Privacy Policy

Last updated: January 2026

1. Overview

Auditable Intake (“we”, “our”, “us”) operates the website intake.auditable.tax and provides compliance-first tax intake services to tax preparation firms. This Privacy Policy describes how we collect, use, store, and protect information.

2. Information We Collect

2.1 Public Intake Data

Our public intake forms are designed to collect the minimum information necessary to qualify a prospective client. This may include:

  • Name and contact information (email, phone)
  • Tax year and filing type
  • General tax situation indicators (employment type, rental, crypto, etc.)
  • Preferred contact method and appointment preferences

We do not collect Social Security Numbers, dates of birth, bank account information, or tax documents through our public intake forms.

2.2 Secure Onboarding Data

After engagement, firms may collect sensitive taxpayer information through our secure upload workflow. This data is encrypted at rest and in transit. Sensitive data includes:

  • SSNs and ITINs
  • Dates of birth
  • Spouse and dependent information
  • Tax documents (W-2s, 1099s, etc.)
  • Bank account information
  • Prior-year tax returns

2.3 Firm Account Data

We collect account information from tax firms including:

  • Firm name, slug, and branding assets
  • Contact email and phone
  • Staff user accounts and role assignments
  • Billing information (processed via Stripe)

2.4 Automatically Collected Data

  • IP addresses and user agents for audit logging
  • Usage analytics (page views, form submissions)
  • Cookies for session management

3. How We Use Information

  • To provide and operate the intake and onboarding service
  • To generate risk flags, complexity scores, and document checklists
  • To maintain audit trails and evidence records
  • To communicate with firms and their clients about intake status
  • To process billing and subscription management
  • To improve our service and prevent fraud

4. Data Storage and Security

  • All data is encrypted in transit (TLS) and at rest (AES-256)
  • Document uploads are stored in encrypted S3-compatible storage
  • Access is controlled by role-based permissions
  • Upload links expire after a configurable period
  • Sessions require OTP verification for sensitive operations

5. Data Retention

Each firm configures their own retention policy. Default retention is aligned with IRS record-keeping guidance. Firms may delete client data at any time through the platform. Deletion events are logged.

6. Data Sharing

We do not sell, rent, or share personal information with third parties except:

  • With the tax firm that created the intake (their client data)
  • Service providers necessary to operate the platform (hosting, email, billing)
  • As required by law or legal process

6.1 Subprocessors

  • Cloud storage: Wasabi or MinIO
  • Email delivery: Amazon SES
  • Billing: Stripe
  • Infrastructure: as disclosed on our security page

7. Your Rights

If you are a client of a tax firm using our service, you may contact that firm directly regarding your data. You may also contact us at privacy@auditable.tax to:

  • Request access to your personal information
  • Request correction or deletion
  • Object to processing
  • Request data portability

8. FTC Safeguards Rule

Our service is designed to support firms' obligations under the FTC Safeguards Rule, including data minimization, access controls, encryption, and audit logging. However, firms remain responsible for their own compliance programs.

9. Children's Privacy

Our service is not directed to children under 13. We do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify firms of material changes via email. Continued use of the service after changes constitutes acceptance.

11. Contact

Auditable Intake
privacy@auditable.tax