← InCite home

Privacy Policy

Last updated: October 6, 2026.

This Privacy Policy explains how Quast Ventures LLC (“Quast Ventures,” “we,” “us,” or “our”) collects, uses, and discloses information in connection with InCite Bookkeeping, InCite Books, InCite Accounting, the InCite desktop application, InCite Payments, and related websites and downloads (the “Services”). It should be read with the Terms of Service.

1. Introduction

InCite is accounting and bookkeeping software for independent businesses, CPA firms, accountants and staff invited by firms, and clients whose books are connected to a firm’s InCite account. We process business and personal information as needed to operate that software. This Policy does not apply to third-party websites or processors except as described below.

These terms do not constitute legal advice. Quast Ventures LLC may update this Policy as described in Section 18.

2. Operator

InCite Bookkeeping is created, owned, and operated by Quast Ventures LLC. InCite Books / InCite Accounting is a product of Quast Ventures LLC.

The controller of personal information processed through the hosted Services is Quast Ventures LLC. When a Firm or Client uses InCite to store books about its own employees, contractors, or customers, that Firm or Client is typically the business that decides why those records are kept; we process that data to provide the Services.

3. Scope and Defined Terms

“Personal information” means information that identifies, relates to, or could reasonably be linked to a particular person or household, as defined under applicable U.S. state privacy laws (including the California Consumer Privacy Act as amended, the “CCPA,” where it applies).

“Customer Content” means ledger data, invoices, bills, bank lines, tax workpapers, 1099 packets, documents, invite codes, audit-trail records, and similar materials you or your invitees submit to the Services.

This Policy covers the web application, authentication, hosted database, InCite Payments pay links, transactional email, and the desktop application’s communication with hosted Services. It does not cover Gusto’s processing of payroll as employer-of-record or payroll processor, Stripe’s processing as a payment processor, or Plaid’s processing as a bank-connectivity provider, except to the extent those parties receive data from InCite.

4. Information We Collect

4.1 Account and identity

Name, email address, authentication credentials and tokens, organization membership, roles, and Firm or Client affiliation. Authentication is handled by Supabase.

4.2 Business and ledger data

Company profile information (such as legal name, addresses, and employer identification numbers you enter), chart of accounts, journals, invoices, bills, vendors, customers, bank register lines, payroll worksheets imported or entered by you, tax review workpapers, 1099-NEC packets and related TIN/W-9 fields you store, documents you upload, invite codes, and the audit trail of actions in the workspace.

4.3 Bank connectivity

If you connect a bank with Plaid, we receive account identifiers, balances, and transaction data that Plaid provides, plus tokens needed to maintain the connection. We do not receive your online banking password.

4.4 Payments and billing

Subscription billing status, Stripe customer and subscription identifiers, invoice pay-link metadata, amounts, fee amounts, payout identifiers, and settlement/reconciliation status. We do not collect or store raw card numbers or CVV. See Section 8.

4.5 Payroll integration

If you connect Gusto, we receive connection tokens and payroll-related data Gusto exposes for bookkeeping (for example company name, pay-run journals, or employee identifiers needed to post books). Gusto remains the payroll processor.

4.6 Usage, device, and log data

IP address, browser or desktop app version, device type, pages or routes requested, approximate timestamps, and diagnostic logs reasonably needed to operate, secure, and debug the Services.

4.7 Communications

Messages you send to support or through in-product invites. Transactional email (for example invite or subscribe notices) may be sent through Resend when configured.

4.8 Information we do not intentionally collect

We do not operate InCite as a live IRS FIRE e-file transmitter. 1099 features store workpapers and export packets you choose to create; they are not an IRS submission unless you use a separate transmitter. We do not use ledger contents to train public machine-learning models.

5. How We Use Information

We use information to:

  • provide, host, secure, and maintain the Services, including firm/client isolation and roles;
  • authenticate Users and enforce subscriptions and paywalls;
  • process software billing and InCite Payments through Stripe;
  • connect banks (Plaid) and payroll (Gusto) when you enable those features;
  • send transactional email and invite or billing notices;
  • post collections, fees, and settlements to the books you configure;
  • maintain an audit trail and investigate abuse, fraud, or security incidents;
  • comply with law, enforce the Terms of Service, and protect rights and safety; and
  • improve reliability and user experience of the software (not by selling your books).

6. How We Disclose Information; Processors

We disclose information to service providers that process it on our instructions, to parties you authorize, and as required by law. High-level subprocessors and processors include:

  • Supabase — authentication and hosted database.
  • Vercel — application hosting and delivery of the web Services.
  • Stripe — subscription billing and InCite Payments (card and ACH). Stripe is the PCI-compliant payment processor.
  • Plaid — bank account connection and transaction feeds.
  • Gusto — payroll processing you enable; Gusto bills payroll separately.
  • Resend — transactional email when that integration is configured.

We may use additional infrastructure, error-reporting, or security vendors that process limited account or log data on our instructions. We may disclose information to a Firm, Client, or User you invite; to professional advisers under confidentiality; to a successor in a reorganization or sale of the business, subject to this Policy; or if we believe disclosure is required by law, legal process, or to prevent harm.

Invoice pay-link customers generally provide payment details directly to Stripe. We receive payment status and metadata needed to receipt the invoice and post the books.

