. — QuickBooks Online accounting platform and API. Handles client accounting data. United States.
Render Services, Inc. — Hosting for our reporting integration. Handles encrypted tokens and report data in transit. United States.
Turso (libSQL) — Encrypted database for connection records. Handles encrypted OAuth tokens only. United States.
Wix.com Ltd. — Website hosting and contact form. Handles website contact submissions. United States / EU.
Microsoft — Client communication and document exchange. Handles correspondence and documents. United States.
ProConnect — Preparation and e-filing of returns. Handles taxpayer data. United States.
We do not sell personal information as that term is defined under applicable state privacy laws, and we have not done so in the preceding twelve months.
6. How We Protect Information
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include:
-
Encryption of data in transit using TLS 1.2 or higher;
-
Encryption of sensitive credentials at rest using AES-256-GCM, with encryption keys stored separately from the encrypted data;
-
Full-disk encryption on devices used to access client information;
-
Multi-factor authentication on systems that hold or access client information;
-
Access limited to personnel who need it to perform their work;
-
A password manager for credential storage, with no shared or reused passwords;
-
Logging of application activity, with credentials and tokens redacted from logs; and
-
A Written Information Security Plan maintained in accordance with the FTC Safeguards Rule (16 C.F.R. Part 314), IRS Publication 4557, and the Massachusetts Standards for the Protection of Personal Information (201 C.M.R. 17.00).
No method of transmission or storage is completely secure. While we take these precautions seriously and review them regularly, we cannot guarantee absolute security.
7. Your Choices and Rights
Depending on where you live, you may have the right to:
-
Request access to the personal information we hold about you;
-
Request correction of inaccurate or incomplete information;
-
Request deletion of your information, subject to our legal and professional retention obligations;
-
Withdraw consent where we rely on consent to process your information; and
-
Opt out of marketing communications at any time.
To exercise any of these rights, contact us using the details in Section 14. We will respond within the time required by applicable law. We may need to verify your identity before acting on a request, and we may be unable to delete records we are legally required to retain, such as filed tax returns and supporting workpapers.
8. Data Retention
We retain information only as long as necessary for the purposes described in this Policy and to meet our legal, tax, regulatory, and professional obligations.
We retain information as follows:
Tax returns and supporting workpapers — 7 years from the filing date.
Bookkeeping records and financial statements — 7 years from the end of the engagement.
OAuth tokens for the QuickBooks integration — until the connection is revoked or the engagement ends, then deleted.
Website contact form submissions — 24 months from submission.
Website analytics data — 26 months.
9. Cookies and Tracking
Our website uses cookies and similar technologies to enable core site functionality, remember your preferences, analyze traffic, and improve the site. You can set your browser to refuse cookies or alert you when cookies are being sent; some parts of the site may not function properly if you do. We do not use cookies to serve targeted advertising.
10. Third-Party Links
Our website may link to third-party websites. We are not responsible for the privacy practices or content of those sites, and this Policy does not apply to them. We encourage you to read the privacy policy of any site you visit.
11. Children’s Privacy
Our website and services are directed to businesses and adults. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
12. Financial Privacy Notice
Because we prepare tax returns, PFS is treated as a "financial institution" under the Gramm-Leach-Bliley Act. We collect nonpublic personal information about you from the information you provide to us, from your transactions, and from third parties you authorize us to contact.
We do not disclose nonpublic personal information about our clients or former clients to anyone, except as permitted by law — for example, to service providers who assist us in providing services to you, to other professionals at your direction, or where required by law, subpoena, or professional standards. Because we do not share your information for marketing purposes, no opt-out is required.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted on this page with a revised effective date, and where required by law we will notify you directly. Your continued use of our website or services after an update constitutes acceptance of the revised Policy.
14. Contact Us
If you have questions about this Policy, or wish to exercise any of the rights described above, contact us at:
Paradise Financial Services, LLC
Email: info@paradisefs.com
Telephone: 781-214-1987
52 Brookhouse Drive, Marblehead MA 01945
