Privacy Policy

Last updated: August 18, 2026

1. Who We Are

Delegait is a software platform operated by DelegAIT LLC, a California limited liability company ("Delegait", "we", "us", or "our"). Delegait provides cloud-based software that accounting and tax firms use to manage bookkeeping, tax workflows, client communication, and document handling for their own clients.

Delegait is a software provider, not an accounting or tax firm. We do not prepare tax returns, perform bookkeeping, or provide tax, accounting, or legal advice. Those professional services are provided by the independent firms that subscribe to our platform ("Firms"). If you are a client of a Firm, a "Taxpayer", your professional relationship and the primary responsibility for your information rest with that Firm.

This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices and rights available to you. It applies to the Delegait platform, our websites, and related services, together the "Service".

2. Our Two Roles: When We Are a Controller and When We Are a Processor

The Service handles two distinct classes of personal information, and our legal role differs for each. Understanding this distinction tells you whom to contact about your data.

Firm Account Data, where Delegait is the controller. When a Firm signs up for the Service, we collect information about the Firm and its personnel: names, email addresses, business information, login credentials, billing details, and usage records. For this information, Delegait decides how and why it is processed.

Firm Client Data, where Delegait is a processor. Firms use the Service to store and manage information about their own clients: tax information, financial and accounting records, and supporting documents. For this information, the Firm is the controller, or "business" under California law, and Delegait is a processor, or "service provider". We process Firm Client Data only on the Firm's documented instructions and under the terms of our Data Processing Addendum. We do not use Firm Client Data for our own purposes, we do not sell it, and we do not decide what is collected or why.

If you are a Taxpayer whose information a Firm has entered into the Service, your requests about that information, whether access, correction, deletion, or questions about consent, should be directed to your Firm. We will support the Firm in responding, and if you contact us directly we will refer your request to the Firm and assist as its processor.

3. Information We Collect

Information Firms provide about themselves.

  • Account and identity data: name, business name, email address, phone number, role or title, and login credentials. Used to create and administer accounts, authenticate users, and provide support.
  • Business and billing data: firm details, subscription plan, and payment-related information. Used for invoicing, account management, and compliance with our contractual and legal obligations.
  • Communications: messages you send to our support channels. Used to respond to you and improve the Service.

Information Firms provide about their clients. Firms may enter, upload, or connect the following categories about Taxpayers. We process this information solely as the Firm's service provider:

  • Identity and contact information: names, addresses, email addresses, phone numbers.
  • Government identifiers: Social Security numbers and other tax identification numbers.
  • Financial and accounting records: bookkeeping data, transactions, account balances, financial statements, and data synchronized from accounting systems such as QuickBooks Online.
  • Tax return information: information furnished for, or in connection with, the preparation of tax returns, which receives additional protections described in Section 7.
  • Documents: files uploaded by the Firm or by Taxpayers through the portal, such as statements, receipts, notices, and signed forms.

Information collected automatically.

  • Access and security logs: login events, IP address, browser and device information, timestamps, and records of access to sensitive records. Used for security monitoring, fraud prevention, troubleshooting, and the audit trail described in Section 10.
  • Usage data: pages and features used, and performance and error data. Used to operate, secure, and improve the Service.
  • Cookies and similar technologies: as described in Section 16.

We do not collect precise geolocation or biometric information.

4. How We Use Information

We use Firm Account Data to provide, maintain, and secure the Service; to set up and administer accounts, authenticate users, and enforce role-based permissions; to bill for the Service and send service and security notices; to provide customer support; to monitor for, prevent, and investigate security incidents, fraud, and misuse; to improve the Service, using aggregated or de-identified information where feasible; and to comply with legal obligations and enforce our agreements.

We use Firm Client Data only to provide the Service to the Firm according to its instructions and our Data Processing Addendum; to maintain the security, integrity, and availability of that data, including backups and access logging; and to comply with applicable law.

