Privacy & Data Practices
Effective: July 22, 2026 · Version 1.0
This notice explains what data Taxly handles, why, and how we protect it. Taxly is practice software for accounting firms, so most of the personal data we process belongs to our customers’ clients — and our customers, the firms, control it.
1Who this covers
Taxly serves two audiences, and this notice addresses both:
- Firms— the CPA and bookkeeping practices that subscribe to Taxly and are the controllers of their clients’ data.
- Firm clients — the businesses and individuals a firm serves, who use the client portal to exchange documents, answer questionnaires, and sign engagement letters.
For data a firm uploads or its clients submit, the firm is the data controller and Taxly is a processor acting on the firm’s instructions. For the account data of firm users and for visitors to this website, Taxly is the controller. If you are a firm’s client and have a question about your data, contact your firm first; we will support their response.
2What we collect
Account and firm data
Names, work email addresses, roles, and authentication data for the people at a firm who use Taxly. We use AWS Cognito for identity; passwords are never stored in plaintext.
Client records
Entity details, contacts, services, and tax-relevant identifiers a firm enters or imports — including sensitive identifiers such as SSNs and EINs. All data is encrypted at rest and in transit; tax identifiers collected through client questionnaires are additionally encrypted as individual fields with keys cryptographically bound to your firm’s tenant, and are displayed to firm staff masked (last four only). See Section 4.
Documents and messages
Files that firms and their clients upload (statements, organizers, engagement letters) and the messages exchanged inside a client record.
Bank and bookkeeping data
Bank-statement PDFs a firm uploads, and — for firms in the early-access bank-feed program — transaction data retrieved through Plaid. See Section 7 for how Plaid data is handled.
Connected email
For firms that connect staff mailboxes, email metadata and previews matched to client records. See Section 6 for exactly what is and is not stored.
Usage and audit data
We record an audit trail of actions taken in the product: actor, IP address, user agent, and timestamp, across document activity, sign-offs, and bookkeeping. This log exists to make the product audit-ready and to protect firms and their clients.
Website data
Our marketing site collects standard server logs. The product uses cookies and browser storage only for sign-in and session state, not for advertising. If we use product or web analytics, we configure them to measure usage — not to build advertising profiles — and we will list the provider in Section 8.
3How we use data
We use data only to operate the service and do the work a firm asks us to do:
- To provide onboarding, the client portal, document collection, bookkeeping review, work-item tracking, and e-signature.
- To parse and categorize bank statements a firm uploads, so staff can review rather than re-key.
- To secure the service, prevent abuse, and maintain the audit trail.
- To provide support and communicate about the service.
We do not sell personal data, and we do not use client data for advertising.
4How we protect data
- Encryption.All data is encrypted in transit (TLS) and at rest. Tax identifiers collected through client questionnaires, bank-connection credentials (tokens), and connected-account credentials are additionally encrypted as individual fields, with encryption keys cryptographically bound to your firm’s tenant — keys used for one firm cannot decrypt another firm’s data.
- Tenant isolation.Every firm’s data is partitioned by tenant, and every request is verified against the firm it belongs to. Cross-firm access is not a permission a firm can grant or a firm user can hold. A small number of Taxly platform administrators have tightly scoped, MFA-protected access for operations and support, and their actions are audit-logged.
- Detailed audit trail. Views, uploads, edits, and signatures are logged with actor, IP, and timestamp, and firms can read their own log.
- Signed, sealed evidence. E-signature completions are hash-sealed with an asymmetric key and stored write-once (WORM) for the retention period — tamper-evident and independently verifiable.
- SOC 2-aligned controls.We build to SOC 2-aligned controls throughout. We say “aligned,” not “certified,” until an audit is complete.
5AI and your data
Some features use AI — most notably bank-statement parsing and transaction categorization. AI processing runs on AWS Bedrock (Anthropic Claude models) under our own AWS account; data submitted to an AI feature is not sent to a model provider under consumer terms.
We do not use your clients’ data to train generalized or foundation AI models — ours or any provider’s. Data submitted to an AI feature is used to do your work and return a result. Our AI processing runs under enterprise terms that prohibit provider-side training on inputs and outputs.
