EXIZIP

Privacy Policy

Last updated: September 7, 2026

This Privacy Policy describes how Stanrell ("we", "us") handles information in connection with EXIZIP, a Chrome Extension that allows authorized QuickBooks Online users to export invoice PDFs and to export invoice, customer and product/service records as CSV or Excel files. Please read this policy carefully before using EXIZIP.

1. What EXIZIP does

EXIZIP is a Chrome Extension. It connects to your QuickBooks Online company using Intuit's OAuth 2.0 authorization and, at your request, reads accounting records from that company in order to produce files that are downloaded to your computer:

  • Invoice PDF export — EXIZIP retrieves your invoice list and downloads selected invoice PDFs directly from QuickBooks to your computer. ZIP archives are assembled locally in your browser.
  • Spreadsheet export — EXIZIP reads invoice records, customer records and product/service records (QuickBooks Item records) and generates CSV or Excel (.xlsx) files locally in your browser.

EXIZIP's current export functionality is read-only. EXIZIP does not create, modify or delete QuickBooks accounting records. EXIZIP uses a single Intuit authorization scope, com.intuit.quickbooks.accounting; no additional scope was added for spreadsheet export.

2. QuickBooks records read for your exports

When you request an export, EXIZIP reads the corresponding records from your connected QuickBooks Online company through Intuit's API. Those records are held in your browser's memory for as long as needed to build the file you asked for, and the resulting PDF, ZIP, CSV or .xlsx file is written to your computer. These accounting payloads are not intentionally sent to Stanrell's backend for processing or permanent storage.

EXIZIP also reads customer records and product/service records from your connected QuickBooks Online company at your request in order to generate CSV or Excel (.xlsx) files that are downloaded to your computer. These accounting records are processed for the requested export and are not maintained by Stanrell as a permanent copy.

Depending on the export you request, the records read may include:

  • Invoices — fields such as invoice number, customer, invoice date, due date, total, balance, currency and memo; and, for PDF export, the invoice PDF generated by QuickBooks.
  • Customers — customer records may contain personal information, including names, email addresses, telephone numbers, postal addresses, company names, balances and related information. These fields may be read when you request a customer spreadsheet export.
  • Products / Services (QuickBooks Item records) — name, type, description, price, account reference, taxable status and active status.

EXIZIP does not maintain a permanent copy of your QuickBooks accounting data.

QuickBooks access tokens are held in browser memory only and are not permanently persisted on your device.

3. Technical connection data on Stanrell's backend (api.stanrell.com)

EXIZIP uses a backend server at api.stanrell.com to establish and maintain your QuickBooks connection. The information below is limited technical authentication, session and connection data required to operate that connection — it is distinct from the QuickBooks accounting records described in section 2. The following is transmitted to and maintained on our backend:

  • OAuth authorization code — sent once during connection to exchange for tokens; single-use and discarded immediately after exchange.
  • QuickBooks Realm ID — your QuickBooks company identifier, used to associate your connection record. Stored as a derived identifier (SHA-256 hash).
  • Encrypted refresh token — received from Intuit during OAuth and stored in encrypted form on our backend. Used to maintain your authorized session without requiring you to re-authorize each time.
  • Session metadata — a session token hash and associated timestamps, used to authenticate extension requests to the backend.

Not maintained on our backend: invoice PDF content, ZIP files, generated CSV or .xlsx files, invoice line items, customer records, product/service records, or QuickBooks access tokens.

4. Data sent to Intuit

The OAuth authorization process involves communication with Intuit's servers. Intuit receives the authorization code during token exchange and issues access and refresh tokens. Intuit's own Privacy Policy governs how Intuit handles your data. EXIZIP does not control Intuit's data practices.

5. Chrome extension storage

EXIZIP stores the following data locally in your browser's extension storage (chrome.storage.local):

  • Your connection identifier (connectionId) and QuickBooks Realm ID
  • Your backend session token (used to authenticate with api.stanrell.com)
  • Session identifier
  • Export progress state (used to resume interrupted exports)

This data is stored locally on your device and is not accessible to websites or other extensions. It is cleared when you disconnect EXIZIP.

6. Data retention and deletion

Connection data (encrypted refresh token, session metadata, connection identifier) is retained on Stanrell's backend until you disconnect EXIZIP. When you disconnect:

  • Your connection record is deleted from Stanrell's backend.
  • Stanrell requests that Intuit revoke the associated refresh token.
  • Your local extension storage is cleared.

If you revoke access from within your Intuit/QuickBooks account settings without disconnecting from the extension, connection data may remain on Stanrell's backend until you subsequently disconnect via the extension or contact us for manual deletion.

7. No analytics, tracking, or advertising

EXIZIP does not include analytics scripts, tracking pixels, advertising networks, or third-party data collection of any kind.

8. Children's privacy

EXIZIP is not directed at children under 13. We do not knowingly collect information from children.

9. Changes to this policy

We may update this Privacy Policy. Material changes will be noted by updating the date at the top of this page. Continued use of EXIZIP after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this Privacy Policy or requests for data deletion: hello@stanrell.com