← Back to Home

Integrations Terms

Last Updated: April 2026

1. Scope

These terms govern the connection between MBR Making Better Rides ("MBR") internal operational systems and third-party platforms used to support accounting, reporting, and customer-experience functions. They apply alongside our Privacy Policy and our Cookie Policy.

2. Connected Services

MBR currently maintains authorized connections to the following third-party platforms:

  • QuickBooks Online (Intuit). Read-only access to MBR's books for internal financial reporting (accounts receivable, accounts payable, cash flow, profit and loss, balance sheet). No write operations are performed against MBR's QuickBooks data.
  • Google Places API. Read-only access to public review data for MBR's Google Business Profile, surfaced on the public website.

3. Authorization & Consent

Each connection is authorized by an MBR administrator using the third-party platform's native consent flow (typically OAuth 2.0). The authorizing admin can revoke access at any time directly from the third-party platform's app management settings, without notifying MBR.

4. Data Handling

  • Scope minimization. We request only the OAuth scopes needed to deliver the stated function. For QuickBooks Online this is com.intuit.quickbooks.accounting (read-only). No payments, payroll, or write scopes are requested.
  • In-memory processing. Data fetched from connected services is processed in operator memory at the time of request. We do not maintain a long-term cache of customer-identifying financial detail on our servers.
  • Aggregated reporting. Non-identifying period totals may be retained in internal operator dashboards or shared with MBR stakeholders.
  • Credential storage. API keys and OAuth refresh tokens are stored encrypted at rest in our secret-management platform (Infisical). They are never written to source control, application logs, browser bundles, or shared with third parties beyond named sub-processors.
  • Sub-processors. Hosting and secret storage for the disconnect notification endpoint and the encrypted credential vault are provided by Vercel and Infisical respectively. Both are SOC 2 Type II audited under their own privacy commitments.
  • Retention & deletion on disconnect. When a connected platform notifies us of a disconnection, the associated OAuth refresh token and realm/account identifier are purged from our secret store within 24 hours. No fetched report data persists beyond the active in-memory request.
  • No resale or third-party marketing. We do not sell, rent, or share data fetched from connected services for advertising or analytics, with anyone outside MBR and the named sub-processors above.
  • Audit logging. API call metadata (timestamps, status, Intuit's intuit_tid trace identifier, realm ID) is logged server-side for support, debugging, and compliance review. Logs do not contain tokens or customer-identifying transaction detail.

5. Disconnection

You may disconnect any integration at any time. The third-party platform will invalidate the access tokens immediately on its end. We will treat the integration as terminated and stop attempting to fetch data once we receive the disconnect notification or our access tokens fail.

For QuickBooks Online: Settings (gear) → Apps → My Apps → Disconnect.

6. Disclaimer of Warranties

Connected-service integrations are provided "as is" and "as available" for internal MBR operational use. MBR makes no warranty, express or implied, regarding the accuracy, completeness, reliability, or fitness-for-purpose of any data fetched from a third-party platform, including without limitation QuickBooks Online financial data. Authoritative records always reside with the third-party platform, not with this integration layer.

7. Limitation of Liability

To the maximum extent permitted by applicable law, MBR Making Better Rides and its operators are not liable for indirect, incidental, special, consequential, or punitive damages arising from these integrations, including business interruption, lost profits, lost data, or decisions made on the basis of fetched data, even if advised of the possibility of such damages. Each connected service is independently governed by its own terms of service and privacy policy, which apply directly between the relevant party and that service.

8. Termination

You may terminate any integration at any time by disconnecting it from the third-party platform's app management settings (for QuickBooks Online: Settings (gear) → Apps → My Apps → Disconnect). On receipt of the platform's disconnect notification, our OAuth refresh token and realm identifier for that integration are purged from our secret store within 24 hours, in line with our Privacy Policy. MBR may also terminate or suspend an integration unilaterally if a security incident, compliance requirement, or operational need warrants it.

9. Governing Law

These terms are governed by the laws of the United Arab Emirates and the Emirate of Dubai, without regard to conflict-of-laws principles. Disputes arising from these integrations are subject to the exclusive jurisdiction of the courts of Dubai.

10. Contact

Questions about a specific integration, or to request disconnection or data deletion on behalf of an MBR account, contact us:

MBR Making Better Rides

16 8 St Al Qouz Ind. Fourth, Al Quoz, Dubai, UAE

Phone: +971 56 501 5800

Email: info@mbrme.com

11. Changes

We may update these terms when integrations are added, removed, or materially changed. The "Last Updated" date above reflects the most recent revision.