Privacy Policy

Last updated: 12/01/2025

CFOly.ai (“we”, “our”, “us”) is a financial analytics and AI-powered advisory platform operated by Profit Matters, located at 3960 FM2181 Ste 120, Hickory Creek, TX 75065, United States. This Privacy Policy explains how we collect, use, store, and protect your personal and business information when you use CFOly.ai (the “Service”).

By creating an account or using the Service, you agree to the practices described in this Privacy Policy.

1. Information We Collect

We collect the following categories of information:

1.1. Account Information

– Full name
– Username
– Email address
– Password (hashed and encrypted)

1.2. Business Information (Onboarding Data)

Provided by users during onboarding:
– Company name
– Number of employees
– Industry and business model
– Business description
– Annual financial goal
– Any additional knowledge the user chooses to provide for dashboard tailoring

1.3. QuickBooks Data

When users connect their QuickBooks account, we process all types of financial data available through QuickBooks, including but not limited to:
– Transactions
– Invoices and receipts
– Payroll data
– Profit & Loss statements
– Balance sheets
– Chart of accounts
– Expense categories
– Vendor/customer information

We process QuickBooks data in real time and do not permanently store it on our servers.

1.4. AI Chat Data

When you use the AI assistant:
– Chat messages and interactions may be stored inside your user account so you can revisit them.
– These messages are NOT used to train AI models.

1.5. Payment Information

Payments are processed securely by Stripe.

We receive and store only:
– Payment status
– Subscription plan
– Billing period

We do not store full credit card numbers or sensitive payment details.

1.6. Cookies and Tracking Technologies

We use all types of cookies:
– Functional
– Analytical
– Performance
– Marketing/advertising

2. How We Use Your Information

We use collected information to:
– Provide and maintain the CFOly.ai platform
– Generate analytics, dashboards, reports, and insights
– Personalize onboarding and financial goal tracking
– Enable real-time synchronization with QuickBooks
– Provide AI-based responses to business questions
– Manage billing and subscriptions
– Improve product functionality and user experience
– Ensure security, prevent fraud, and comply with legal obligations

3. Legal Basis for Processing

We process your data in accordance with applicable laws in your jurisdiction. This may include:
– Providing and maintaining the Service, including onboarding, QuickBooks integration, dashboard generation, AI chat, and subscription management.
– Legitimate business interests, such as improving and securing the platform, preventing fraud, and analyzing usage to enhance functionality.
– Compliance with legal and regulatory obligations.
– User consent where required, for example, for cookies, optional data fields, or marketing communications.This general approach ensures that data processing is lawful, fair, and transparent across all regions, including the EU, USA, and other countries.

4. How We Share Information

We do not sell your personal or business data. We may share data only with trusted third-party services necessary to operate the platform, such as:
– QuickBooks (Intuit) — real-time data synchronization
– Stripe — payment processing
– AWS — secure cloud hostingWe currently do not share data with any other third parties.

5. Data Storage and Security

– All data is stored securely on AWS (Amazon Web Services).
– QuickBooks data is processed only in real time and not stored long-term.
– Passwords are encrypted using modern hashing algorithms.
– Access to personal data is strictly limited to authorized personnel.

6. Data Retention

– We retain account and onboarding data for up to 30 days after a user deletes their account.
– After 30 days, all data is permanently erased.
– QuickBooks data is not stored and therefore not retained.

7. Your Rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to:
– Access your data
– Correct inaccurate data
– Request deletion of your data
– Export your data (data portability)
– Withdraw cookie or data processing consent

8. International Data Transfers

Your information may be transferred to and processed in the United States, where our servers and company are located.
We implement safeguards consistent with GDPR and industry standards.