1. Who we are
Toolports (“Toolports,” “we,” “us”) provides hosted ports — remote Model Context Protocol (MCP) endpoints that let your AI client talk to business software you already use. The first live port is QuickBooks Online at qbo.toolports.com. The same rules apply to every port we operate now or later (for example field-service tools), unless a port-specific notice says otherwise.
Contact: hello@toolports.com. This policy should be read with our Terms of Service and EULA.
2. Scope
This policy covers:
- The marketing site and waitlist on toolports.com
- Hosted ports (subdomains such as qbo.toolports.com)
- OAuth, API calls, logs, and optional local-platform files those ports store to run the service
It does not cover third-party products you connect or the AI client you use (Cursor, Claude, ChatGPT, Grok, and similar). Those have their own policies. We are not Intuit, Jobber, or any Connected Service provider.
3. Information we collect
Account and contact
Email address, the tool you say you want to connect, and messages you send us. Waitlist submissions may include a timestamp and that the source was toolports.com.
Connection and credentials
When you connect a port, we receive OAuth tokens, a company or tenant identifier (for QuickBooks Online, a realm ID), environment (sandbox/production), and similar connection metadata from that provider. We store tokens so the port can call the provider’s API on your behalf. We do not ask for your Connected Service password.
Connected Service content
The port retrieves or writes only what your authorized MCP client requests — for example vendors, bills, invoices, reports, attachments, or other records the provider’s API exposes under the scopes you approved. We process that content to complete the request. We do not use it to build marketing profiles or to train our own models.
Port platform files
If you use optional port features (document upload, review tasks, bank-feed inbox, close checklists, named report packs, company memory), those files and records live with your port data until you delete them or disconnect.
Technical and security data
IP address, user agent, timestamps, request path, status code, and duration. MCP access uses a bearer token you (or we) configure. Audit logs may record tool name, tenant id, whether the call was a read or write, related record ids, and outcome — not secrets, request bodies, or credentials.
Cookies
The marketing site is static besides the waitlist form. We do not use advertising or cross-site tracking cookies. Essential hosting cookies may be set by our site host. If we add analytics later, we will update this policy.
4. How we use information
- Operate, authenticate, and secure the site and ports
- Complete OAuth and keep your connection alive (token refresh)
- Proxy API calls between your MCP client and the Connected Service you authorized
- Send waitlist and service messages you would expect
- Diagnose outages, abuse, and security incidents
- Improve the product using aggregated or de-identified signals
- Comply with law and enforce our terms
Writes to a Connected Service stay off until you enable them and, where we offer an allowlist, until the operation is allowed. Default for QuickBooks Online is read-only plus a narrow bill allowlist that remains disabled until writes are turned on.
5. We do not sell your information
We do not sell personal information or Connected Service content. We do not share one customer’s data with another customer. We do not use Connected Service content for advertising.
6. Who we share with
We share information only as needed to run the service:
- You and your agents. Your MCP client receives API results you requested. You are responsible for that client’s policies and for what your agents do with the data.
- Connected Service providers. Intuit (QuickBooks Online) and any future provider you connect. Their use of data is governed by their terms and privacy statements. For QuickBooks, see Intuit’s Global Privacy Statement and the data-sharing notices shown during connect.
- Infrastructure processors. Website hosting (currently Vercel), port hosting (currently DigitalOcean), DNS/email providers, and waitlist processors (for example Formspree) if configured. They may process data only to provide their service to us.
- Professional advisors and authorities when required by law, to prevent harm, or in a merger, financing, or sale — with appropriate protections.
7. Roles (business data)
For business records that pass through a port, you (or your organization) are the controller / business. Toolports is a processor / service provider: we handle that content only to provide the port you asked for, as described here and in the Terms. You must have the right to connect the company file or tenant and to let an AI client use it.
8. QuickBooks Online (and other ports)
When you connect QuickBooks Online we request accounting API access (currently the Intuit accounting scope). We use that access solely to run the QBO port: identity (`whoami` / company profile), reads (lists, reports, transactions), and — only if you enable writes — the operations you allow. We do not use QuickBooks data to market to your customers or vendors, and we do not share it across Toolports accounts.
Future ports follow the same pattern: we collect the minimum connection data the provider requires, use it to serve that port, and list material extras here if they differ.
You can disconnect in the Connected Service’s app settings (for QuickBooks, My Apps) and by asking us to delete stored tokens.
9. Retention
- Waitlist email: until you ask to be removed, or we close the list
- OAuth tokens: until you disconnect, they expire, or we delete the port data
- Audit and request logs: a limited operational window, then deletion or aggregation
- Platform files you upload: until you delete them or disconnect
We may keep a residual copy where the law requires or where backups have not yet rotated.
10. Security
Ports are served over HTTPS. MCP calls require a bearer token in the Authorization header (never in the query string). Tokens on disk are stored with restricted permissions. The application process is not published on the public internet except through the TLS proxy. No method is perfect; you should use a unique bearer, keep writes off until you need them, and treat agent access as production access to your books.
11. International transfers
We currently operate infrastructure in the United States. If you access the service from elsewhere, information is processed in the U.S. and anywhere our processors run. By using the service you understand that transfer.
12. Your rights and choices
Subject to law, you may request access, correction, deletion, or a copy of personal information we hold, or object to certain processing. Email hello@toolports.com. You can:
- Disconnect a Connected Service at the provider
- Ask us to drop stored tokens and port data for your tenant
- Unsubscribe from waitlist mail
- If you are a California resident: we do not sell or share personal information as those terms are used in the CCPA/CPRA
If we cannot verify a request, we may ask for more information. Some records we must keep. If we process data for your organization, we may redirect you to your admin.
13. Children
The service is for businesses and professionals, not for children under 16 (or the age required in your country). We do not knowingly collect their data.
14. Changes
We may update this policy. The effective date at the top will change. Material changes will be posted on this page. Continued use after the effective date means you accept the update.
15. Contact
Privacy requests: hello@toolports.com