Privacy Policy

Last updated: 2026-05-21.

Fuzzy Xero Integration ("the App") is operated by Part Two Enterprises, Inc. for internal use. It is single-tenant and not distributed to third parties.

What we access

With the connected organisation's consent, the App accesses the Xero Accounting API to create and read the chart of accounts, contacts, and manual journals, using only the scopes listed on the home page.

What we store

Only OAuth tokens (access token, rotating refresh token, tenant ID) in Cloudflare Workers KV, encrypted at rest, plus short-lived single-use CSRF state tokens. No Xero business data is copied or retained.

Third parties

Xero (data source — xero.com privacy) and Cloudflare (infrastructure — cloudflare.com privacy).

Your rights

Disconnect at any time from Xero → Settings → Connected apps, or via /disconnect. This deletes stored tokens.

Contact

alex@fuzzywumpets.com