Privacy Policy

Effective Date: July 1, 2026 · Last Updated: July 4, 2026 (rev 2)

Questions? Email privacy@taxero.ai

1. Introduction

Taxero, LLC ("Taxero," "we," "us," or "our") operates Taxero, a sales tax compliance platform for e-commerce sellers ("Service"). This Privacy Policy explains how we collect, use, store, share, and protect information about you when you use our Service.

By creating an account or using Taxero, you agree to this Privacy Policy. If you do not agree, do not use the Service.

2. Information We Collect

2.1 Information You Provide Directly

  • Account information: name, email address, business name, state of incorporation
  • Phone number: Collected to deliver one-time passcodes for account security verification (see Section 3).
  • Tax identification: Employer Identification Number (EIN) — encrypted at rest with AES-256-GCM
  • Identity verification: government-issued ID and selfie captured via Stripe Identity — processed by Stripe; we store only the verification status
  • Social Security Numbers (SSN): Collected from business owners during registration onboarding. Required by certain state Departments of Revenue to process sales tax registration applications on your behalf. SSNs are encrypted at rest using AES-256-GCM encryption; plaintext is never written to our database or logs. SSNs are transmitted only to the applicable state DOR during the registration process and are deleted from active storage once registration is complete. SSNs are not shared with any third party other than the applicable state DOR during registration.
  • Driver's License Numbers (DLN): Collected from business owners during registration onboarding for state registration identity verification purposes. DLNs are encrypted at rest using AES-256-GCM encryption and are subject to the same security controls as SSNs described above. DLNs are transmitted only to the applicable state DOR during the registration process and are deleted from active storage once registration is complete. DLNs are not shared with any third party other than the applicable state DOR during registration.
  • Portal credentials (state tax authority accounts): For states where Taxero files on your behalf via direct portal access, we collect the portal username and password you provide. These credentials are encrypted at rest using AES-256-GCM encryption and are used solely to access the applicable state tax portal to file your returns. Credentials are never shared with third parties other than transmission to the applicable state portal during the filing process.
  • Bank account information (ACH/remittance): If you enroll in Filing Services, we collect bank account and routing numbers to enable direct debit by state tax authorities. This information is encrypted at rest and transmitted directly to the applicable state portal. Taxero does not store or transmit this information to any party other than the applicable state tax authority.
  • Sales data: Sales transaction data uploaded via CSV files (transaction amounts, dates, buyer states, platform source). In the future, we may also accept data via direct platform integrations. We will update this policy when integrations launch.

2.2 Information Collected Automatically

  • IP address and browser/device information for security and fraud prevention
  • Usage logs (pages viewed, features used) for product improvement
  • Session cookies required for authentication (see Section 9)

2.3 Information from Third Parties

  • Stripe: payment status, subscription status, identity verification result

3. SMS Communications

We use your phone number solely to send one-time passcodes (OTP) for account security verification. We do not sell, rent, or share your mobile phone number with third parties for marketing purposes. Message frequency varies based on account activity. Message and data rates may apply. Reply STOP to opt out or HELP for assistance.

4. How We Use Your Information

  • To calculate your sales tax obligations (nexus detection, filing generation)
  • To file sales tax returns on your behalf with state tax authorities
  • To verify your identity (KYC) as required for financial compliance
  • To process payments for subscriptions and filing fees
  • To send transactional notifications (filing confirmations, nexus alerts)
  • To provide customer support
  • To detect fraud and ensure platform security
  • To improve our product and services (aggregated, anonymized analytics only)

We do not use your data for advertising. We do not sell your data to third parties.

5. EIN Handling

Your Employer Identification Number (EIN) is a sensitive financial identifier. We handle it with extra care:

  • Encrypted at rest: AES-256-GCM encryption; plaintext never written to our database
  • Never logged: EINs are never written to application logs
  • Transmitted only to DOR: Your EIN appears only in the return filed with the relevant state Department of Revenue — and nowhere else in our systems
  • Masked in UI: EINs are displayed as **-*****XXXX (last 4 digits only)
  • Isolated per seller: Row Level Security in our database ensures your data cannot be accessed by other sellers

6. Data Retention

  • Tax records: Retained for 7 years as required by IRS regulations and state tax authority requirements
  • Account data: Retained until account deletion, then anonymized within 30 days (except records required by law)
  • Identity verification: Stripe retains verification records per their policy; we retain only the verification status and date
  • Support conversations: Retained for 2 years for audit and support quality purposes
  • State portal credentials: Deleted promptly upon your revocation of credential authorization, and in any event within 30 days of account closure.
  • Bank account / ACH information: Retained while you are enrolled in Filing Services and deleted upon cancellation of Filing Services or account closure, except that ACH authorization records are retained for two (2) years following termination or revocation as required by applicable payment network (NACHA) rules.

