Integration Privacy Policy
What the integration collects, how we use and protect it, and the choices you have.
Effective date: October 1, 2026
1. Who we are and what this policy covers
1.1 The Real People CRM integration between QuickBooks Online and HubSpot (the "Service") is operated by Real People CRM Solutions LLC ("Real People," "we," "us"), of Buffalo, New York. The Service connects a business's QuickBooks Online company to that business's HubSpot account so the business can see its customers, balances and invoices in HubSpot.
1.2 This policy explains what information the Service collects, how we use, share, store and protect it, how long we keep it, and the choices available. It covers two kinds of information:
(a) information about the people who sign in to the Service ("Account Information"), for which we decide how it is used; and
(b) information the Service reads from and writes to our clients' QuickBooks Online and HubSpot accounts ("Client Data"), which we handle on behalf of, and only on the instructions of, the business that connected those accounts.
1.3 Our clients are businesses. The Service is not offered to individuals for personal, family or household use, and it is offered only to businesses in the United States.
1.4 For Client Data, the business that connected its accounts (the "Client") decides what the Service does and is responsible for giving its own customers any notice the law requires. If you are a customer of one of our Clients and have a question about your information, please contact that business; we will help it respond.
1.5 We are independent of Intuit Inc. and HubSpot, Inc. We do not process any information on Intuit's behalf or on HubSpot's behalf, and neither company is responsible for how the Service handles information. Your use of QuickBooks Online and HubSpot is governed by their own terms and privacy policies.
2. Information we collect
2.1 Account Information. When a Client invites you, or you sign in, we collect your email address, your name if you give it, the workspace you belong to and your role in it, and when you last signed in.
2.2 Connection credentials. When a Client connects its accounts, we receive and store (a) the authorization Intuit issues that lets the Service read that Client's QuickBooks Online company, together with the company's QuickBooks identifier, and (b) the private-app access token the Client creates in its HubSpot account.
2.3 Client Data from QuickBooks Online. The Service asks Intuit for one permission only, the QuickBooks Online accounting permission, and uses it to read:
(a) Customers: name, company name, billing email address, phone number, website, currency, balance, whether the customer is active, and when the customer was created;
(b) Invoices: invoice number, invoice date, due date, total, balance, currency, billing email address, tax and discount totals, and, for each line, the product or service name, description, quantity, unit price and amount; and
(c) Payments: amount, date and the invoices each payment was applied to.
QuickBooks Online returns each record in full. The Service uses only the details listed above and keeps a copy of each record as it was received, so that it can tell when something has changed (see Section 6). The Service does not read payroll, employee, banking, journal-entry or chart-of-accounts information. The Service does not write to, change or delete anything in QuickBooks Online.
2.4 Client Data from HubSpot. The Service reads the HubSpot contacts and companies needed to match each QuickBooks Online customer to the right record; the list of properties in the Client's HubSpot account, so the Client can choose where information is written; the permissions granted to the Client's HubSpot token; and the invoices, line items, taxes and discounts the Service itself created, to check they still match QuickBooks Online.
2.5 Activity records. The Service records each sync it runs (what ran, when, which records it touched, what changed and what failed) and each request it makes to QuickBooks Online and HubSpot (which request, when, how long it took and whether it succeeded). Request records do not contain the contents of QuickBooks Online data or any credentials.
2.6 Technical information. Our hosting provider keeps standard server logs, which can include IP addresses, browser type and the pages requested, to operate and secure the Service. The Service itself does not store IP addresses, and we do not use server logs to identify or track anyone.
2.7 Communications. If you contact us, we keep the correspondence so we can respond and keep a record of the support given.
2.8 Information the Service is not designed to handle. Clients must not use the Service to send health information protected by HIPAA, payment card numbers, bank account numbers, Social Security numbers or other government identification numbers, including in invoice line descriptions. See Section 5.3 of the End-User Agreement.
