Plaid tutorial

Connect your bank with Plaid

Link a bank or credit card to Tidy Orders in about a minute. This guide walks through the connection flow, explains exactly how Plaid works, and spells out what data we use (and what we deliberately leave behind).

Goal: securely connect your business bank or credit card so charges flow into the review queue every two days, deduplicated against Amazon orders and emailed receipts.

What is Plaid, and why use it?

Plaid is the bank-connectivity layer used by apps like Venmo, Robinhood, Chime, and most modern bookkeeping tools. Instead of asking you to upload CSV statements, Plaid acts as a secure middle layer between Tidy Orders and your bank — over 12,000 financial institutions in North America are supported.

The flow looks like this:

You → Plaid Link (popup) → Your bank → Plaid → Tidy Orders

Your bank credentials are entered inside Plaid's popup, not on a Tidy Orders form. Plaid exchanges them with your bank for a long-lived access token and hands that token to us. We never see your username or password.

How safe is it?

  • No password storage. Tidy Orders never receives, sees, or stores your online banking credentials. Plaid handles the bank handshake inside their own secured popup.
  • Read-only access. The Plaid connection scope we request only allows reading transactions and account names. We cannot initiate transfers, payments, or balance changes — the access token literally does not permit it.
  • Encrypted at rest. The Plaid access token we receive is encrypted in our database before being written, using a key that lives outside the database.
  • Revocable anytime. Disconnect from the Integrations page in Tidy Orders, or revoke directly inside Plaid's my.plaid.com portal. Either action immediately stops new data from flowing.
  • Bank-grade transport. All traffic between us, Plaid, and your bank is TLS encrypted. Plaid is SOC 2 Type II and ISO 27001 certified.

What data we actually use

Tidy Orders is bookkeeping software for small businesses. We only need the minimum detail required to classify a charge and put it on a Schedule C.

What we read from Plaid

  • Transaction amount, date, and currency
  • Merchant name and the raw bank description (e.g. SQ *BLUE BOTTLE COFFEE)
  • Plaid's merchant entity ID, so "AMZN Mktp" and "Amazon.com" canonicalize to one vendor
  • Account nickname ("Business Checking ••1234") so you can pick which accounts to sync
  • Pending vs. posted status, used to reconcile pending charges into the final posted row without duplicates

What we never store or look at

  • Your online banking username or password
  • Full account or routing numbers
  • Account balances or available credit
  • Personal identity data (SSN, address, phone) — Plaid offers these endpoints; we don't call them
  • Investment holdings, loan details, or income data
LLM privacy: when our AI classifier sees a transaction, it receives the merchant name, amount, and your business industry — nothing that identifies you as an individual. Account numbers and personal details are stripped before any prompt leaves our backend.

Before you start

  • Your online banking login for the bank or card you want to connect.
  • Your phone or email handy — banks often send a one-time code during first connection.
  • A Tidy Orders account open at Integrations.
Account type tip: connect the account(s) you actually use for business spending. If business and personal share one card, connect it and use the review queue to mark personal charges as excluded — they won't count against your monthly usage.

Step 1: open Plaid Link

  1. In Tidy Orders, open Integrations.
  2. Find the Bank & credit cards (Plaid) card.
  3. Click Connect a bank. Plaid's secure popup opens in front of Tidy Orders.
  4. Search for your bank by name. If multiple variants show, pick the one matching your login page (e.g. "Chase" vs. "Chase Business").
  5. Enter your online banking username and password inside Plaid's popup.
  6. If your bank requires it, complete the multi-factor prompt (SMS code, security question, push notification).

When Plaid finishes, the popup closes and you'll see the bank listed on the Integrations page with a green status dot.

Step 2: pick which accounts to sync

Most banks return multiple accounts (checking, savings, credit card). On the connection card, toggle off the ones you don't want — for example, a personal savings account that has no business activity.

Disabled accounts are skipped entirely: no transactions are imported and no usage is counted against your plan.

Step 3: let the first sync run

The initial sync pulls up to 24 months of transaction history (or as far back as your bank shares with Plaid). It usually finishes in under a minute.

While it runs, the card shows a yellow pulsing dot. When it switches back to green, open the Review Queue — new charges are tagged with a Bank source badge and pre-classified by our AI.

What we filter out automatically:

  • Transfers between your own accounts
  • Payments to credit cards (avoids double-counting the underlying purchases)
  • Deposits, payroll credits, and other income (Tidy Orders tracks expenses only)
  • Refunds are applied back to the original charge, not stored as separate rows

Step 4: ongoing automatic sync

After the first import, Tidy Orders refreshes your bank every 2 days using Plaid's incremental sync — we only pull new and changed transactions, never the full history again.

Sync now Pull new charges immediately instead of waiting for the cycle.
Test connection Ping your bank to confirm the access token still works.
Reconnect Re-authorize when your bank invalidates the session (typical every 90 days).

Step 5: handling "Needs reauth"

Most banks force a re-login every 90 days under Open Banking rules, or sooner if you change your password. When that happens the card flips to Needs reauth with a red dot.

  1. Click Reconnect on the bank's card.
  2. Plaid Link opens — sign in again and re-confirm MFA.
  3. The next scheduled sync resumes from where the last successful run stopped, so nothing is duplicated.
Bank of America heads up: linked sub-accounts (some authorized-user cards) occasionally fail to surface through Plaid's API. If a card you expect isn't listed, contact us — we may need to suggest an alternate connection path.

Disconnecting

You can disconnect at any time from the Integrations page — that removes the encrypted access token and stops new transactions from importing. Previously imported transactions remain in your Tidy Orders account so your historical reports don't change.

To revoke from the bank's side too, visit my.plaid.com, sign in with the email you used during Plaid Link, and revoke "Tidy Orders" from the connected apps list.