Last Updated: August 24th, 2026
This Privacy Policy describes how KJONGSys LLC (“KJONGSys”, “we”, “us”, “our”) collects, uses, stores, shares and protects information. It covers this website and the software platforms KJONGSys builds and operates for its clients, including order management and fulfillment platforms that connect to third-party accounting, shipping and payment services.
KJONGSys is the software publisher. Where we operate a platform on behalf of a client, that client is the owner of the business records held in it, and KJONGSys processes those records on the client’s instructions and for the client’s purposes only.
1. Information We Collect
1.1 Business Contact Information
We collect and store business contact details for our clients’ staff and for the trade partners those clients transact with. This typically includes names, work email addresses, telephone numbers, company names, and shipping and billing addresses.
1.2 Order and Transaction Information
Where we operate an ordering or fulfillment platform, we store the records of transactions made through it: products ordered, quantities, prices, order dates, shipping method and destination, tracking information, and the resulting invoice or receipt records.
1.3 Account and Authentication Information
For users who sign in to a platform we operate, we store the information needed to maintain that account and control access to it, including a username or email address, a securely hashed password, role and permission assignments, and records of sign-in activity.
1.4 Website Visitors
This website collects only what is necessary to serve pages and to operate its live chat feature. See section 8 for details on cookies.
1.5 Health Information
Where a client engagement involves protected health information, that information is handled only within the systems and workflows covered by a Business Associate Agreement with that client. It is kept separate from the accounting, shipping and payment integrations described below. See section 6.
We do not sell personal information, and we do not share it for advertising or marketing purposes.
2. QuickBooks Online Integration
Some KJONGSys platforms connect to a client’s QuickBooks Online company so that sales originating in the platform are posted into that client’s own accounting records. This section describes precisely what that connection does. It applies only where a client has authorized the connection, and only to that client’s own QuickBooks company.
2.1 What We Read
With the client’s authorization, the platform reads the following from their QuickBooks Online company, for the sole purpose of mapping platform records onto the correct accounting destinations:
- The chart of accounts
- The customer list
- Product and service items
2.2 What We Write
The platform writes records that represent sales which originated in the platform itself:
- Sales receipts and invoices
- Payment records
- Product and service item records, where a matching item does not already exist
2.3 What We Store
To maintain the connection, the platform stores:
- OAuth access and refresh tokens issued by Intuit
- The QuickBooks company identifier (realmId)
- Mappings between platform records and the corresponding QuickBooks account and item identifiers
Tokens are held encrypted, in storage located outside the application directory, and are used solely to maintain the authorized connection. They are not used for any other purpose and are not shared with any other party.
2.4 What We Do Not Do
We do not copy, mirror or retain a client’s wider financial records. We do not read or store bank feeds, payroll data, tax filings, or any accounting record beyond what is described in section 2.1. We do not use QuickBooks data for analytics, product development, benchmarking, resale, or any purpose other than posting that client’s own sales into that client’s own books. We do not transmit protected health information to QuickBooks Online.
A client may disconnect the QuickBooks connection at any time. On disconnection we revoke and delete the stored tokens.
3. How We Use Information
We use the information described above only to provide and support the services our clients have engaged us for. Specifically: to operate ordering, fulfillment and accounting workflows; to process and ship orders; to post sales into a client’s accounting system; to authenticate users and control access; to communicate about orders, support requests and service matters; to maintain security and investigate misuse; and to meet legal and record-keeping obligations.
We do not use client or trade-partner information to market unrelated products, and we do not build advertising profiles.
4. Service Providers
We share information with the following categories of service provider, only to the extent needed to deliver the service, and only for the purposes described:
- Intuit QuickBooks Online — to post a client’s sales into that client’s own accounting records, as described in section 2.
- ShipStation — to generate shipping labels and retrieve tracking information. This requires the recipient’s name, address and contact details.
- Authorize.Net — to process card payments. See section 5.
- Our hosting provider — to host the servers on which platforms and websites run.
These providers act on our instructions or as independent processors under their own terms, and each maintains its own privacy policy. We do not sell information to them or to anyone else, and we do not permit them to use our clients’ information for their own marketing. Protected health information is not shared with these providers; see section 6.1.
