Privacy Policy
This Privacy Policy explains how Maximinds Limited (“Maximinds,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with PracticePilot (the “Service”), a bookkeeping and financial-reporting platform for medical practices available at www.practicepilotjm.com. By using the Service you agree to this Policy.
1. A note on health information
PracticePilot is built to stay outside the scope of health-privacy regulation such as HIPAA. We do not collect, receive, store, or process protected health information (PHI) or any clinical or patient-identifying data. The Service works only with financial records: bank feeds, payroll data, card-processor settlements, and accounting data from connected systems. Please do not submit PHI to the Service.
2. Information we collect
Account and contact information
When you or your organization create an account, we collect your name, work email address, the practice or organization you belong to, your assigned role, and authentication data needed to sign you in securely.
Financial and accounting data
To provide bookkeeping and reporting, we process the financial records you or your bookkeeper connect or upload, which may include bank transactions, payroll summaries, card-processor settlements, chart-of-accounts structures, journal entries, and the account balances and transactions we import from connected accounting systems such as QuickBooks Online (see Section 3).
Technical and usage data
We collect standard technical data required to operate and secure the Service, such as log records, device and browser information, and strictly necessary cookies used for authentication and session management. We do not use advertising cookies.
3. QuickBooks Online data (Intuit)
If you choose to connect a QuickBooks Online company, you authorize the connection through Intuit’s official OAuth 2.0 flow. Our access is strictly read-only. Specifically:
- What we access.The company’s chart of accounts, account balances and trial balance, and transaction (general ledger) detail for the reporting periods you select. We use this data solely to import your books and produce the financial reports and analytics you request.
- What we never do. We do not create, modify, or delete anything in your QuickBooks company. PracticePilot never writes back to QuickBooks.
- How tokens are stored. The access and refresh tokens Intuit issues are encrypted at rest using authenticated encryption (AES-256-GCM) with a key held only in our server environment. Tokens are accessible only to privileged server-side processes and are never exposed to your browser or to any other customer.
- How to disconnect.You can disconnect QuickBooks at any time from Settings › QuickBooks in the Service. Disconnecting marks the connection revoked and deletes the stored tokens, ending our access.
- How we use it. QuickBooks data is used only to deliver the features you request. We do not use it for advertising, and we do not sell it.
Our use and transfer of information received from Intuit APIs adheres to the applicable Intuit developer and platform requirements.
4. How we use information
- To provide, maintain, and improve the Service and its bookkeeping and reporting features.
- To import connected financial data and reconcile it to its source of record.
- To generate financial statements, analytics, and insights you request.
- To authenticate users, enforce access controls, and secure the Service.
- To provide customer support and to communicate about your account and service matters.
- To comply with legal obligations and enforce our agreements.
5. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- Service providers (sub-processors). We use vetted providers to run the Service, including cloud database and authentication hosting, application hosting, the Intuit platform as the source of connected accounting data, an artificial-intelligence provider used to generate financial mappings and insights from your non-clinical financial data, and a transactional email provider. These providers process data only on our instructions and under contractual confidentiality and security obligations.
- Within your organization.Data is visible to authorized users of your own practice according to their assigned role. One practice can never access another practice’s data.
- Legal and safety. We may disclose information if required by law, or to protect the rights, safety, and security of our users, the public, or the Service.
- Business transfers. If Maximinds is involved in a merger, acquisition, or sale of assets, information may be transferred subject to this Policy.
6. Data retention and deletion
We retain information for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with legal, accounting, and reporting obligations. You may request deletion of your data as described in Section 8; when you disconnect a data source such as QuickBooks, the stored credentials for that source are deleted promptly.
7. Data security
We apply administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and at rest, encryption of third-party access tokens, database row-level security that isolates each practice’s data, role-based access controls, and audit logging of changes. No method of transmission or storage is completely secure, but we work to protect your information and to review our controls on an ongoing basis.
8. Your rights and choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, or to ask a privacy question, contact us at kadeem@maximindsltdja.com. We will respond consistent with applicable law. You can also disconnect connected data sources and request account closure at any time.
9. International data transfers
We operate internationally and use cloud providers that may process and store data in countries other than your own, including the United States and Canada. Where required, we rely on appropriate safeguards for such transfers.
10. Children’s privacy
The Service is intended for businesses and their authorized personnel. It is not directed to children, and we do not knowingly collect personal information from children.
11. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised Policy.
12. Contact us
Maximinds Limited, operator of PracticePilot. For privacy questions, requests, or general support, contact kadeem@maximindsltdja.com.