1. Who we are
Impact Codes ("we", "us") builds and operates its own software products — including its accounting platform — and develops custom software for our clients. We are based in Boston, Massachusetts, United States. For anything in this policy, write to contact@impactcodes.com.
This policy covers impactcodes.com, every application we provide and the services we run alongside them. It is written to apply to all of our software rather than to one product, so that the same commitments hold whichever of our systems you use. Where we build custom software for a client, that client is normally the controller of the data in their own system, and their own policy applies to it.
The applications this policy covers. Today they are IC Accounting, our accounting platform, sold in editions and run as a separate instance for each customer; and custom software we design, build and host for an individual client. Naming them is not a limit on this policy — it applies to whatever we run for you, and adding a product does not require a new one.
Of these, IC Accounting is the application that connects to Google. It is published and operated by Impact Codes, and the Google application you are shown when you connect is registered as “Impact Codes” — the same organisation named at the top of this policy. Section 5 describes that connection in full: the single permission it asks for, what it reads, what we store, and how to revoke it.
2. What we collect
Information you give us
- When you contact us: your name, email address, and anything else you choose to put in the message — optionally your company, phone number and budget range.
- When you buy: your name, work email, company name and address, tax identifier where you supply one, phone number, the workspace address you choose, and any note you add to the order.
- When you use our software: the account details your administrator creates for you — name, email, role and permissions.
Information collected automatically
- Server logs: IP address, browser and operating system, the pages requested and when. Kept to keep the service running and to investigate abuse and faults.
- Analytics: aggregate usage of this website — which pages are read, how people arrive. We do not use it to build a profile of you, and it is never joined to the contents of a workspace.
Payment information
We never see your card details. Payments are taken by a third-party payment provider on their own pages and infrastructure. Card numbers, expiry dates and security codes are never sent to, processed by, or stored on our systems. We receive only confirmation that a payment succeeded or failed, the amount, and the provider's reference for it.
3. Why we use it
| What we use | What for | Our basis |
|---|---|---|
| Order and company details | Taking your order, building your workspace, invoicing you, supporting you | Performance of a contract |
| Contact form submissions | Replying to you, and following up if you asked us to | Legitimate interest, or steps taken at your request before a contract |
| Account details in our software | Signing you in, applying your permissions, keeping an audit trail | Performance of a contract |
| Server logs | Security, fault diagnosis, abuse prevention | Legitimate interest |
| Invoicing and tax records | Meeting our own accounting and tax obligations | Legal obligation |
| Website analytics | Understanding which pages are useful | Consent, where required |
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We have never done so and have no plans to.
4. Data inside your workspace
Everything you enter into your workspace — your customers, vendors, invoices, transactions, documents and reports — is yours. We process it on your behalf so the software works, and for no other purpose. Specifically, we do not mine it, sell it, use it to train anything, or share it with anyone other than as described in this policy.
Across our products, each customer runs on their own instance and their own database. Your records are not stored in a shared table alongside another company's. Our staff access a customer database only when it is necessary to operate or support the service — for example to investigate a fault you have reported — and that access is logged. Custom software we build for a client runs on whatever the engagement specifies, and that is set out in the agreement for it.
You may request an export of your data at any time, and you may ask us to delete it when your service ends. See how long we keep it.
5. Google user data
This section applies to the Google application registered as “Impact Codes”, which is how our software identifies itself when it asks for your permission.
IC Accounting offers an optional Google Drive connection, so that a document you attach to a record — a signed delivery note, a contract, a receipt — can be opened from within your workspace without keeping a second copy of it. Nothing connects to Google unless you choose to connect it, and the application works fully without it. This section applies to every application we provide that connects to Google.
We request one permission, and it is the narrowest one Google offers for this:
| Scope requested | What it grants | Why we need it |
|---|---|---|
.../auth/drive.file | Access only to the individual files you pick, or that this application created. It grants no access to the rest of your Drive, and Google does not let it list or read anything you have not chosen. | To open an attachment you linked to a record, and to confirm it is still there when the record is viewed. |
We request no other Google permission of any kind. We do not use Google sign-in, we do not read your Gmail, your Calendar or your Contacts, and we do not ask for full Drive access.
- What we access: the files you select when attaching them, and the metadata needed to display and open them.
- What we store: a reference to the file and the authorisation token needed to read it. The file itself stays in your Google account — we do not copy your documents into our storage.
- What we do with it: show the attachment, and open it when you ask us to. Nothing else.
- How to revoke it: disconnect from within your workspace, or remove our access at myaccount.google.com/permissions. Access stops immediately.
