USTaxHub Privacy Notice
Introduction
USTaxHub ("USTaxHub", "we", "our" or "us"), offers tax filing and related services to Customers (as defined below) using the USTaxHub Portal (the "Portal"). The Portal enables Customers to upload information such as via an online tax questionnaire, excel/word questionnaire, review their own documents, and make payments.
We also offer the website www.ustaxhub.com (the "Site", and together with the Portal – the "Services"), which provides further information regarding our Services, our company and the ways to get in touch with us.
Specifically, it describes our practices regarding –
- Data Collection
- Data Uses
- Cookies and Tracking Technologies
- Storage and Retention
- Data Sharing
- Communications
- Data Security
- Data Subject Rights
- Children
- Data Controller/Processor
- Updates & How to contact us
Please read this notice and make sure that you fully understand and agree to it. If you do not agree to this notice, please discontinue and avoid using our Services.
You are not legally required to provide us with your Personal Data, but without it we will not be able to provide you with some or all of our Services, or certain features of the Services.
1. Data Collection
We collect the following categories of data (and to the extent it may enable the identification of a specific person, or is linked to such potentially identifying data, we will deem it as "Personal Data"):
Data automatically collected or generated: When someone visits, interacts with or uses our Services, we may collect or generate technical data about them. We do so either independently or with the help of third party services (as detailed in Sections 4 and 5 below).
Such data consists of connectivity, technical or aggregated usage data, such as IP address, non-identifying data regarding the device, operating system, browser version, locale and language settings used, the cookies and pixels installed on such device, and the activity (clicks and other interactions) of Users of our Services.
We do not use such data to learn a person's true identity or contact details, but mostly to have a better understanding on how our Users typically use and engage with our Services, to better secure our Services and to optimize the overall user experience and performance of our Services.
- Data received from you: You may provide us with Personal Data voluntarily, such as your name and e-mail address and/or phone number when you contact us or when you sign-up to receive e-mail updates; your name, e-mail address, and (hashed) password, when you register to use our Portal; and demographic (e.g., date of birth, marital status, spouse and dependents, occupation and physical address) and/or financial information (e.g., pensions, salaries, real estate and foreign bank accounts), when you submit information while using the Portal, e.g. when you upload tax questionnaires or other information to the secure client area on the Portal for our tax professionals to review.
- Data received from our corporate Customers: Our Customers who are legal entities as opposed to individuals may provide us with Personal Data regarding their users, namely the designated individuals in their organization who will use our Portal; and other Personal Data which may appear in the material transmitted by each Customer to USTaxHub ("Material"). Such data is processed by us solely on the behalf of our Customers, as further described in Section 10 below.
- Transaction Data: Customers may also provide us additional data in order to complete their selected transaction (such as their credit card number and related account and billing information, which we may update from time to time should they grant us permission to bill them for recurring charges), as well as their organization's information and preferences. To the extent that such information concerns a non-human entity (e.g., a company or business), we do not regard it as "Personal Data" and this Notice shall not apply to it.
- Data received from Third Parties: We may receive your Personal Data from other sources. For example, if you participate in an event or webinar that we sponsor or participate in, we may receive your Personal Data from the event organizers. We may also receive your contact and professional details (e.g., your name, company, position, contact details and professional experience, preferences and interests) from business partners or service providers and through the use of tools and channels commonly used to connect between companies and individuals in order to explore potential business and employment opportunities, such as LinkedIn.
2. Data Uses
We will use your Personal Data as necessary for the performance of our Services; for complying with applicable law; and based on our legitimate interests in maintaining and improving our Services and offerings, understanding how our Services are used, improving our customer service and support operations, and protecting and securing our Users, ourselves, our Services and members of the general public.Accordingly, we use Personal Data for the following purposes:
- To facilitate, operate, and provide our Services, e.g. preparing your tax return, and (following your signature) submission of the return to the US Internal Revenue Service (IRS);
- To authenticate the identity of our Users, and allow them access to additional features;
- To provide our Users with customer care, assistance and technical support services;
- To further develop, customize and improve the Services and your user experience, based on common or personal preferences, experiences and difficulties;
- To contact our Users with general or personalized service-related messages (such as purchase confirmations or system maintenance notices) and promotional messages (such as updates regarding new features and services, etc.), and to facilitate, sponsor and offer certain events and promotions;
- To support and enhance our data security measures, including for the purposes of preventing and mitigating the risks of fraud, error or any illegal or prohibited activity;
- To create aggregated statistical data, inferred non-personal data or anonymized or pseudonymized data (rendered non-personal), which we or our business partners may use to provide and improve our respective services; and
- To comply with any applicable laws and regulations.
