Privacy Policy

Your data is the foundation of your business.
We treat it that way.

This policy explains exactly what data we collect, how we use it, who sees it, and how you control it. Written in plain language — no legalese necessary.

Home/Privacy Policy
Read-Only Access
We never write to, modify, or delete your data
Never Sold
Your data is never shared with or sold to third parties
Deleted at Completion
All client data purged within 30 days of audit close
Minimum Necessary
We access only the data required for your audit
Last updated March 1, 2025
This policy was reviewed and updated to reflect our current data handling practices. If you have questions about any changes, contact us directly.
01

Who We Are

TaxTrimIQ Strategic Partners ("TaxTrimIQ," "we," "our," or "us") is a sales tax recovery firm that provides audit and recovery services for e-commerce businesses. Our registered address is on file with clients and regulatory bodies upon request.

This Privacy Policy governs how we collect, use, store, and protect information related to: (a) visitors to our website at taxtrimiq.com, and (b) clients who engage us for audit and recovery services. Where these two contexts have different rules, we distinguish them clearly below.

Plain language summary: TaxTrimIQ is a tax recovery business. This policy explains how we handle data from both our website visitors and our audit clients. The rules are different for each, and we're transparent about both.
02

What We Collect

We collect two distinct categories of data: information you provide directly, and information generated during the course of an audit engagement.

A. Website & Contact Information

When you visit our website, submit an inquiry, or request an audit, we may collect:

Name and business email address
Company name, website URL, and general business details you share
Messages or questions submitted through contact forms
Standard web analytics data (pages visited, browser type, referring URL) via cookies — see Section 8

B. Audit Client Data

For clients who proceed with an audit engagement, we access the following data from your Avalara or TaxJar account via read-only API:

Data Type Purpose We Access
Transaction records Core audit analysis — classification review and rate validation Yes
SKU identifiers & product tax codes Classification audit and reclassification recommendations Yes
Jurisdiction & address data Jurisdiction rate validation and boundary verification Yes
Tax amounts remitted Calculating over-remittance and recovery value Yes
Customer names or personal details No
Payment or banking information No
E-commerce platform backend No
We access the minimum data necessary. Our API token requests are scoped to read-only tax transaction data only. We cannot and do not access anything outside this scope.
03

How We Use Your Data

We use the data we collect exclusively for the purposes described below. We do not use your data for advertising, profiling, resale, or any purpose unrelated to delivering your audit.

For website visitors and inquiries:

To respond to your inquiry or audit request
To determine whether your brand is a fit for our services
To improve our website and user experience through aggregate, anonymized analytics

For audit clients:

To conduct your sales tax audit across all five phases described in our engagement agreement
To generate and deliver your savings report
To implement approved corrections in your tax platform
To coordinate amended return filings on your behalf
To provide ongoing monitoring if you engage that service
To fulfill our contractual and legal obligations related to the engagement
We do not use your audit data to train models, benchmark against other clients, or generate aggregate industry reports in any identifiable form. Any internal research we conduct is done on fully anonymized, aggregated data that cannot be traced back to your business.
04

Who Sees Your Data

Your data is not sold, rented, or traded. We do not share it with advertisers, data brokers, or any party with a commercial interest in it. Access is limited to the following:

Internal access

Only the audit personnel specifically assigned to your engagement have access to your client data. Internal access is logged, role-based, and subject to strict confidentiality agreements. No other team members, departments, or systems have access.

Sub-processors and infrastructure

We use a small number of third-party sub-processors to operate our infrastructure. These include cloud hosting providers and data processing tools, all of which are contractually bound to our data protection standards and do not have permission to use your data for any purpose other than providing the underlying infrastructure.

We maintain an up-to-date list of sub-processors and will provide it upon written request.

Legal requirements

We may disclose information if required to do so by law, court order, or valid legal process. We will notify you of any such request to the extent permitted by law, and we will take reasonable steps to contest requests we believe to be overbroad or unjustified.

We will never voluntarily share your audit data with a state tax authority, a competitor, or any third party without your explicit written consent.
05

Data Security

We take data security seriously — both as an ethical obligation and as a practical requirement given the nature of the data we handle.

