Legal

Privacy Policy

Effective Date: March 10, 2026 • Last Updated: March 10, 2026

This Privacy Policy describes how TaxCreditScan ("Company," "we," "us," "our") collects, uses, discloses, and protects your information when you use our Service. By using the Service, you consent to the practices described in this Privacy Policy.

1. Information We Collect

1a. Information You Provide Directly

  • Account Information: Name, email address, and password when you create an account.
  • Payment Information: Payment card details and billing address are processed by Stripe. We do not store your complete payment card number.
  • Tax Documents: Files you upload for analysis, including Form 1040, W-2s, 1099s, schedules, and state returns. These may include sensitive personal and financial information.
  • Quiz Responses: Filing status, occupation, number of dependents, and other tax-relevant information.
  • Communications: Information provided when contacting support at contact@taxcreditscan.com.

1b. Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, click events, and interaction patterns.
  • Device Information: Browser, OS, device type, screen resolution, and unique device identifiers.
  • Log Data: IP address, access times, referring URLs, and error logs.
  • Cookies and Similar Technologies: Cookies, pixels, and similar tools for analytics, functionality, and advertising.

1c. Information from Third Parties

  • Payment Processor: Transaction confirmation and payment status from Stripe.
  • Analytics Providers: Aggregated usage data from analytics services.

2. How We Use Your Information

  • Provide the Service: Analyze documents, generate reports, and deliver output.
  • Process Payments: Complete transactions and send confirmations/invoices.
  • Improve the Service: Analyze usage and technical issues, develop features, and use anonymized, aggregated data to improve machine learning systems.
  • Communicate with You: Support, service notices, and responses to inquiries.
  • Marketing: With consent, send product updates and reminders. You can opt out at any time.
  • Legal Compliance: Meet legal, regulatory, and governmental requirements.
  • Security: Detect and prevent fraud, abuse, and unauthorized access.

3. How We Handle Your Tax Documents

Your tax documents contain sensitive personal and financial information.

  • Processing: Documents are analyzed by automated systems, including third-party AI services (such as Anthropic Claude API), to generate output.
  • Transmission: Documents are transmitted using TLS 1.2+ encryption in transit.
  • Storage: Uploaded documents and extracted data are stored in encrypted form on secure cloud infrastructure and retained only as long as necessary under this policy.
  • Third-Party AI Processing: Content is sent via encrypted API calls. We use providers that do not use customer inputs to train their models.
  • No Human Review by Default: Documents are processed automatically. Personnel access is limited to explicit support consent, legal requirements, or fraud/abuse investigation.
  • No Sale of Tax Data: We do not sell, rent, or trade tax document contents or extracted financial data for third-party marketing or commercial purposes.

4. How We Share Your Information

  • Service Providers: Cloud, payment, analytics, and AI vendors that operate under contractual data protection requirements.
  • Legal Requirements: Disclosures required by law, subpoena, court order, or necessary to protect rights, safety, or investigate fraud.
  • Business Transfers: Information may transfer in mergers, acquisitions, reorganizations, bankruptcy, or asset sales.
  • Aggregated and Anonymized Data: We may share de-identified data that cannot reasonably identify you.
  • With Your Consent: We may share information when you explicitly authorize us.

5. Data Retention

  • Tax Documents: Retained for ninety (90) days after scan completion, then automatically and permanently deleted. You may request earlier deletion at any time at contact@taxcreditscan.com.
  • Account Information: Retained while your account is active; removed within thirty (30) days after deletion, except where legal retention is required.
  • Payment Records: Retained for seven (7) years for tax/accounting compliance.
  • Usage/Analytics Data: Retained in anonymized or aggregated form up to twenty-four (24) months.
  • Machine Learning Training Data: Only anonymized, aggregated derived features are used. No individual tax documents or directly identifying personal information are used directly as training data.

6. Data Security

We implement commercially reasonable technical and organizational safeguards, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
  • Need-to-know access controls for personnel.
  • Regular security assessments and monitoring.
  • Secure cloud infrastructure with SOC 2-compliant hosting providers.

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

7. Cookies and Tracking Technologies

We use:

  • Essential Cookies: Required for authentication, session management, and security.
  • Analytics Cookies: Used to understand product usage (e.g., Google Analytics, PostHog, or similar).
  • Marketing Cookies: Used for advertising relevance and campaign measurement, with consent where required.

You can control cookies in browser settings, but some features may be limited if disabled.

8. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access personal information we hold about you.
  • Correct inaccurate or incomplete personal information.
  • Delete personal information, subject to legal retention requirements.
  • Receive portable copies of your data in structured, machine-readable format.
  • Opt out of marketing communications.
  • Opt out of sale/sharing where applicable under local law.

To exercise rights, contact contact@taxcreditscan.com. We respond within 30 days or as required by law.

9. California Privacy Rights (CCPA/CPRA)

California residents may have additional rights to know, delete, correct, and opt out as defined by CCPA/CPRA. We do not sell personal information as defined under CCPA/CPRA.

10. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children under 18.

11. International Users

The Service is operated from the United States. If you access it from outside the U.S., your information will be transferred to, stored in, and processed in the United States.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be posted with an updated "Last Updated" date. Continued use of the Service constitutes acceptance of the updated policy.

13. Contact

For privacy questions or rights requests, contact: contact@taxcreditscan.com

These documents are provided for informational purposes and should be reviewed by a licensed attorney to ensure compliance with all applicable laws in your jurisdiction.