5. Payment Information
Card payments are processed by our payment processor. Cardholder data is captured and handled by the processor. KJONGSys platforms do not store full payment card numbers or bank account numbers. Where a record of a payment is retained, it consists of the transaction outcome and a reference identifier — for example the amount, date, authorization result, and the last four digits of the card — which is what is needed to reconcile the sale.
6. Health Information
Some KJONGSys client engagements involve protected health information (“PHI”) as defined by the Health Insurance Portability and Accountability Act (“HIPAA”). Where an engagement requires KJONGSys to create, receive, maintain or transmit PHI on a client’s behalf, KJONGSys acts as a Business Associate and enters into a Business Associate Agreement with that client before any such information is handled.
In those engagements we apply the administrative, physical and technical safeguards required of a Business Associate, limit access and use to the minimum necessary for the task, and report any breach of unsecured PHI to the covered entity as required under HIPAA.
KJONGSys does not hold, and does not claim, any third-party HIPAA certification. No such certification exists under HIPAA; compliance is a matter of ongoing practice and contractual obligation rather than a credential held.
6.1 Protected Health Information Is Not Sent to QuickBooks
Protected health information is not transmitted to QuickBooks Online. The records posted through the QuickBooks integration described in section 2 consist of business and commercial details only — products, quantities, prices, and business billing and shipping details. Patient identifiers do not travel with an order and are never written to a client’s accounting records.
The same applies to the shipping and payment providers listed in section 4. Those integrations carry commercial order and payment details only.
7. How We Protect Information
We apply the following measures to the systems we operate:
- Encryption in transit. Public endpoints are served over HTTPS with certificates from a recognized authority, and plain HTTP requests are redirected to HTTPS.
- Restricted credential storage. Database credentials, API keys and OAuth tokens are stored outside the application directory, with filesystem permissions restricting them to the service account that needs them.
- Access controls. Platform users are assigned roles that limit them to the functions and records their role requires.
- Server hardening. Administrative access is by key-based authentication only on a non-default port, with password authentication disabled, a default-deny firewall, automated intrusion blocking, and automatic security patching.
- Least privilege for third-party connections. Integration credentials are scoped to the specific client account they serve and are revoked when no longer required.
No system can be guaranteed absolutely secure. We do not claim any third-party security certification, and we make no representation of holding one. If we become aware of a breach affecting a client’s information, we will notify that client without undue delay.
8. Cookies and Analytics
This website uses cookies only where they are needed for the site to function and to operate its live chat feature, which is provided by Zoho. Static assets are served from a content delivery network.
This website does not run Google Analytics, Google Tag Manager, advertising pixels, or third-party behavioral tracking, and it does not use cookies for advertising.
Platforms we operate for clients use cookies or equivalent browser storage to keep a signed-in user’s session active. These are necessary for the platform to work and are not used for tracking.
9. Data Retention and Termination
We retain client business records for as long as we operate the relevant service for that client, and afterwards only for as long as needed to meet legal, tax or record-keeping obligations.
On termination of a service, we will, at the client’s direction, return an export of their data and then delete the working copies held in the platform, subject to any retention we are legally required to observe. Credentials and integration tokens for that client, including QuickBooks OAuth tokens, are revoked and deleted at termination. Routine backups are retained on a rolling schedule and expire on their normal cycle.
10. Access, Correction, Export and Deletion
A client may request a copy of the information held in a platform we operate for them, ask us to correct it, or ask us to delete it. Requests should be sent to the contact address in section 13 and will be acknowledged promptly.
Where the information concerns a client’s own staff or trade partners, that client is the appropriate point of contact, as they control those records. If an individual contacts us directly about information held on a client’s behalf, we will refer the request to that client and assist them in responding.
11. Children’s Privacy
Our services are business-to-business tools and are not directed at children. We do not knowingly collect information from anyone under 13.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top of this page shows when it was last revised. Where a change materially affects how we handle a client’s information, we will notify affected clients directly.
13. Contact
Questions about this Privacy Policy, or requests concerning information we hold, may be sent to:
KJONGSys LLC
Email: keith.gallagher@kjongsys.com