We do not use Firm Client Data for advertising, for marketing to Taxpayers, to build profiles for our own purposes, or to train artificial intelligence models. We do not sell or share personal information as those terms are defined under California law.

5. Artificial Intelligence Features

Certain features of the Service use artificial intelligence to assist Firms with accounting categorization, for example suggesting how a transaction should be classified. These features are powered by Anthropic, an AI provider that acts as one of our subprocessors.

  • What is sent: the transaction and accounting context needed to generate a categorization suggestion.
  • We do not send your tax documents to an AI provider. Automatic reading of uploaded documents such as W-2s, 1099s, and K-1s is turned off. Those documents are not transmitted to Anthropic or to any other AI provider, and we do not store the text extracted from them.
  • What we do not do. We do not use these features for advertising or profiling, and we do not send data to any AI provider other than the ones listed at /subprocessors.
  • No model training: data submitted through these features is not used by us, and under our contractual terms is not used by the provider, to train models for third parties.
  • Human responsibility: AI outputs are suggestions. The Firm remains responsible for reviewing and approving accounting classifications.

6. QuickBooks Online Integration

Firms may connect the Service to Intuit QuickBooks Online to synchronize accounting data. If a Firm authorizes this connection, we receive accounting data from QuickBooks Online under the scope of that authorization and process it as Firm Client Data under the Firm's instructions. OAuth access tokens used for the connection are stored encrypted. The Firm can disconnect the integration at any time from within the Service or through Intuit's own controls, which revokes our access to new data from that connection. Intuit's handling of information within QuickBooks Online is governed by Intuit's own privacy policy, not this one.

Delegait is not affiliated with, endorsed by, or sponsored by Intuit Inc. QuickBooks is a trademark of Intuit Inc.

7. Tax Return Information and IRC Section 7216

Some information processed on the Service is tax return information: information furnished in connection with the preparation of a tax return. Federal law, including Internal Revenue Code section 7216 and its regulations, restricts how tax return preparers and their contractors may use and disclose this information, with civil and criminal penalties for violations.

Our commitments:

  • We process tax return information solely to provide the Service to the Firm, as an auxiliary service provider to the tax return preparer. We do not use it for our own purposes, including product marketing, advertising, or analytics unrelated to providing the Service.
  • Consents belong to the Firm's relationship with the Taxpayer. Where section 7216 requires a taxpayer's consent for a use or disclosure, obtaining that consent is the responsibility of the Firm as the tax return preparer. Delegait does not solicit consents from Taxpayers on its own behalf.
  • We apply heightened technical controls to tax return information and related identifiers, as described in Sections 10 and 11.
  • Our personnel access tax return information only when necessary to operate, support, or secure the Service, and such access is logged.

8. GLBA and the FTC Safeguards Rule

Firms that provide tax preparation and related financial services are generally financial institutions under the Gramm-Leach-Bliley Act, and much of the Firm Client Data on the Service is nonpublic personal information under the GLBA Privacy Rule. As a service provider to those Firms, Delegait:

  • Uses nonpublic personal information only to perform the services for which it was disclosed to us, and does not disclose or reuse it for other purposes, consistent with GLBA's limits on reuse and redisclosure;
  • Maintains a written information security program with administrative, technical, and physical safeguards designed to meet the FTC Safeguards Rule, 16 CFR Part 314, including a designated individual responsible for the program, risk assessments, access controls, encryption, monitoring, personnel training, oversight of our own service providers, and an incident response plan;
  • Contractually commits to appropriate safeguards in our Data Processing Addendum, which Firms can rely on to meet their own obligation to oversee service providers.

Firms remain responsible for their own GLBA privacy notices to their clients; this Privacy Policy does not replace a Firm's notice.

