Privacy Policy

Last updated: August 22, 2026

This Privacy Policy explains how Lion, LLC, an Illinois limited liability company doing business as Books Backup ("Lion," "we," "us," or "our"), collects, uses, discloses, and safeguards information in connection with this website and the QuickBooks Online archive service (collectively, the "Service").

This Privacy Policy describes our information practices; where consent or authorization is legally or contractually required, we obtain it separately (for archive engagements, through the signed engagement paperwork). This Privacy Policy is part of and subject to our Terms of Service.

1. Three Separate Systems

We deliberately run the Service on three operationally separate systems. Understanding the separation is the fastest way to understand this policy:

  1. The marketing website (the pages you are reading). Static pages served by Cloudflare Pages. Cloudflare sees ordinary web-request metadata (your IP address, browser user agent, pages requested) in the course of serving the site. It stores no form submissions and holds none of your financial data.
  2. Lead capture (the Get Started form). What you type in the form is sent directly from your browser to our form database (Supabase). It never passes through the website host, and we do not store or merge QuickBooks data in the lead database.
  3. The archive service (your QuickBooks data). If you engage us, the contents of your QuickBooks Online company are handled only inside this system: our AI provider (Anthropic) during archive production, an isolated working folder on our equipment, and the secure file-delivery step that hands you the finished archive. The only exceptions are the legal-process and security disclosures described in Section 6.

The Service is designed so that your QuickBooks data never touches the website infrastructure, never enters the lead database, and is never stored in any shared or version-controlled repository.

2. Information We Collect

2.1 Get Started Form (Lead Data)

If you submit the Get Started form, we collect:

  • Your name and email address
  • How many QuickBooks companies you need archived
  • How many years the business has been operating
  • Whether the QuickBooks subscription is still active
  • The reason for archiving (your situation)
  • Whether the company ran QuickBooks Payroll
  • Any notes you choose to add

We use this information to respond to your inquiry, qualify the engagement, and deliver the Service. New submissions also trigger a notification to our private Slack workspace so we can respond quickly; the notification contains the form contents.

The form is for intake only. Please do not paste financial records, tax documents, account numbers, or payroll details into the notes field. If you do, we will delete them from the lead systems promptly.

2.2 Client Financial Data (Archive Engagements)

If you engage us for an archive, we access the contents of the QuickBooks Online company you designate, through the accountant-user invitation you send us, including:

  • Your general ledger and transaction data
  • Financial reports
  • Transaction attachments and source documents
  • The audit log
  • Payroll reports, where applicable

Depending on what the company contains, these records may include personal and sensitive information about owners, employees, customers, vendors, and other individuals (names, contact details, bank and account information, taxpayer identifiers, wage information).

We collect this data for exactly one purpose: producing and delivering your archive.

2.3 Website Visitors

If you just browse the site, the data involved is ordinary web-request metadata seen by our hosting provider, as described in Section 1, plus the advertising measurement described here. We do not use Google Analytics, and we do not collect payment information through this website.

We run two measurement tools on this website. Ahrefs Web Analytics is cookie-free and records aggregate page views only. Google Ads conversion tracking uses a Google tag to tell us whether a visit that arrived from one of our ads went on to become an inquiry or an order. That tag sets advertising cookies and sends a limited set of event data to Google, which may include a hashed version of an email address you type into one of our forms, so that Google can match an order back to an ad click.

We also keep our own first-party visit analytics, stored on our systems (Supabase) and shared with no advertising network. For each page view we record the page visited, the referring website (if any), campaign parameters in the link you followed, your country, and whether the visit came from a phone or a computer, tied to a random identifier stored in your browser. We use this only to understand which articles, referrals, and campaigns bring visitors and inquiries. We do not record your IP address, and this identifier is not shared with anyone.

This measurement covers activity on this website only. The Google tag has no access to a QuickBooks company, and none of the customer records described in Section 2.2 are ever sent to Google Ads or any other advertising system. You can opt out by blocking cookies in your browser or through your Google Ads settings.

3. How We Access Your Books

We only ever access a QuickBooks company through access you grant us (an accountant-user invitation), and only after you have signed a written engagement agreement describing the engagement and consenting to the processing it involves.

We use that access only to view and export: we do not create, edit, or delete anything in your books. QuickBooks accountant access is not a technically restricted read-only permission, so this is a promise about our conduct, and your own QuickBooks audit log is one place you can check it, to the extent QuickBooks records that activity.

After delivery is confirmed, we stop using that access, and we ask you to revoke the accountant-user invitation from your QuickBooks account (removal is controlled on your side).

4. AI-Assisted Processing

Parts of the archive service are performed with AI assistance. This means portions of your QuickBooks data (screens, reports, and file listings) are processed by our AI provider, Anthropic, through its commercial API. Under Anthropic's commercial terms:

  • Your data is not used to train AI models
  • Your data is retained by Anthropic only for a limited period after processing, with longer retention only where required for safety or legal compliance; we do not currently have a zero-data-retention agreement with Anthropic
  • AI tools are used solely to produce your archive and for no other purpose

We obtain your signed, written consent before any processing begins. We will never remove or soften this disclosure: if you engage us, your financial data passes through the Anthropic API, and you should make your decision knowing that.

5. Service Providers (Subprocessors)

We keep the list short, and we group it by which system each provider belongs to.

