← Two Birds KPI Dashboard

Privacy Policy

Last updated: 14 August 2026

In short. The Two Birds KPI Dashboard is a private internal tool. It reads Two Birds' own accounting data from QuickBooks Online in order to display that data back to Two Birds staff. It is not distributed to the public, it has no customers, and it does not sell, share, or transmit data to any third party for advertising, analytics, or profiling.

1. Who this covers

This policy applies to the “Two Birds KPI Dashboard” application (the “Application”) operated by Two Birds (“we”, “us”), a childcare provider operating in Washington DC, Virginia and Maryland. The only users of the Application are Two Birds’ own officers, employees and contractors who have been individually authorised.

2. What data the Application accesses

Connected to QuickBooks Online under the com.intuit.quickbooks.accounting scope, the Application reads:

This is Two Birds’ own corporate accounting data, accessed from Two Birds’ own QuickBooks company. The Application does not access any other organisation’s QuickBooks data.

3. What the Application does not access

Where accounting records unavoidably contain a counterparty name (for example a vendor or a customer on an invoice), that information is displayed only to authorised Two Birds staff and is never exported to any third party.

4. Why the data is used

Solely to produce internal management reporting for Two Birds — statements of profit and loss, balance sheet, cash flow, and related operating metrics. The data is not used for advertising, is not sold, is not licensed, and is not used to train machine-learning models.

5. Where the data is stored, and for how long

6. Who can see it

Access to the Application is restricted by Cloudflare Access to an explicit allowlist of Two Birds email addresses, each authenticated by Google sign-in. Anyone not on that list cannot reach the Application at all. There is no public, anonymous, or guest access.

7. Disconnecting and deletion

The connection to QuickBooks Online can be revoked at any time from within QuickBooks, or by contacting us at the address below. On disconnection the stored OAuth tokens are invalidated and any cached accounting data is deleted. To request deletion of data held by the Application, email mayank@twobirdsinc.com.

8. Third parties

The Application relies on Intuit (QuickBooks Online) as the source of the data, Google (Sheets and Apps Script) for a secondary reporting pipeline, and Cloudflare for hosting and access control. No other third party receives the data. There are no advertising networks, trackers, or third-party analytics in the Application.

9. Security

Authorisation uses OAuth 2.0; the Application never sees or stores QuickBooks sign-in credentials. Client secrets and tokens are held as encrypted environment secrets on the hosting platform. All traffic is served over HTTPS. Authentication to the Application itself is enforced at the network edge before any application code runs.

10. Changes

If this policy changes materially, the revised version will be published at this URL with an updated date above.

11. Contact

Two Birds
mayank@twobirdsinc.com