3. Cookies and Tracking Technologies
Our Site utilizes "cookies", anonymous identifiers and other tracking technologies, which help us to provide and improve our Services, and in order to provide a better experience to our Users. In order for some of these technologies to work properly, a small data file ("cookie") must be downloaded and stored on your device. Some cookies and other technologies serve to recall Personal Data, such as an IP address, and are used for purposes of session and user authentication, security, keeping the user's preferences, connection stability, monitoring performance and generally providing and improving our Services.While we do not change our practices in response to a “Do Not Track” signal in the HTTP header from a browser, most browsers allow you to control cookies, including whether or not to accept them and to remove them. You may set most browsers to notify you if you receive a cookie, or to block cookies with your browser.
4. Storage and Retention
Your Personal Data may be maintained, processed, accessed and stored by USTaxHub and our authorized affiliates, Service Providers (as defined below) and business partners worldwide, as necessary for the proper delivery of our Services, or as may be required by law.While privacy laws may vary between jurisdictions, we have taken reasonable steps to ensure that your Personal Data is treated by its affiliates and Service Providers in a secure and lawful manner, and in accordance with common industry practices, regardless of any lesser legal requirements that may apply in their jurisdiction.
We retain your Personal Data for the period necessary in order to maintain and expand our relationship, and to provide you with our Services. In other words, we will retain your Personal Data for as long as you remain our User and have not notified us otherwise. We will also retain your Personal Data for legal and accounting purposes (i.e. as required by laws applicable to our record and bookkeeping, and in order to have proof and evidence concerning our relationship, should any legal issues arise following your discontinuance of use).
Please note that except as required by applicable law, we will not be obligated to retain your data for any particular period, and are free to securely delete it for any reason and at any time, with or without notice to you. We periodically delete unused Personal Data.
5. Data Sharing
We may share your data with certain third parties, including law enforcement agencies, our service providers and our affiliates – but only in accordance with this Notice:- Compliance with Laws, Legal Orders and Authorities: We may disclose or allow government and law enforcement officials access to certain Personal Data, in response to a subpoena, search warrant or court order (or similar requirement), or in compliance with applicable laws and regulations, including for national security purposes. Such disclosure or access may occur with or without notice to you, if we have a good faith belief that we are legally compelled to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing.
- Service Providers and Business Partners: We may engage selected third party companies and individuals to perform services complementary to our own (e.g. hosting and database services, data analytics services, data and cyber security services, marketing and advertising services, payment processing services, e-mail distribution and monitoring services, session recording services, and our business, legal, financial and compliance advisors) (collectively, "Service Providers"). These Service Providers may have access to your Personal Data, depending on each of their specific roles and purposes in facilitating and complementing our Services, and may only use it for such purposes.
- Sharing Personal Data with our Customers: We may share the Personal Data of our Customer’s users with such Customer. USTaxHub is not responsible for and does not control any further disclosure, use or monitoring by or on behalf of its Customers, that themselves may act as the “Data Controller” of such data (as further described in Section 10 below).
- Subsidiaries and Affiliated Companies: We may share Personal Data internally within our family of companies, for the purposes described in this Notice. In addition, should we or any of our affiliates undergo any change in control or ownership, including by means of merger, acquisition or purchase of substantially all or part of its assets, your Personal Data may be shared with the parties involved in such event (including prior to such event). If we believe that such change in control might materially affect your Personal Data then stored with us, we will notify you of this event and the choices you may have via e-mail and/or prominent notice on our Services.
For the removal of doubt, we may share your Personal Data in additional manners, pursuant to your explicit approval, if we are legally obligated to do so, or if we have successfully rendered such data non-personal and anonymous. We may share or otherwise use non-personal data in our sole discretion and without the need for further approval.