9. How We Share Information, and Our Subprocessors

We share personal information only in the following circumstances:

  • Subprocessors. We use a limited set of vendors to host and operate the Service. Our current subprocessors are Anthropic, Cloudflare, Google, Intuit, Resend, Stripe, Supabase, and Vercel. The authoritative, current list, including each subprocessor's function, is published at /subprocessors. Each subprocessor is bound by contractual obligations of confidentiality and data protection, and we notify Firms of subprocessor changes as described in the Data Processing Addendum.
  • At the Firm's direction. We disclose Firm Client Data to the Firm that controls it and to persons the Firm authorizes, for example a Taxpayer accessing their own documents through the portal.
  • Legal requirements. We may disclose information when required by law, subpoena, or court order, or to protect the rights, safety, or property of Delegait, our customers, or others. Where legally permitted, we will notify the affected Firm before disclosing Firm Client Data in response to legal process so the Firm can seek protective measures.
  • Corporate transactions. If Delegait is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy's commitments and the Data Processing Addendum.

We do not sell personal information, share it for cross-context behavioral advertising, or disclose it to data brokers.

10. How We Protect Information

We maintain a written information security program with safeguards that include:

  • Encryption in transit and at rest for data stored on the Service;
  • Field-level encryption of tax identifiers such as Social Security numbers, so these values are separately encrypted within the database beyond ordinary disk-level encryption;
  • Role-based access control, so users and personnel can access only what their role requires;
  • Access logging for sensitive records, creating an audit trail of who accessed what and when;
  • Independent encrypted backups, maintained separately from production systems;
  • Personnel confidentiality obligations and security training, vendor due diligence, and an incident response plan.

No system is perfectly secure, and we cannot guarantee absolute security. We commit to maintaining safeguards appropriate to the sensitivity of the information we process and to the requirements described in Section 8.

11. Where Information Is Processed, and Access from Outside the United States

Our production systems are hosted with the infrastructure subprocessors listed at /subprocessors, in data centers located in the United States.

Some development and support work for the platform is performed from Tijuana, Mexico. We state this plainly because we believe Firms and Taxpayers are entitled to know where their data may be accessed. The controls that apply to this access include:

  • Masking of Social Security numbers and similar tax identifiers before support or development access of this kind, so full identifiers are not exposed in the course of that work;
  • Role-based access limits, so cross-border access is restricted to what the specific task requires;
  • Logging of access to sensitive records, wherever the access originates;
  • The same confidentiality obligations, security training, and information security program requirements that apply to all Delegait personnel.

Where the law requires a specific taxpayer consent for access to tax return information from outside the United States, that consent is obtained separately by the Firm, as described in Section 7.

Firms that require additional restrictions on cross-border access can address them in their agreement with us.

12. How Long We Keep Information

Retention differs by data class, and follows our written retention schedule:

  • Original uploaded files, such as the source PDF or image of a bank statement, are cleared 18 months after the import has been processed. Once a statement has been parsed, the original file is no longer needed for day-to-day work, and purging it early reduces the amount of raw financial-document data at rest.
  • Structured tax and bookkeeping records, including imported transactions, client documents such as W-2s and 1099s, and tax return records, are retained for 7 years from creation, then marked for deletion and, after a 30-day grace period, disposed of. The 7-year window matches IRS and California recordkeeping expectations for tax records.
  • Firm Account Data is retained for the life of the Firm's subscription and afterward only as needed for billing, contract, and tax records, and to resolve disputes.
  • Access logs and audit records are retained long enough to support security investigations and the audit obligations described in Sections 8 and 10, and are rotated on a defined schedule.
  • Encrypted backups roll off on a fixed cycle after the corresponding data is deleted from production. Data deleted from production may persist in backups until that cycle completes, during which it remains encrypted and is not restored except for disaster recovery.
  • On termination of a Firm's subscription, Firm Client Data is returned to the Firm, deleted, or both, in accordance with the Data Processing Addendum.

Legal retention obligations take precedence over deletion requests. Tax and accounting records are subject to statutory retention requirements. Where the law, or the Firm's own professional retention obligations as instructed to us by the Firm, requires that records be kept, we will retain them for the required period even if a deletion request is received, tell you which specific records are being retained and why, and delete them when the requirement lapses.