SOC 2 Type II certified infrastructure. Our audit environment runs on infrastructure that has passed independent SOC 2 Type II security audits, covering security, availability, and confidentiality controls.
Encryption in transit. All data transmitted between your tax platform and our systems is encrypted using TLS 1.3.
Encryption at rest. Data stored within our systems is encrypted using AES-256.
Access controls. All internal data access is role-based and logged. Audit trails are maintained for all data interactions.
Read-only API tokens. Our integration uses scoped, read-only API tokens. We have no technical ability to write to, modify, or delete data in your tax platform.
Incident response. In the event of a data breach affecting your information, we will notify you within 72 hours of becoming aware of the incident, consistent with applicable legal requirements.
06

Retention & Deletion

We retain data only for as long as necessary to fulfill the purpose for which it was collected.

Data Category Retention Period Deletion Method
Audit transaction data 30 days after audit completion Automated secure deletion with written confirmation available
Savings report & findings Duration of engagement + 12 months Deleted upon request or at engagement end + 12 months
Contact & inquiry data 24 months from last contact Deleted upon request or automatically at expiry
Website analytics 13 months (aggregate only) Anonymized — no individual deletion required
Financial records (invoices) 7 years (legal requirement) Retained per applicable tax and accounting law
Deletion confirmation: Upon request, we will provide written confirmation that your audit data has been deleted from our systems. Submit the request to privacy@taxtrimiq.com.
07

Your Rights

Depending on your location and the nature of your relationship with us, you may have the following rights with respect to your data. We honor these rights regardless of whether they are legally mandated in your specific jurisdiction.

Right of access. You may request a summary of what data we hold about you or your business at any time.
Right to correction. If any information we hold about you is inaccurate, you may request that it be corrected.
Right to deletion. You may request that we delete your data. We will honor this request except where retention is required by law (e.g., financial records) or where we need the data to fulfill an active contractual obligation.
Right to revoke access. You may revoke our API access to your tax platform at any time by deleting the API token from your Avalara or TaxJar account settings. This requires no notice to us.
Right to portability. You may request a copy of any data we hold about you in a structured, machine-readable format.
Right to object. You may object to our processing of your data for any purpose beyond fulfilling your audit engagement.

To exercise any of these rights, email privacy@taxtrimiq.com. We will respond within 10 business days.

08

Cookies & Website Analytics

Our website uses a minimal set of cookies to operate correctly and to understand how visitors use the site. We do not use advertising cookies, tracking pixels, or third-party behavioral targeting tools.

Cookie Type Purpose Duration
Essential cookies Required for the website to function. Cannot be disabled. Session
Analytics cookies Aggregate, anonymized page view data to improve the site. No individual identification. 13 months
Preference cookies Remembering form inputs and UI preferences. 30 days

You can disable non-essential cookies through your browser settings at any time. This will not affect your ability to use our website.

We do not use Google Ads, Meta Pixel, LinkedIn Insight Tag, or any other advertising or retargeting cookies on this website.
09

Children

Our services are designed for and directed exclusively at businesses and their authorized representatives. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected information from a minor, we will delete it immediately.

If you believe we have inadvertently collected information from a minor, please contact us at privacy@taxtrimiq.com.

10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:

Update the "Last Updated" date at the top of this page
Email active clients to notify them of the changes
Where required by law, obtain fresh consent before processing continues under the new terms

Continued use of our services after a policy update constitutes your acceptance of the revised policy. If you disagree with any changes, you may terminate your engagement and request deletion of your data by contacting us.

11

Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or our data handling practices, please reach out. We take every inquiry seriously and respond within one business day.

Privacy Inquiries
Data access, deletion requests, policy questions
General Contact
All other inquiries and audit requests
Response commitment: We respond to all privacy-related inquiries within one business day. For deletion requests, we confirm completion within 5 business days of processing.
Ready to start?

Your data stays yours.
Your savings come back to you.

Zero upfront cost. Read-only access. Data deleted at close. No surprises.