7. Your Customers' Data

When you upload transaction data to Taxero, that data may include information about your end customers (transaction amounts, buyer states, and similar data). Taxero processes this data solely to provide the Service to you.

  • We do not sell, share, or use your customers' data for any purpose other than providing the Service
  • We do not use your customers' data for advertising or profiling
  • We act as a service provider / data processor with respect to this data — you remain the controller
  • Your customers' transaction data is subject to the same 7-year retention schedule as your other tax records
  • Upon termination of your account, we will delete your customers' transaction data per the retention schedule in §6, subject to applicable legal retention requirements

If you are subject to CCPA or similar privacy laws with respect to your end customers, this section provides the contractual basis for your use of Taxero as a service provider for that data.

8. Data Sharing

We share your data only with:

  • State tax authorities: Your sales tax return is filed with the relevant state Department of Revenue on your behalf
  • Stripe: For payment processing and identity verification (Stripe Privacy Policy applies)
  • Supabase: Our database and file storage provider (data stored in US-based infrastructure)
  • Anthropic: AI processing (nexus analysis, return generation). Transaction data and filing context shared; no PII beyond what's necessary for filing. Under our API agreement, data sent to Anthropic is not used to train Anthropic's models. The same applies to OpenAI under our backup arrangement.
  • OpenAI: AI processing (backup). Data is not used to train OpenAI's models under our API agreement.
  • Cloudflare: CDN, security, and DDoS protection. Connection metadata (IP addresses) only; no personal data transmitted to Cloudflare beyond standard CDN operation.
  • Resend (email) / Twilio (SMS): Transactional notifications (filing confirmations, OTP codes, deadline reminders). Email address and phone number only. No marketing data shared.
  • Legal requirements: If required by law, court order, or government request

We do not sell your personal data. We do not share your data with advertisers.

9. Cookies

We use only authentication cookies required for the Service to function:

  • sb-auth-token — Your authentication session (expires when you log out or after 1 hour)
  • sb-refresh-token — Used to refresh your session (expires after 7 days)

We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.

10. Your Rights

All Taxero users have the following privacy rights. Users in California, Virginia, Colorado, Connecticut, Texas, Utah, Montana, Florida, Oregon, Delaware, and other states with comprehensive privacy laws may have additional rights under applicable law.

  • Know: Request disclosure of the personal information we have collected about you
  • Delete: Request deletion of your personal information (subject to legal retention requirements for tax records)
  • Opt-out: We do not sell personal information — there is nothing to opt out of
  • Non-discrimination: We will not discriminate against you for exercising your privacy rights
  • Correct: Request correction of inaccurate personal information
  • Portability: Receive your data in a portable format upon request

Right to Appeal: If we deny your request to exercise any privacy right, you have the right to appeal our decision. To appeal, email privacy@taxero.ai with "Appeal" in the subject line. We will respond within 30 days.

To exercise any of these rights, email privacy@taxero.ai with the subject line "Privacy Rights Request."

11. Shopify GDPR Compliance

Taxero is built to meet Shopify's mandatory GDPR requirements for App Store listing. We implement all three required GDPR webhook endpoints:

  • Customer Data Request: When a customer requests a copy of their data, Shopify notifies us and we prepare a data export for the requesting customer.
  • Customer Data Erasure: When a customer requests deletion, we anonymize all personally identifiable information (name, email, address) in their transaction records. Transaction amounts and dates are retained as required for 7-year tax record obligations — the data can no longer be linked to the individual.
  • Shop Data Erasure: When a merchant uninstalls the Taxero app, we queue full deletion of their seller account and associated data. Deletion executes after a mandatory 48-hour window as required by Shopify policy.

All GDPR webhook requests are verified using HMAC-SHA256 signatures before processing. Every request is logged in our audit trail with a unique request ID.

Shopify GDPR Compliant

12. Security

We protect your data with:

  • AES-256-GCM encryption for sensitive fields (see Encrypted fields below)
  • TLS 1.2+ for all data in transit
  • Row Level Security at the database layer (sellers cannot access each other's data)
  • JWT authentication with cryptographic signature verification
  • Rate limiting and DDoS protection via Cloudflare WAF

Encrypted fields: The following fields are encrypted at rest with AES-256-GCM beyond standard database encryption: EIN, SSN, Driver's License Numbers, state portal credentials, bank account information. Encryption keys are managed separately from the encrypted data.

Breach notification: In the event of a security breach that affects your personal information, we will notify you in accordance with applicable law. Notification will be sent to your registered email address.

No security system is perfect. If you discover a security vulnerability, please email security@taxero.ai before public disclosure.

13. Changes to This Policy

We will notify you of material changes to this Privacy Policy by email (at the address on your account) at least 30 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

Taxero, LLC
531 Breton Drive
Grand Prairie, TX 75052
Email: privacy@taxero.ai · support@taxero.ai