BNM Fleet Ledger

WINDOWS APPLICATION · LOCAL ACCOUNTING DATA

Privacy policy

BNM-controlled Windows deployment · Effective September 18, 2026

Local application data

BNM Fleet Ledger keeps imported bank and Turo records, classifications, mappings, audit history, retrieved QuickBooks accounting data and reports on the Windows installation. QuickBooks tokens are encrypted there using Windows user-bound DPAPI. Those accounting records and tokens are not sent to this companion.

Temporary authorization handoff

When you explicitly connect, the companion temporarily processes an OAuth authorization code, random state and realm/company identifier supplied through Intuit's browser redirect. It encrypts the result to the initiating installation's public key before holding it in a private, shared, in-memory relay store. Only a separate retrieval credential can retrieve it. The result is removed on retrieval or expiration. Application restarts do not normally remove it, but a relay-store restart or failure can discard pending connections. The configured lifetime is at most ten minutes from registration; the default is five minutes.

The companion does not exchange authorization codes for tokens and does not hold the Intuit Client Secret. The Windows application communicates directly with Intuit for tokens and accounting reads.

Website and infrastructure

No analytics, advertising, cookies or third-party scripts are used. Servers necessarily process network addresses and request metadata to deliver HTTPS. The application does not record request URLs, query strings, bodies or credentials. The relay store retains public keys, hashed verification values and encrypted results for the configured short lifetime; persistence and backups are disabled. Hosting providers also process infrastructure metadata under their own policies. Provider logging and retention must be checked before production authorization; application logging settings do not control provider infrastructure.

Control and retention

You may abandon a connection and allow the handoff to expire. You may disconnect using the Windows application or QuickBooks Connected apps. Local records remain subject to BNM's local retention and backup practices; this website cannot erase them. Intuit operates its own authentication and accounting services under its own terms and privacy practices.

Contact

For privacy questions, contact your BNM Enterprises administrator through your existing business contact. Do not include secrets or accounting data in website requests.