COTO

Privacy Policy

Last updated: August 4, 2026

1. Internal Application

This Privacy Policy explains how COTO collects, uses, stores, and shares information when authorized internal users access the COTO application and its GoHighLevel and QuickBooks Online integration. The application is for internal business use only and is not intended for public use.

2. Information We Collect

The application may collect account and login information such as name, email address, profile information, session data, and role or feature-flag access. It may also store OAuth tokens and connection identifiers needed to operate connected services.

For the QuickBooks Online integration, the application may process company connection data such as realm ID, access token metadata, refresh token metadata, customer records, product and SKU data, item references, sales receipt identifiers, accounting workflow results, API responses, API errors, and Intuit transaction IDs such as intuit_tid.

For GoHighLevel workflows, the application may process order payloads, location IDs, customer contact details, purchased products, line items, quantities, prices, discounts, shipping amounts, tax amounts, order totals, and sync status records.

3. How We Use Information

COTO uses information to operate the internal application, authenticate users, connect approved systems, sync orders from GoHighLevel to QuickBooks Online, create sales receipts, support inventory and accounting workflows, prevent duplicate syncs, troubleshoot errors, secure the application, maintain auditability, and provide internal support.

4. How We Share Information

COTO does not sell personal information or integration data. Information is shared only as needed to operate the application, including with connected platforms such as QuickBooks Online and GoHighLevel, hosting providers, database providers, authentication providers, monitoring providers, and other service providers that support the internal workflow.

5. Data Retention

COTO retains application data for as long as needed to operate the internal workflow, support accounting and inventory records, troubleshoot issues, meet security and audit needs, or satisfy business and legal obligations. OAuth tokens may be replaced or removed when a connection is refreshed, disconnected, or no longer needed.

6. Security

COTO uses administrative, technical, and operational controls intended to protect the application and connected data. No method of transmission or storage is completely secure, and authorized users must follow internal security requirements when accessing the application.

7. User Choices and Access

Because this is an internal application, access is controlled by COTO administrators. Authorized users may request access changes, account review, or removal of unnecessary access through internal support channels.

8. Third-Party Services

Connected platforms and service providers may process information under their own terms and privacy policies. COTO uses these services only as needed to operate the internal integration and related business workflows.

9. Changes to This Policy

COTO may update this Privacy Policy from time to time. Updates will be posted on this page with a revised last updated date.

10. Contact

Questions about this Privacy Policy may be sent to hello@cotocollective.com.