Legal

Privacy Policy

How CardenPay collects, uses, protects, retains, and deletes information, including data obtained through a QuickBooks Online connection.

Last updated: September 28, 2026

1. Scope and our role

This Privacy Policy explains how CardenPay LLC, a Wyoming limited liability company (“CardenPay,” “Carden,” “we,” or “us”), handles information when you visit CardenPay.com, use a savings calculator, communicate with us, or connect accounts to Carden's payment-cost analysis and data-enrichment services (collectively, the “Service”). The Service is intended for business representatives acting for a company, not for personal or household use.

When CardenPay processes data for a paying client under a Revenue-Share Services Agreement, the client generally controls that data and CardenPay processes it on the client's behalf. The separate Data Processing Agreement (“DPA”) governs that processing and controls over this Policy if there is a conflict concerning client data. The client is responsible for required notices and permissions for data it directs CardenPay to process.

2. Information we collect

Information you provide directly

  • Contact and account information: name, business email, phone number, company name, job role, authentication identifier, workspace membership, and permissions.
  • Calculator and inquiry information: approximate card volume, business details, answers submitted through forms, and information exchanged during scheduling, sales, onboarding, account setup, and support.
  • Configuration and contract information: connected-account settings, approved mappings, service instructions, Order Forms, savings statements, invoices, and payment status.

Information from connected accounts

If a paying client authorizes an accounting, invoicing, payment-gateway, processor, or settlement account, CardenPay accesses the business records needed to provide the signed service. Depending on the authorized provider, this may include company settings, customers, items, invoices, order or purchase- order references, line items, quantities, unit prices, units of measure, stock-keeping units, tax, shipping, discounts, accounting payments, payment and refund records, settlement and interchange reporting, source identifiers, and source timestamps.

CardenPay uses OAuth or restricted API keys instead of asking for raw provider passwords. CardenPay does not access or store full payment-card numbers, card verification codes, or magnetic-stripe data.

Information collected automatically

We collect device and usage information such as IP address, browser and device type, pages and features used, timestamps, referring URL, approximate location, cookie identifiers, session and security events, and diagnostic logs. Necessary cookies support authentication and security. Where enabled, analytics services help us understand aggregate website and product use. Browser settings or available consent controls can limit optional analytics.

3. QuickBooks data

When a client connects QuickBooks Online, authorization occurs on Intuit's OAuth consent page. CardenPay does not receive the user's Intuit password. The current connector requests the QuickBooks accounting scope and uses read-only application behavior to import relevant company information, accounting preferences, customers, items, invoices, invoice line items, accounting payments, source identifiers, update timestamps, and related response metadata. It does not use the QuickBooks Payments API and does not create, update, or delete QuickBooks records.

CardenPay uses QuickBooks data only for the client-authorized Service, including to:

  • maintain an auditable copy of relevant accounting source records;
  • match invoices with separately authorized payment and settlement evidence;
  • evaluate data completeness, eligibility constraints, and processing-cost outcomes;
  • prepare factual, client-authorized commercial transaction fields for supported workflows;
  • identify stale, missing, unsupported, or unreconciled data; and
  • provide reports, customer support, security monitoring, and audit history.

At a client's direction, factual transaction fields derived from QuickBooks records may be transmitted to that client's separately authorized payment gateway, processor, or applicable card network as part of the enrichment service. CardenPay does not give independent third parties access to QuickBooks data for their own purposes, sell QuickBooks data, use it for behavioral advertising, or use it to train general-purpose artificial intelligence models. CardenPay does not invent missing transaction facts.

A client administrator may disconnect QuickBooks in Carden, and a user may disconnect through Intuit. CardenPay immediately disables local use of the connection, stops eligible imports, requests Intuit token revocation, and deletes the encrypted token set after successful revocation. Disconnecting stops new imports but does not itself delete records already imported; Section 7 explains deletion.

