Security
You’re about to give a company you’ve never heard of access to your accounting system and your mailbox. Here is exactly what that gets us, in full.
QuickBooks' own identifier for the invoice. It's how we match the same invoice on the next day's sync instead of creating a duplicate.
The number your client knows it by. Every reminder names it, because someone holding hundreds of invoices needs to know which one you mean.
Who owes it. Used in the subject line so the reminder is identifiable at a glance, and to look up the right contact at send time.
Where the reminder goes. The one on the invoice, not one we found somewhere else.
So a message can say “invoice 1241 from the fourteenth” rather than a bare number.
The whole schedule hangs off this. Every reminder is timed as an offset from it — three days before, the day after, a week, a fortnight, a month.
Shown alongside the balance on part-paid invoices, so a message says “$239 of the original $459” rather than quoting a number from nowhere.
What's actually still owed. This is the number we chase, and it's re-read live from QuickBooks in the moment before anything sends.
Not stored, at all: line items, item descriptions, tax detail, postal addresses, customer notes, payment records, bank details, payroll, general ledger. QuickBooks offers all of it and it’s discarded as it arrives — the database has no columns for it, which is a stronger guarantee than a policy saying we won’t look.
How it’s held
None of this is novel. It’s the boring, well-understood version of each decision, which is the version you want.
Everything moves over TLS — between your browser and us, and between us and QuickBooks or Google. Nothing about your invoices crosses a network in the clear.
The credentials for your accounting system and mailbox are encrypted with AES-256-GCM before they're written, and the key is held apart from the database. A copy of the database on its own can't read your books or send mail as you.
A one-time link emailed to the address on your account, good for thirty minutes and one use. There is no password in this product to be guessed, reused or leaked, and what we store is the link's hash — not the link.
Revoke us from your QuickBooks or Google settings and the token is dead immediately; every sequence stops on the next run and nothing further is sent. You don't need to ask us, and you don't need us to agree.
Invoice records are removed within 30 days of an account ending. The history of what was sent on your behalf is kept as a record of what was said in your name — ask and we'll delete that too.
The legal version of all this is in the privacy policy, written to be read rather than to be survived.
Email ben@payspotter.com and a person will answer — usually the same day, and without a sales call.