3. How we use information
3.1 We use Account Information to create and secure your account, send sign-in and invitation emails, show you your workspace, provide support, and tell you about the Service, including changes to this policy and our terms.
3.2 We use Client Data only to provide the Service to the Client that connected it, in the way that Client sets it up. Specifically, the Service:
(a) matches QuickBooks Online customers to HubSpot contacts or companies, and puts uncertain matches in a review queue for the Client to decide;
(b) writes the fields the Client chooses onto matched HubSpot records;
(c) only if the Client turns it on (it is off by default), creates a HubSpot record for a QuickBooks Online customer that matches no existing record, using only information the QuickBooks Online record states;
(d) only if the Client turns it on (it is off by default), creates and keeps up to date a copy of each QuickBooks Online invoice in HubSpot's invoice object, with its lines, tax and discount, associated with the customer's HubSpot contact and company. The copies are marked as not billable and have payment collection turned off, so HubSpot does not ask anyone to pay them;
(e) calculates totals shown in HubSpot, such as balances, overdue amounts and last payment dates;
(f) shows the Client a preview before changes are made, an activity log and a review queue; and
(g) keeps the Service secure, investigates problems, and provides support when the Client asks.
3.3 We do not sell Client Data or Account Information, share it for cross-context behavioral advertising, use it for advertising or marketing, combine it with information from any other source or any other Client, or use it to train or improve artificial-intelligence or machine-learning models.
3.4 Deletions in HubSpot. The Service does not delete records in a Client's HubSpot account, with two exceptions, both limited to records the Service created: it replaces the line, tax and discount records on an invoice copy when the QuickBooks Online invoice changes, and it removes a draft invoice copy of its own that it could not complete. The Service never changes an invoice copy that HubSpot shows as paid.
4. How we share information
4.1 Service providers. We use the following providers to run the Service. Each receives only what it needs and is bound by written terms to protect it:
- Railway Corporation: hosting and database, in the United States. Stores Account Information and Client Data.
- Resend: sends sign-in and invitation emails. Receives the recipient's email address and the email, never Client Data.
We will give Clients at least 30 days' notice before adding or replacing a provider that handles Client Data.
4.2 At the Client's direction. The Service reads from the Client's QuickBooks Online company and writes to the Client's HubSpot account because the Client connected them and told it to. Intuit and HubSpot are the Client's own providers. Once information is in the Client's HubSpot account, HubSpot holds it under the Client's agreement with HubSpot.
4.3 Our staff. Authorized Real People staff can view every workspace so they can set up connections, operate the Service and provide support. Access is limited to staff who need it, and all of them are bound by confidentiality obligations.
4.4 Never between Clients. One Client's data is never shown or made available to another Client. On every request, the Service checks the signed-in person's workspace membership before it returns any information, and those checks are covered by automated tests.
4.5 Legal requirements. We may disclose information if a law, subpoena or court order requires it, or where necessary to protect the rights, property or safety of Real People, our Clients or others. Where the law allows, we will tell the affected Client first so it can respond.
4.6 Business transfers. If Real People is involved in a merger, acquisition or sale of assets, information may pass to the successor, which will remain bound by this policy for information collected under it. We will tell Clients before that happens.
4.7 We do not otherwise share, rent or disclose information to anyone.
5. Cookies, tracking and Do Not Track
5.1 The Service uses only the cookies it needs to sign you in, keep you signed in and protect sign-in from forgery. It also saves your light or dark display choice in your own browser's storage.
5.2 The Service does not use analytics, advertising or tracking technologies, and does not allow any third party to track you across websites or over time.
5.3 Do Not Track. Because the Service does not track anyone across other websites, there is nothing for a Do Not Track signal or Global Privacy Control to switch off, and the Service's behavior is the same whether or not one is sent.
5.4 This policy covers the Service. Pages on realpeoplecrm.com, including the page this policy is published on, are hosted by HubSpot and can set HubSpot's own cookies. The Service itself sets only the cookies described in Section 5.1.
