R Resilient Trading & Contracting W.L.L Procurement & Inventory

Privacy Policy

Effective date: 27 August 2026 Last updated: 27 August 2026

This Privacy Policy explains what information the Procurement & Inventory application (the “Procurement App”) collects, why it is processed and how it is protected. The Application is operated by Resilient Trading & Contracting W.L.L (“the Company”, “we”, “us”) at procurement.westqtrading.com.

The Procurement App is a private internal business system. There is no public sign-up, no advertising, and no analytics or tracking service is used. We do not sell or rent any information held in the Application, and we do not use QuickBooks data for advertising or profiling.

1. Account information we collect

Accounts are created by an administrator, not by self-registration. For each account the Application stores:

  • user name, full name and, where an administrator enters one, an email address;
  • the assigned role and whether the account is active;
  • a cryptographic hash of the password — passwords are never stored in readable form (see “How data is protected”); and
  • the time the account last signed in, and whether a password change is required.

2. Usage information we collect

  • Sessions. When you sign in, a session record is created holding a random session token, your account, the sign-in and expiry time, the IP address and the browser's user-agent string.
  • Sign-in attempts. Failed and successful sign-in attempts are recorded with the user name tried and the originating IP address, so that repeated failed attempts can be slowed down.
  • Audit trail. Actions that change a record — creating, editing, approving, dispatching, invoicing, connecting or disconnecting QuickBooks — are logged with the account that performed them, a short description and a timestamp.
  • Business records you enter. Quotations, sales orders, purchase orders, receipts, shipments, deliveries, invoices, items, stock movements and any files you attach, together with the customer and supplier contact details entered for them.

Server logs kept by the web server and the application process may also contain request information such as IP addresses and error details.

3. QuickBooks Online data

Where an administrator connects the Application to QuickBooks Online, it uses the single QuickBooks accounting scope (com.intuit.quickbooks.accounting) and touches only the data it needs to post an accepted quotation to the Company's own QuickBooks company file:

QuickBooks dataWhat the Application does with it
Company information Reads the connected company's name and its home currency, and whether multi-currency is enabled, at connection time — so a quotation in another currency can be refused before it is posted rather than landing as the wrong amount.
Customers Searches for a customer by exact display name; creates a customer from the name and contact details already held in the Application when no match exists. The resulting QuickBooks customer id is stored so the same customer is reused rather than duplicated.
Products and services (items) Searches the catalogue by code or name so a quotation line is booked against the right entry. Where an administrator has switched the option on, an item may be created against the income account they have configured; otherwise lines are booked to the default product/service the administrator has chosen. The QuickBooks item id is stored so it is reused rather than duplicated.
Estimates Checks whether an estimate with the same document number already exists, then creates the estimate with its lines, quantities, prices and totals. The QuickBooks estimate id, the time it was posted and any error returned are stored against the quotation.

The Application does not read or store QuickBooks payroll, banking, payments or employee data, and it does not read your QuickBooks customer list or catalogue in bulk — lookups are made for the specific record being posted.

4. Why this data is processed

  • To provide the Application — to run the purchasing, stock, delivery and invoicing workflows it exists for.
  • To authenticate and authorize — to sign accounts in, keep sessions valid and enforce what each role may see and do.
  • To keep an accurate commercial and accounting record — including the audit trail of who did what, which is relied on internally and for accounting.
  • To post accepted quotations to QuickBooks Online, at the request of an authorized user, so the Company's books reflect what was sold.
  • To protect the Application — to detect and slow down repeated failed sign-in attempts and to investigate problems.

5. How data is protected

OAuth tokens

QuickBooks access and refresh tokens are encrypted before they are written to the database, using authenticated encryption (HMAC-SHA256 counter-mode with encrypt-then-MAC, with separate encryption and authentication keys derived from one master key). The master key is not stored in the database beside the data it protects: it is supplied through an environment variable or, failing that, a file readable only by the account the Application runs as. A token that fails its authentication check is refused rather than used. Tokens are never written to logs, and credential-shaped values are scrubbed from error messages before they are recorded or displayed.

Passwords and sessions

Passwords are stored as PBKDF2-HMAC-SHA256 hashes with a per-password random salt and 240,000 iterations; the original password is never stored and cannot be recovered from the hash. Session tokens are random values stored server-side with an expiry, and the session cookie is marked HttpOnly and SameSite=Lax so it cannot be read by page scripts or sent from another site. State-changing requests additionally require a custom request header, which a cross-site form cannot set.

