Consolidt is operated by Consolidt LLC, a Colorado limited liability company. This policy explains what data the Consolidt service collects, what it does with that data, and what it deliberately does not do. It covers the application at app.consolidt.com and this website.
Consolidt is a business tool used by finance teams. It is not directed at consumers and is not intended for anyone under 18.
Consolidt reads your accounting data, computes a consolidation, and gives it back to you. We connect to QuickBooks Online in read-only fashion and never write to your books. Your general ledger detail and the workbook we generate from it exist only in memory for the length of a run and are never written to our disks. We do not sell your data, we do not use it for advertising, and we do not use your financial data to train machine learning models.
Your work email address, a password stored only as a PBKDF2-HMAC-SHA256 hash with a per-user random salt (we never store or have access to your password itself), your organization name, and session tokens with expiry times.
For each QuickBooks company you connect: the Intuit company identifier (realm ID), the company name as QuickBooks reports it, and an OAuth refresh token. The refresh token is encrypted at rest using authenticated symmetric encryption (Fernet: AES-128-CBC with an HMAC-SHA256 signature) before it is written to our database.
Your chart-of-accounts mapping: account names, numbers, and labels, together with how you have grouped entities and which relationships you have designated as intercompany. This is structural information about how your books are organized. It is retained so you do not have to re-map every period.
When you run a close, Consolidt requests account lists and financial report data for the periods and companies you select. This data is held in server memory for the duration of the run and is not written to our database. See section 4 for the one exception.
Ordinary server logs generated by our hosting provider, such as IP address, timestamp, and requested path, used for security and troubleshooting.
| Data | Stored | Retention |
|---|---|---|
| Account and password hash | Encrypted-in-transit, on an access-controlled server disk | Until you delete the account |
| QuickBooks refresh token | Encrypted at rest in our database | Until you disconnect that company or delete the account |
| Chart-of-accounts mapping | Our database | Until you change or delete it, or delete the account |
| General ledger and report data | Server memory only, for the run | Discarded when the run completes or the process restarts |
| Generated close pack | Built in memory and streamed to you | Never written to the server filesystem |
| Server logs | Hosting provider | Per the provider's standard retention |
Your financial results never touch our disks. General ledger and report data is pulled for a run and held in process memory; the consolidated workbook you download is assembled in memory and streamed directly to your browser. Neither is written to the server filesystem, neither is backed up, and both are gone when the run ends.
We use a small number of service providers to run Consolidt. We do not share your data with anyone else, and none of these providers are permitted to use it for their own purposes.
We may disclose information if we are legally required to, or to protect our rights or the safety of others. If we are ever compelled to produce customer data, we will tell you unless we are legally prohibited from doing so.
All traffic to Consolidt is served over HTTPS. Session cookies are marked Secure and HttpOnly. Passwords are salted and hashed, never stored in recoverable form. QuickBooks refresh tokens are encrypted at rest with a key held outside the database. Each organization's data is isolated by tenant, and every request that touches organization data is checked against the signed-in user's organization.
We want to be straightforward about our stage: Consolidt is in private beta and holds no third-party security certification such as SOC 2 or ISO 27001. We will say so plainly rather than imply otherwise. If a certification becomes a requirement for you, tell us and we will discuss the timeline honestly.
Depending on where you are, you may have additional rights under laws such as the Colorado Privacy Act or the California Consumer Privacy Act, including rights of access, correction, deletion, and the right not to have personal data sold. We do not sell personal data. To exercise any right, email us and we will not discriminate against you for asking.
Consolidt is operated from the United States and your data is processed and stored there. If you are outside the United States, do not connect data to Consolidt unless you are comfortable with that.
If we change this policy in a way that materially affects how we handle your data, we will notify account holders by email before the change takes effect and update the date at the top of this page.
Questions, requests, or concerns: hello@consolidt.com
Consolidt LLC, 992 S 4th Ave, Unit 100, PMB 448, Brighton, CO 80601, United States