MATF Business Services — PRIVACY POLICY
MATF Business Services — PRIVACY POLICY
Effective date: September 9, 2026
1. Scope and operator
My Adventure to Fit, Inc. (“Company,” “we,” “us,” or “our”) operates MATF Business Services (the “Service”), a private application supporting authorized business operations, data management and connected services. This Policy explains how we handle information through the Service.
The Service is restricted to authorized Company personnel and service providers working for the Company. This Policy is specific to the Service. Shopping and general browsing on myadventuretofit.com are covered by our storefront privacy policy at https://myadventuretofit.com/pages/privacy-policy.
2. Information processed
Depending on enabled features and permissions, the Service may process:
• Connection information, such as company names, company identifiers, authorized scopes, API credentials, access tokens, refresh tokens and connection status.
• QuickBooks Online records, such as accounts, balances, transactions, invoices, bills, payments, journal entries, customer and vendor details, and reports.
• Cin7 Core records, such as products, inventory quantities and values, purchase orders, sales orders, supplier information and related transactions.
• User requests, prompts, selected records, proposed changes, approvals, generated analyses and exported files.
• Operational or support information, such as error details, request identifiers and information users provide when requesting assistance, where collected by the applicable version or service.
Business records can contain personal information, including names, email addresses, postal addresses and transaction details concerning customers, suppliers or personnel. Only information relevant to an authorized task should be submitted or retrieved.
Listing a category does not mean every version collects it. Unconnected or disabled integrations do not supply data through the Service.
3. Purposes of use
We use information to establish and maintain authorized connections; respond to user requests; analyze and reconcile accounting and inventory records; prepare proposed corrections; execute approved changes where supported; investigate problems; protect access; and meet applicable recordkeeping obligations.
Connected business data is used for the benefit of the business whose accounts are connected. We do not sell Service financial data, use it for targeted advertising, or use it to create data products or benchmarks for unrelated businesses.
4. AI processing and model training
When an authorized user uses AI-assisted features, prompts and relevant records or tool results are transmitted to OpenAI for processing and generation of responses. Information appearing in a ChatGPT conversation may be stored with that conversation under the applicable account settings and service terms.
Company policy prohibits using QuickBooks or Cin7 data submitted through the Service to train or fine-tune general-purpose AI models. Authorized users must use approved accounts and configurations that exclude that content from model training. If those conditions cannot be met, financial data must not be submitted to the AI service.
AI processing is distinct from model training. Excluding content from training does not mean that no information is transmitted or retained. OpenAI's applicable terms and privacy practices govern its processing, including retention and security-related processing.
5. Recipients of information
Information may be accessed by authorized Company personnel and professional service providers who need it for Company business. It may also be processed by:
• Intuit, to authorize and perform QuickBooks Online operations.
• Cin7, to perform enabled and authorized inventory or related business operations.
• OpenAI, to provide ChatGPT, AI processing and integration connectivity used for the requested workflow.
• Providers of hosting, communications, storage or technical support used in the applicable deployment, to the extent needed to provide those services.
We may disclose information when legally required or reasonably necessary to address fraud, security incidents or legal claims. We do not make connected financial records publicly available through our policy pages.
6. Storage and safeguards
We restrict access to connection credentials and store them separately from application source code. Requests to external service APIs use HTTPS. No method of electronic storage or transmission is completely secure.
Records may also exist in QuickBooks, Cin7, OpenAI conversations, authorized exports and associated backups. Access must be limited to authorized personnel. Credentials must not be included in prompts, public pages or shared troubleshooting materials.
Providers may process information in the United States and other countries in which they or their service providers operate, subject to their applicable terms and safeguards. Hosting these public information pages on Shopify does not, by itself, grant Shopify access to connected financial accounts.
7. Retention and deletion
We retain connection information while needed for an authorized connection. When a connection is permanently ended, the administrator must revoke the relevant access and remove credentials that are no longer needed.
Business records, analyses and approved-change documentation are retained for the period needed for accounting, operational, security and applicable legal purposes. Temporary copies and troubleshooting materials should be removed when no longer needed. Information subject to a legal retention requirement or preservation obligation may be retained for that purpose.
Provider-hosted records, conversations and backups have separate retention controls and schedules. Disconnecting the Service does not automatically delete those copies or remove underlying transactions from QuickBooks or Cin7.
8. Choices and requests
Authorized administrators may manage available integration permissions and request disconnection, access to information, correction or deletion by contacting jonathan@myadventuretofit.com. Individuals whose personal information appears in Company records may also contact us concerning that information.
We may need to verify identity and authority before acting. We will address requests as required by applicable law, subject to recordkeeping duties, other individuals' rights and applicable exceptions. Deleting a Service copy does not necessarily delete the source record or a provider-hosted copy.
9. Public pages and cookies
These policy pages are hosted on our Shopify storefront. Visiting them may involve cookies, analytics or other technologies described in our storefront privacy policy and Shopify's applicable privacy information. The Service's financial data is not intended for use by storefront advertising or analytics tools.
10. Children, changes and contact
The Service is a workplace tool and is not directed to children under 18. We do not knowingly solicit personal information from children through the Service.
We may update this Policy as the Service or our practices change. We will update the effective date and communicate material changes to authorized users before they take effect, obtaining additional consent where required.
My Adventure to Fit, Inc.
Privacy and Service support: jonathan@myadventuretofit.com