6. How long we keep information
| Information | How long |
|---|---|
| Connection credentials | Until the Client's workspace is deleted. Once a connection is disconnected, its credentials no longer work. |
| Stored copies of QuickBooks Online records, the links between QuickBooks Online and HubSpot records, sync records and request records | For as long as the Client's workspace exists. |
| Account Information | For as long as you have an account. Deleted within 30 days of your request. |
| Support correspondence | For as long as needed to provide support and keep ordinary business records. |
6.2 Deletion. On a Client's written request, or within 30 days after the Client's agreement with us ends, we permanently delete the Client's workspace and everything belonging to it: its connections and credentials, stored copies of QuickBooks Online records, record links, sync and request records, settings and user memberships. We confirm the deletion in writing on request. Any copies held in our database backups are erased as those backups expire on their normal schedule, and are not restored in the meantime except to recover the Service, in which case the deletion is carried out again.
6.3 Information the Service already wrote to a Client's HubSpot account belongs to the Client and stays there. The Client may keep or delete it; deleting a workspace does not remove it.
6.4 Disconnecting. When a Client disconnects QuickBooks Online, whether from inside QuickBooks Online or by asking us, the Service stops reading from QuickBooks Online and stops processing its data straight away. Disconnecting does not by itself delete stored information. To have it deleted, ask us to delete the workspace.
7. How we protect information
7.1 The measures we use include:
- All connections to the Service are encrypted in transit (HTTPS).
- Connection credentials are encrypted before they are stored, using AES-256-GCM with a unique initialization vector for each one and a key kept separately from the database. They are never written to logs in full.
- Sign-in uses single-use email links that expire after 15 minutes, so there are no passwords to steal. Invitations expire after 72 hours. Sign-in and invitation links are stored only as one-way hashes.
- Every request is checked against the signed-in person's workspace membership.
- The Service asks Intuit only for the accounting permission and uses its QuickBooks Online connection only to read.
- The Service does not record QuickBooks Online data or credentials in its request logs.
- We keep software dependencies up to date and keep a written record of known security findings and how each was assessed.
7.2 No method of storing or sending information is completely secure, and we cannot guarantee that information will never be accessed, disclosed, altered or destroyed through a failure of our safeguards.
7.3 If we confirm a security incident affecting Client Data, we will tell the affected Client without undue delay, as set out in the End-User Agreement, and help it respond.
8. Your choices and rights
8.1 If you have an account, you can change your name in the Service at any time. To see, correct or delete your Account Information, email support@realpeoplecrm.com.
8.2 Clients control their Client Data. They can change which fields are written, turn record creation and invoice copies on or off in Settings, decide review-queue items, disconnect QuickBooks Online, and ask us to delete their workspace.
8.3 If you are a customer of one of our Clients, we handle your information as a service provider to that business. Please send any request about your information to that business. If you contact us instead, we will pass your request to that business and help it respond.
8.4 We will check that a request is genuine before acting on it, to protect information from people who aren't entitled to it. We will not treat anyone differently for making a privacy request.
9. Where information is stored
Information is stored and processed in the United States.
10. Children
The Service is for businesses and is not directed to children. We do not knowingly collect information from children under 13. If we learn that we have, we will delete it.
11. Changes to this policy
We will post any change on this page with a new effective date. For a material change, we will email each Client's workspace administrators at least 30 days before it takes effect. A new optional feature is different: it applies only to a Client that turns it on and agrees to it at that time, as described in Section 3.4 of the End-User Agreement. We will not use information we already hold in a materially different way from what this policy described when we collected it, unless the Client agrees.
12. Contact
Questions, requests and complaints about privacy: support@realpeoplecrm.com. Real People CRM Solutions LLC, Buffalo, New York.
QuickBooks and Intuit are trademarks of Intuit Inc. HubSpot is a trademark of HubSpot, Inc. The Service is independent and is not affiliated with, sponsored by or endorsed by Intuit Inc. or HubSpot, Inc. Their names are used only to identify the products the Service connects to.