5.1 Providers That Receive Your QuickBooks Data (Archive Engagements Only)

  • Anthropic — AI-assisted processing during archive production, under commercial API terms that prohibit training on your data and retain it only for a limited period after processing, with longer retention only for safety or legal-compliance purposes (see Section 4)
  • Google Workspace (Google Drive) — used to hand you the finished archive. We share the archive directly with the email address you gave us, rather than posting a public link, so only that account can open it. Google encrypts it in transit and at rest and does not use Workspace content for advertising. If an archive is too large for that path, we will identify the alternative delivery service to you in writing before we use it. The hosted copy is removed, and access revoked, on the same deletion schedule as our working copies in Section 7

5.2 Providers That Never Receive Your QuickBooks Data

  • Supabase — stores Get Started form submissions
  • Cloudflare — hosts and serves this marketing website
  • Slack — receives an internal notification when a new form submission arrives
  • Stripe — processes invoice and payment information for engagements (contact details, invoice amounts, transaction status). Card or bank credentials are entered on Stripe's own payment page, not on this website, and Stripe never receives your QuickBooks data

If this list changes, we will update this page. Questions about any provider: [email protected].

6. What We Do Not Do

  • We do not sell your information
  • We do not use your financial data for any purpose other than producing your archive: no analytics, no product development, no marketing, no aggregated or de-identified reuse
  • We do not permit your data to be used to train AI models
  • We do not provide ongoing storage; after delivery is confirmed, we delete our working copies as described in Section 7, and keeping copies of the delivered archive is your responsibility

We share information only with the service providers described in this policy, with people you authorize, and where necessary to comply with law or legal process or protect rights or security, in each case subject to applicable confidentiality and tax-return-information rules. Ordinary engagement records that do not contain your financial data may also be shared where necessary to obtain professional advice or complete a business transaction; the contents of your QuickBooks company are not.

7. Data Retention and Deletion

7.1 Lead Data

Kept while we are working with you or while your inquiry is open. On request, we will delete the lead records we control, subject to legal, security, dispute-resolution, and recordkeeping limits.

7.2 Your Books (Working Copies)

Working copies live in an isolated, per-client folder on encrypted equipment for the duration of the engagement only:

  • We delete our working copies within 7 days after you confirm receipt of your archive
  • If we do not hear from you, receipt is deemed confirmed 14 days after we make the archive available, and the same deletion clock starts then; the only exception is time we spend fixing a problem you have reported
  • Customer data is never committed to shared or version-controlled repositories
  • We may keep ordinary business records about the engagement (the signed engagement agreement, invoices, correspondence); we do not intentionally place your QuickBooks exports, reports, attachments, or payroll data in those records, and we ask that you not send financial records through ordinary email or intake channels

7.3 The Delivered Archive

Once delivered and confirmed, the archive is yours and lives with you. We are not a storage service, so keep at least two copies in places you control.

8. Data Security

We maintain a written information security program aligned with the FTC Safeguards Rule and IRS Publication 4557. In practice that includes:

  • Full-disk encryption on equipment that holds working copies
  • Encrypted connections for systems that carry customer data
  • Multi-factor authentication on the accounts used to provide the Service
  • Per-client isolation of working data
  • Secure disposal after delivery

No security program eliminates all risk, and we will not pretend otherwise, but the short-lived, delete-after-delivery design limits how much of your data exists to be exposed at any time.

9. Breach Notification

If we experience a data breach affecting your information, we will provide the notices required by applicable law. That may include notice to affected individuals under state breach-notification laws and, if the Safeguards Rule applies to us, notice to the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unauthorized acquisition of unencrypted customer information of at least 500 consumers.

10. Tax Professionals (IRC Section 7216)

If you are a tax return preparer engaging us on a client's behalf, disclosures of tax return information are governed by IRC section 7216 and its regulations. Where the engagement qualifies, we operate as your contractor for auxiliary services under Treas. Reg. 301.7216-2 and sign a written acknowledgment that sections 7216 and 6713 apply to us in that role. Because producing the archive involves AI-assisted processing through Anthropic's commercial API, the engagement must also establish a lawful section 7216 basis for that processing; our acknowledgment as your contractor does not by itself authorize that further disclosure. Where taxpayer consent is required or advisable, we can provide a consent template for Form 1040-series return information intended to be consistent with Rev. Proc. 2013-14. Ask us for the tax-professional engagement pack before sending any client data.

11. Your Choices and Rights

You can ask us to:

  • Show you the personal information we control about you
  • Correct information we control
  • Delete it

These requests cover lead, contact, and engagement information we control. Requests concerning information inside a client's QuickBooks company are referred to the business or tax professional that controls those records; we assist only when authorized and legally permitted, and our access is view-and-export only, so we cannot edit QuickBooks data. We honor reasonable requests regardless of which state you live in, after verifying your identity and authority, and subject to legal, security, confidentiality, tax-return-information, and recordkeeping limits. Some state privacy laws may give you additional statutory rights if they apply to us, and some information we handle (such as tax return information, or data processed under federal financial-privacy law) may be exempt from certain state privacy-law rights or subject to different rules.

To make a request, email [email protected]. We will respond within 30 days, or tell you within that period if verification or a complex request reasonably requires more time.

12. Children's Privacy

The Service is for businesses and their advisors. It is not directed at children, and we do not knowingly collect information from anyone under 16.

13. Changes to This Policy

If we change this policy, we will update this page and the date at the top. Material changes that affect an active engagement will be communicated to you directly.

14. Contact

If you have questions about this Privacy Policy or your data, contact:

Lion, LLC (d/b/a Books Backup)
Email: [email protected]