Transport and hosting

The Application is served over HTTPS with a certificate obtained and renewed automatically. It runs on a single virtual server whose firewall accepts only SSH and web traffic, with the application itself reachable only through the web server. Data is held in a SQLite database file on that server, with uploaded attachments stored alongside it.

We describe here only measures the Application actually implements. We hold no security certification (such as ISO 27001 or SOC 2) and make no such claim. No system can be guaranteed completely secure.

6. Service providers who may process data

  • Intuit Inc. — QuickBooks Online, where the connection is enabled. Data listed in section 3 is exchanged with Intuit and is then handled under Intuit's own terms and privacy policy.
  • Hetzner Online GmbH — the hosting provider whose infrastructure the server and its backups run on.
  • Let's Encrypt (ISRG) — issues the HTTPS certificate for the site's domain name.
  • Carrier tracking services (DHL, FedEx, UPS) — only where an administrator has entered credentials for them; a tracking number is then sent to that carrier to retrieve shipment status.
  • An offsite backup destination — only where an administrator has configured one; encrypted-at-rest arrangements depend on the destination chosen.

We do not use advertising networks, analytics providers or third-party trackers.

7. Data retention and deletion

  • Business records, attachments and the audit trail are kept for as long as the Company needs them for business, accounting and legal purposes. Documents are generally cancelled or closed rather than deleted, so the record of what happened survives.
  • Sessions expire automatically (14 days by default) and are removed when you sign out.
  • Deactivating a user account stops all access to it; the account record and its audit entries are retained so past actions remain attributable.
  • Backups run nightly and are kept for 30 days, after which they are discarded. Data removed from the live database may therefore persist in backups for up to 30 days.
  • Requests to delete specific personal data may be made to the contact below and will be handled subject to the Company's accounting and legal record-keeping obligations.

8. Disconnecting QuickBooks

An administrator may disconnect QuickBooks Online at any time from the Application's Settings. When this happens:

  • the Application asks Intuit to invalidate the stored token;
  • the stored connection — including both encrypted tokens, the company identifier and any pending authorization state — is deleted from the database, and the disconnection is written to the audit trail;
  • the Application stops reading from or writing to QuickBooks entirely, and posting a quotation is refused until a new connection is authorized;
  • estimates, customers or items already created in QuickBooks stay in QuickBooks and are managed there — disconnecting does not remove them; and
  • identifiers previously returned by QuickBooks may remain on our records as a historical note of what was posted.

The disconnection is carried out even if Intuit cannot be reached to invalidate the token, so that the request is always honoured locally.

9. Your privacy rights

Subject to applicable law and to the Company's record-keeping obligations, you may ask us to:

  • confirm what personal data about you the Application holds, and provide a copy;
  • correct personal data that is inaccurate or incomplete;
  • delete personal data that is no longer required; and
  • restrict or object to a particular use of your personal data.

Requests should be sent to the contact address below. As the Application is an internal system, most account data can also be viewed and corrected by an administrator directly.

10. Cookies and local storage

The Application sets no advertising or analytics cookies. It uses only the following, all of which are strictly necessary or a convenience for you:

NameTypePurpose
pr_session Cookie (HttpOnly, SameSite=Lax) Keeps you signed in. Strictly necessary; expires after 14 days or when you sign out.
theme Browser local storage Remembers whether you chose the light or dark appearance. Stays in your browser and is never sent to the server.
estimate:pdf-prefill Browser session storage Carries the details read from a quotation PDF into the quotation form in the same tab. Removed as soon as the form reads it, and cleared when the tab is closed.

11. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page shows when it last changed, and the current version is always the one published at this address. Where a change materially affects how personal data is handled, we will make users aware of it through the Application.

12. Contact

Questions about this Privacy Policy, or a request concerning your personal data, may be sent to:

Resilient Trading & Contracting W.L.L
Falcon Fitness Building, First Floor, Office No-1,
Matar Al Qadeem, Street No-840, Zone-45,
P.O. Box 38491, Doha, Qatar
Email: trading@resilient.qa
Telephone: +974 4001 3309
Terms of Use Privacy Policy Back to the Application
© 2026 Resilient Trading & Contracting W.L.L. All rights reserved.