6. Communications
Service Communications: we may contact you with important information regarding our Services. For example, we may notify you (through any of the means available to us) of changes or updates to our Services, billing issues, etc. You will not be able to opt-out of receiving such service communications.Promotional Communications: we may also notify you about new services, events and special opportunities or any other information we think you will find valuable. We will provide such notices through any of the contact means available to us (e.g. phone, mobile or e-mail), through the Services, or through our marketing campaigns on any other sites or platforms. If you wish not to receive such promotional communications, you may notify us at any time by e-mailing us at [email protected] or by following the "unsubscribe", "stop" or "change e-mail preferences" instructions in the promotional communications you receive.
7. Data Security
In order to protect your Personal Data held with us and our Service Providers, we use industry-standard physical, procedural and electronic security measures, including encryption where deemed appropriate, such as when we collect sensitive information including credit card data or personal financial information. Only those employees who need the information to perform a specific function (for example, billing, customer service, or providing the Services) are granted access to Personal Data. However, please be aware that regardless of any security measures used, we cannot and do not guarantee the absolute protection and security of any Personal Data stored with us or with any third parties. We are not responsible for the privacy practices of third party sites to which our Site contains links.
8. Data Subject Rights
If you wish to exercise your rights under applicable law to request access to, and/or rectification or erasure of your Personal Data held by us; to restrict or object to such Personal Data’s processing; or to port such Personal Data – please contact us at [email protected].Please note that once you contact us by e-mail, we may require additional information and documents, including certain Personal Data, in order to authenticate and validate your identity and to process your request. Such additional data will be then retained by us for legal purposes (e.g. so we have proof of the identity of the person submitting the request), in accordance with the applicable provisions of this Notice.
Please note that in some cases, as we may rely on our Service Providers' APIs and systems, your requests may require several weeks to process.
9. Children
Our Services are not designed to attract children under the age of 16. We do not knowingly or intentionally collect Personal Data from children and do not wish to do so. If we learn that a child is using the Services, we will prohibit and block such use and will make all efforts to promptly delete any Personal Data stored with us with regard to such child.If you believe that we might have any such data, please contact us at [email protected]
10. Data Controller/Processor
Certain data protection laws and regulations typically distinguish between two main roles for parties processing Personal Data: the "Data Controller", who determines the purposes and means of processing, and the "Data Processor", who processes the data on behalf of the Data Controller. To the extent that such laws and regulations apply, USTaxHub is the "Data Controller" of Visitors' and Customers’ Personal Data collected by USTaxHub, and assumes the responsibilities of Data Controller (solely to the extent applicable under law), and as set forth under this Notice.If a Customer is an entity who uploads or submits any Personal Data concerning Users from such Customer's organization, or transmits any materials containing Personal Data to our Services, such Customer is deemed the "Data Controller" of this Personal Data, and we will only process it on the Customer's behalf, as their "Data Processor". This means that in such cases, we will only process such data on behalf of such Customers and in accordance with their reasonable instructions, subject to our contractual agreements. Such Customers will be solely responsible for meeting any legal requirements applicable to Data Controllers (such as establishing a legal basis for processing and responding to Data Subject Rights requests concerning the data they control).
If you are a data subject of any of our Customers (either their employee, or an individual whose Personal Data appears in any Materials), please note that USTaxHub only processes your data solely on such Customer's behalf. If you would like to make any requests or queries regarding your Personal Data, we encourage then to contact such Customer(s) directly. For example, if you wish to access, correct, or delete data processed by USTaxHub on behalf of its Customers, please direct your request to the relevant Customer (who is the “Controller” of such data). Unless otherwise instructed by our Customer, we will retain the Personal Data processed on their behalf for the period set forth in Section 4 above.
11. Updates & How to Contact Us
Updates and amendments: We may update and amend this Notice from time to time by posting an amended version on our Services. The amended version will be effective as of the published effective date. We will provide an advance notice if any substantial changes are involved, via any of the communication means available to us, or on the Services. After this notice period, all amendments shall be deemed accepted by you.Questions, Concerns or Complaints: If you have any comments or questions about this Notice or if you have any concerns regarding your Privacy, please contact us at [email protected]