7. Firm and Client Isolation; Access

Customer Content is stored by organization. Firm views are limited to Client books the Firm is permitted to access. Invited accountants see assigned books and the Firm name, not an automatic dump of every Client. Role-based access is enforced in the application and, on hosted Postgres, with row-level security where implemented.

Workspace owners and Firm administrators control invitations. If you invite a person, they will see the Customer Content associated with that invitation. You are responsible for mistaken invites and for revoking access.

8. InCite Payments and Payment Card Data

Card and ACH collection on invoices is processed by Stripe. InCite does not store primary account numbers (PAN) or CVV. Stripe is responsible for PCI DSS as the payment processor. We store tokens, payment-intent or checkout identifiers, amounts, fee actuals, payout identifiers, and the ledger impact of the payment.

The User must confirm the payout account used for settlements. Confirmation, destination choice, and reconciliation remain the User’s, Client’s, CPA’s, and Firm’s responsibility as applicable.

Test or sandbox payment modes do not move production money and should not be used with live card or bank credentials of real customers.

9. Cookies, Authentication, and Similar Technologies

We use cookies and similar storage that are reasonably necessary to authenticate sessions (Supabase auth cookies), keep you signed in, remember workspace or display preferences, and protect the Services. The desktop application may store session or preference data locally.

We do not use ledger contents for cross-context behavioral advertising. If we later use optional analytics cookies that are not strictly necessary, we will describe them here and, where required, provide a choice.

10. Desktop Application

When you use InCite Desktop, a local SQLite company file may reside on your computer. You can export CSVs or a SQLite copy from available export tools. You are responsible for backups of local files, device security, and who can access that computer. Hosted Customer Content remains subject to this Policy; local copies are under your control.

11. Integrations

Enabling Stripe, Plaid, or Gusto is your instruction to share the data those products require. Their privacy policies govern their processing. Gusto is not an InCite payroll product; payroll amounts, tax deposits, and wage payments are Gusto’s and the employer’s responsibility. Plaid connections can be revoked in Plaid and in InCite. Disconnecting an integration may not delete historical lines already posted to your books.

12. Retention

We retain account and Customer Content for as long as the organization remains active and for a reasonable period afterward so you can export records, resolve billing, or meet bookkeeping continuity. Hosted backups follow the database provider’s retention. We may retain limited records longer where needed for legal claims, security, tax on our own fees, or audit of our systems.

You may request export or deletion as described in Section 14. Residual copies in encrypted backups expire on the backup cycle.

13. Security

We use reasonable administrative, technical, and organizational measures designed to protect Customer Content, including access controls, encrypted transport to the hosted application, and processor security practices. No method of transmission or storage is completely secure. We do not claim SOC 2, PCI DSS (as a merchant storing cards), or similar certifications in this Policy. Payment card data is handled by Stripe, not stored by InCite.

You are responsible for device security, password strength, and the access you grant.

14. Your Privacy Rights (including California)

Depending on your state of residence, you may have the right to request access to, correction of, or deletion of personal information; to receive a copy of certain information in a portable format; to appeal a denial; and not to receive discriminatory treatment for exercising privacy rights. California residents may have additional CCPA rights, including the right to know the categories of personal information collected, sources, purposes, and categories of third parties to whom it is disclosed, as described in this Policy.

To exercise rights, use the support or contact channels published at incitebooks.com or ask the workspace owner to export or delete organization data. We will verify the request and respond as required by applicable law. Authorized agents may submit requests where the law allows, with proof of authorization.

We do not operate a GDPR Article 27 representative or appoint a Data Protection Officer. If you are in the EEA, UK, or another jurisdiction with extra-territorial privacy rules, do not use the Services unless you have determined that your use is lawful; we do not represent that the Services are offered with GDPR-specific transfer mechanisms.

15. Sale of Personal Information

We do not sell personal information, and we do not sell Client books or ledger contents. We do not share personal information for cross-context behavioral advertising as those terms are used in the CCPA. We do not use Customer Content to train public models.

16. Children

The Services are not directed to children and are not for anyone under 18. We do not knowingly collect personal information from children. If you believe we have done so, contact us and we will delete the information.

17. United States Orientation

The Services are operated from the United States. Information is processed in the United States and in locations where our processors maintain infrastructure. If you access the Services from elsewhere, you consent to that processing. The Services are designed for U.S.-oriented bookkeeping workflows.

18. Changes

Quast Ventures LLC may update this Privacy Policy from time to time. We will revise the “Last updated” date and may provide in-product or email notice for material changes. Continued use after the effective date constitutes acceptance of the updated Policy.

19. Contact

Privacy requests and questions should be directed to Quast Ventures LLC through the support or contact channels published at incitebooks.com, or through the email associated with your InCite account. Please identify the organization and the nature of your request (access, correction, deletion, or appeal).

20. Not Legal Advice; Updates

This Privacy Policy does not constitute legal advice. It describes our current practices for the InCite software platform. Quast Ventures LLC may update it. Have qualified counsel review this Policy before relying on it for your jurisdiction or compliance program.

See also Terms of Service.

© 2026 Quast Ventures LLC. InCite Books / InCite Accounting is a product of Quast Ventures LLC.