Limited Use. Impact Codes' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide or improve this feature, to comply with the law, or as part of a merger or acquisition, and we do not allow humans to read it except with your explicit permission, for security purposes, to comply with the law, or where the data has been aggregated and anonymised.
We do not use Google user data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models.
6. Data migrated from another system
If you use the Data migration module, you authorise us to read data from the accounting system you are moving off, so that we can bring your history into your new workspace.
- What we read: customers, vendors, your chart of accounts, and transactions, for the company and period you choose.
- What we write: nothing. The connection is read-only; we never create, change or delete anything in the system you are migrating from.
- Where it goes: the data is rebuilt as documents inside your own workspace. From that point it is your workspace data, covered by section 4.
- Tokens: where the migration connects to a platform directly, the authorisation tokens are held encrypted in a dedicated service, separate from the workspace itself, and are used only to perform imports you have asked for.
- Files: where you supply an export instead, the file is deleted once the migration is complete and verified.
- How to revoke it: disconnect within your workspace, or remove the connection from the other platform's own account settings. We delete the stored tokens when a connection is revoked.
We do not use data read from another platform for advertising, do not sell it, and do not share it with third parties other than as described in section 7.
Intuit / QuickBooks Online. Where the migration connects to QuickBooks Online, everything above applies to that connection: read-only access to the company you select, used solely to build your own workspace, never written back, never used for advertising, and never sold. Revoke it at any time from within your workspace or from your Intuit account, and we delete the stored tokens.
7. Who we share it with
We share personal information only with:
- Our hosting and infrastructure providers, who run the servers your workspace and this website are hosted on.
- Our payment provider, which takes your payment and holds your card details instead of us.
- Email delivery, operated by us, to send invoices, receipts, notifications and replies.
- Professional advisers — accountants and lawyers — where they need it and are bound to confidentiality.
- Authorities, where we are legally required to, and only to the extent required.
If our business is ever sold or merged, personal information may transfer as part of it. We would tell you before that happened and this policy would continue to apply until it was replaced by one you were told about.
8. How long we keep it
- Workspace data: for as long as your service is running. After it ends we keep a backup for up to 90 days so an accidental cancellation can be undone, then delete it. You can ask us to delete it sooner.
- Orders and invoices: seven years, because tax law requires it.
- Contact enquiries: up to two years, then deleted.
- Server logs: up to 12 months.
- Integration tokens: deleted as soon as the connection is revoked or the service ends.
9. How we protect it
Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes and cannot be read by us or recovered — they can only be reset. Sensitive credentials, including integration tokens, are encrypted at rest. Administrative access to our infrastructure requires multi-factor authentication and is restricted to a private network.
Each customer's data lives in its own database, which limits what any single fault or mistake can reach. More detail is on our security and data page.
No system is perfect. If a breach affects your personal information we will tell you and any relevant regulator without undue delay, and tell you what happened rather than the least we can get away with saying.
10. Your rights
Wherever you are, you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct anything that is wrong;
- delete it, where we are not required to keep it;
- restrict or object to how we use it;
- export it in a portable format;
- withdraw consent, where consent is what we relied on.
If you are in the EEA or the UK, these are your rights under the GDPR and you may complain to your national supervisory authority. If you are a California resident, the CCPA gives you the rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share your personal information, so there is nothing to opt out of — and we will not discriminate against you for exercising any of them.
Email contact@impactcodes.com and we will respond within 30 days. If you are a user of a workspace operated by your employer, ask them first: for that data they are the controller and we act on their instructions.
11. Cookies
This website uses cookies and similar storage only for two things: keeping you signed in where you have signed in, and remembering your own preferences, such as your chosen theme. Where we use analytics, it is limited to understanding which pages are useful.
We do not use advertising cookies and we do not allow third parties to track you across other websites from here. You can block or delete cookies in your browser; signing in will stop working if you block ours.
12. International transfers
We are based in the United States and our infrastructure is operated there. If you are outside the United States, using our services means your information is transferred there. Where the law requires a transfer mechanism — such as the European Commission's Standard Contractual Clauses — we put one in place with the providers concerned.
13. Children
Our services are for businesses. They are not directed at children under 16 and we do not knowingly collect their personal information. If you believe we have, tell us and we will delete it.
14. Changes to this policy
We update this page when what we do changes. The date at the top always reflects the current version. If a change materially affects how we handle your information we will email active customers before it takes effect, rather than relying on you noticing.
15. Contact us
Impact Codes
Boston, Massachusetts, United States
contact@impactcodes.com
+1 (857) 272-6770