TaxAgentPortal provides software infrastructure. The firm using the platform remains responsible for how it collects, uses, manages, and handles client information within its own professional relationship.
1. Information we collect
- Account info: name, email, phone, firm details, role.
- Client info entered by firms: contact details, entity info, identifiers used for tax workflows.
- Tax documents: files uploaded by firms or their clients (receipts, statements, returns, BAS records).
- Usage data: log data, device/browser info, IP, feature usage analytics.
- Payment data: processed by Stripe; we do not store card numbers.
2. How we use information
- To provide and operate the platform.
- To authenticate users and protect accounts.
- To process subscription payments.
- To communicate operationally about the service.
- To improve product quality and security.
3. Where data is stored
Data is stored using third-party cloud infrastructure. Data may be processed in regions where these providers operate. We require providers to use industry-standard security controls.
4. Third-party services
See Subprocessors for the current list, including Supabase (database, auth, storage), Stripe (payments), Lovable (hosting/build), and future email providers.
5. Security
See our Data Security Statement for technical safeguards. No system is 100% secure; you must keep your password and devices secure.
6. Access control
Row-level security restricts records to the firm and roles permitted to view them. Clients can only see their own records. Staff see only their own firm.
7. Data retention
We retain data for as long as your account is active or as needed to provide the service. Firms may request export or deletion subject to legal retention obligations that apply to them.
8. Your rights
You may request access, correction, or deletion of your personal information by contacting us. Where firms control client data, requests from clients should be directed to the firm first.
9. Breach notification
If we become aware of a personal information breach that is likely to result in serious harm, we will notify affected users and act in accordance with applicable notification laws.
10. International / global users
The platform may be accessed globally. Users outside Australia are responsible for ensuring use complies with their local privacy laws (e.g. GDPR, CCPA).
11. Contact
Privacy enquiries: legal@taxagentportal.com.au