13. Security Incident Notification

If we discover a security incident affecting personal information, we follow our incident response plan:

  • We notify the affected Firm first, without undue delay, because the Firm is the controller of Firm Client Data and holds the direct relationship with affected Taxpayers. Our notice includes what happened, what data was involved, and what we are doing about it, so the Firm can meet its own notification obligations to its clients and regulators.
  • For incidents affecting Firm Account Data, for which we are the controller, we notify the affected Firm and, where required, affected individuals and regulators directly.
  • We cooperate with the Firm's reasonable requests for information needed for its own legal notifications, including obligations that tax professionals may have to the IRS and state authorities.
  • We notify law enforcement and regulators where required by law.

Timelines for processor-to-controller notification are specified in the Data Processing Addendum.

14. Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, may give you the following rights with respect to personal information for which Delegait is the business:

  • Right to know what personal information we collect, use, and disclose, including the categories of sources and third parties;
  • Right to delete personal information, subject to legal exceptions;
  • Right to correct inaccurate personal information;
  • Right to limit the use of sensitive personal information to purposes permitted by the law;
  • Right to non-discrimination for exercising any of these rights.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined in California law. We have not done so in the preceding 12 months. Because we do not sell or share personal information, there is no "Do Not Sell or Share" opt-out to offer, and we do not process personal information for targeted advertising.

Two scope notes:

  • Some information we handle may fall under the California exemption for information subject to the Gramm-Leach-Bliley Act. Where that exemption applies, these rights may not attach to that information. We do not claim that all information on the Service is exempt, and we evaluate requests individually.
  • For Firm Client Data, the Firm is the business and Delegait is a service provider. If you are a Taxpayer, please direct requests about that data to your Firm; we will assist the Firm in responding as required by our contract and the law.

How to exercise your rights: email info@delegait.biz. We will verify your identity before acting, typically by confirming control of the email address associated with your account and, where needed, additional information proportionate to the sensitivity of the request. You may use an authorized agent, in which case we may require proof of the agent's authority and verification of your identity. We respond within the timeframes required by law, generally 45 days, extendable once by a further 45 days with notice.

15. Rights of Users Outside California

Residents of other states with comprehensive privacy laws may have similar rights of access, correction, and deletion. You may submit requests to info@delegait.biz and we will honor them as required by the law applicable to you, subject to the same controller and processor distinction described above: requests concerning Firm Client Data will be referred to the responsible Firm.

16. Cookies and Similar Technologies

The Service uses cookies and similar technologies for a narrow set of purposes: strictly necessary cookies for session management, authentication, and security, for example keeping you signed in and protecting against request forgery; and functional preferences, for remembering settings within the Service.

We do not use third-party advertising cookies, ad networks, third-party analytics, or cross-site tracking. Because we do not engage in such tracking, browser "Do Not Track" and Global Privacy Control signals do not change how the Service behaves: there is no advertising tracking to opt out of. You can control cookies through your browser settings, but disabling strictly necessary cookies will prevent the Service from functioning.

17. Children

The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information directly from minors. A Firm's records may lawfully contain information about minors, for example dependents listed on a tax return; such information is Firm Client Data controlled by the Firm and processed by us only as its service provider. If you believe a minor has created an account on the Service, contact us at info@delegait.biz and we will delete it.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top of this page. For material changes, we will provide advance notice to Firm account administrators by email or by prominent notice within the Service before the changes take effect, and where a Taxpayer has accepted this policy through the portal, we will ask for acceptance of the updated version. Changes affecting the processing of Firm Client Data are governed by the Data Processing Addendum and will not reduce its protections without the process it specifies.

19. Contact Us

For privacy questions, requests, or complaints, email info@delegait.biz. A postal address is available on request.

If you are a client of a Firm, remember that the fastest path for questions about your tax or financial records is your Firm, which controls that information. We will always support the Firm in answering you.

Version 2026-08-18