4. How we use information

  • operate, maintain, secure, support, and improve the Service;
  • authenticate users and enforce workspace, role, and integration permissions;
  • map and submit client-authorized commercial transaction fields;
  • calculate, document, and invoice Net Realized Savings under a signed agreement;
  • provide estimates, reports, support, and account communications;
  • diagnose errors, prevent fraud and abuse, and maintain security and audit records;
  • comply with legal obligations and enforce agreements; and
  • create aggregated or deidentified information that does not reasonably identify a person or client.

Where applicable law requires a legal basis, we process information to perform a contract, pursue legitimate interests such as providing and securing the Service, comply with legal obligations, or act with consent. Consent may be withdrawn where it is the basis, without affecting earlier processing.

5. How we share information

CardenPay does not sell personal information. We share information only as follows:

  • At the client's direction: with authorized Company users, Connected Accounts, payment gateways, processors, and applicable card networks as needed to perform the signed service.
  • Service providers: with vendors providing hosting, databases, authentication, monitoring, communications, analytics, billing, and other infrastructure on CardenPay's behalf under confidentiality, security, and use restrictions.
  • Legal and safety: when reasonably necessary to comply with law or legal process, protect rights or safety, investigate abuse, or secure the Service.
  • Business transfers: in connection with financing, due diligence, a merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protection.

CardenPay does not share personal information for cross-context behavioral advertising. Contracted service providers may process client data only to provide services to CardenPay, not for their own independent purposes.

6. Data security

CardenPay uses administrative, technical, and physical safeguards designed to protect information, including encryption in transit, authenticated encryption of integration credentials at rest, tenant separation, role-based access, server-side authorization, audit logging, webhook verification, secure development practices, monitoring, and incident response. No system is completely secure, and we cannot guarantee absolute security.

Clients are responsible for managing authorized users and Connected Accounts, protecting credentials, and promptly reporting suspected unauthorized access to hello@cardenpay.com.

7. Retention and deletion

CardenPay retains information for as long as reasonably necessary to provide the Service; establish and apply the agreed baseline; calculate, support, and invoice Net Realized Savings; preserve reproducible financial and audit records; resolve disputes; secure the Service; and meet tax, accounting, contractual, and legal obligations. A signed DPA may set shorter or more specific periods.

QuickBooks OAuth credentials are deleted after disconnection and successful revocation. Temporary invitation and authorization records expire and are deleted or rendered unusable. Imported accounting, payment, settlement, report, and audit records may remain after disconnection because they support historical results and contractual obligations.

An authorized client administrator may request access, export, correction, or deletion by emailing hello@cardenpay.com. After verifying identity, authority, and scope, CardenPay will delete or deidentify covered active-system data within a commercially reasonable period unless law, a legal hold, security needs, a dispute, or a signed agreement requires retention. Restricted backup copies may remain until normal rotation. We may retain minimal records of the request and completion to demonstrate compliance.

8. Your choices and rights

You may revoke CardenPay's access to a Connected Account through that provider or Carden's controls. Depending on applicable law, you may also have rights to access, correct, delete, or obtain a copy of personal information; object to or restrict processing; withdraw consent; or appeal a decision.

Submit a request to hello@cardenpay.com. We may verify your identity and authority. If CardenPay processes the information only for a client, we may route the request to that client. Authorized agents may submit requests where permitted. CardenPay will not discriminate against a person for exercising an applicable privacy right.

9. International data

CardenPay is based in the United States. CardenPay and its service providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, CardenPay uses contractual or other lawful safeguards for cross-border transfers.

10. Children

The Service is for business use by adults and is not directed to children under 18. CardenPay does not knowingly collect personal information from children. Contact us if you believe a child provided information so we can review and delete it as appropriate.

11. Changes and contact

CardenPay may update this Policy to reflect changes in the Service, practices, or law. We will post the updated version here and change the “Last updated” date. Material changes affecting client data will receive additional notice when required.

Questions and privacy requests may be sent to CardenPay LLC at hello@cardenpay.com. Include the Company name and enough information to route the request, but do not send passwords, OAuth tokens, card data, or sensitive accounting records by email.

Questions about Carden's legal terms or privacy practices may be sent to hello@cardenpay.com.