Some features learn from your firm’s own historical activity to serve your firm — for example, remembering how your firm categorizes a recurring merchant. Those firm-specific mappings stay in your tenant. Separately, to improve categorization for everyone, we maintain an aggregated cross-customer index of merchant descriptors and the expense categories commonly applied to them (for example, that a given payee is usually an office-supplies expense). This index contains merchant and payee information and category tallies — not your clients’ identities, account data, or records.
6Email integration (Google Workspace / Gmail)
Where this feature is offered, firm staff may optionally connect their work mailbox so that email correspondence with a firm’s clients appears on the client’s record. When a mailbox is connected:
- We access Gmail with read-only scope. We cannot send, modify, or delete mail in a connected mailbox.
- We store message metadata (sender, recipients, subject, timestamps) and a short body preview, matched to a client record. We do not store full message bodies.
- Email from senders we cannot match to a client is not stored as messages — we keep only an aggregate per-sender tally (address, count, first/last seen) for 90 days so a firm admin can link the sender to a client, after which it is deleted.
- Synced email is visible to the firm only — never to the firm’s clients through the portal.
- Disconnecting a mailbox stops syncing and removes synced data attributable to that mailbox.
Limited Use.Taxly’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the email-linking feature described above; we do not transfer it except as necessary to provide that feature, for security, or to comply with law; we do not use it for advertising; and we do not use it to train generalized AI or machine-learning models, nor allow humans to read it except with the user’s consent, for security, or to comply with law.
7Plaid and bank data
For firms in the early-access bank-feed program, a firm’s client may connect their bank account through Plaid, a third-party financial-data network. When a bank connection is established:
- Bank credentials are entered with Plaid, not with Taxly — we never see or store them.
- We receive transaction history and account and balance information needed to do bookkeeping, scoped to the connected accounts.
- Plaid’s handling of data is governed by Plaid’s own privacy policy in addition to this notice.
- Disconnecting a bank connection stops future data retrieval; previously imported transactions remain in the firm’s books as accounting records.
- Account holders can also view and manage their Plaid connections directly at my.plaid.com.
8Sharing and subprocessors
We share data only with infrastructure and service providers that help us run Taxly, under contract and only as needed. Core subprocessors include Amazon Web Services (hosting, storage, identity, email, and AI inference — including Anthropic Claude models via AWS Bedrock, under enterprise terms), Plaid (bank data, for connected accounts), and Google (email sync, for connected mailboxes). We do not share client data with third parties for their own purposes.
9Where data lives
Taxly is operated from the United States. Data is stored in AWS’s us-east-1 (N. Virginia) region and processed in the United States; AI inference may run across AWS’s U.S. regions.
10Retention
We retain data for as long as a firm maintains its account, and as needed to provide the service and meet legal and professional record-keeping obligations. Signed documents are held in write-once storage for their retention period. On account closure, firms can request an export of their data; upon written request we then delete or de-identify firm data, except where retention is legally required (for example, signed documents held in write-once storage).
11Security incidents
If we become aware of a security incident affecting a firm’s data, we will notify the affected firm’s administrators without undue delay, share what we know as we investigate, and cooperate with the firm’s own notification obligations to its clients and regulators.
12Your choices and rights
Firm clients: your firm controls your data — contact your firm to access, correct, or delete it, and we will support them. Firm users: manage your profile and account data in-product. Depending on your jurisdiction, you may have additional rights over your personal data; we honor applicable requests routed through the controlling firm.
For data we process on a firm’s behalf, we act as a service provider / processor: we process it to provide the service on the firm’s instructions, and we do not sell it or use it for advertising. The aggregated merchant-category index described in Section 5 is used only to operate and improve the service. Residents of California and other U.S. states with privacy laws may have rights to access, correct, or delete personal information; because the firm is the controller of its clients’ data, those requests are honored through the firm.
13Children
Taxly is business software and is not directed at children under 13. We do not knowingly collect personal information from children.
14Changes to this notice
We may update this notice as the product evolves. Material changes will be communicated to firm administrators, and the effective date above will be updated. Prior versions are available on request.
15Contact
Questions about this notice or our data practices: hello@taxly.com. Security reports: security@taxly.com.