Privacy Policy
1. Who we are and what this covers
Finaxel operates Finaxel. This policy explains what personal information we handle on the website and in the application, why, and who we share it with.
We decide how your account data is used (we are the “controller” or “business”). The data you enter about your customers, vendors and employees we process on your behalf, as a service provider (“processor”): see section 10.
2. Information we collect
What you give us:
- Account: name, email, password (stored only as a bcrypt hash), optional photo, two-step verification settings.
- Business: name, address, phone, email and tax profile (EIN, entity type, state employer IDs).
- Subscription: plan, dates and Stripe customer identifiers. Card details go to Stripe; Finaxel never sees or stores them.
- Messages you send to support.
What you enter about other people (“Customer Data”): customers and vendors (including vendors’ taxpayer identification numbers for Form 1099), employees (name, email, home address, work state, pay, W-4 elections and only the last 4 digits of the SSN), invoices, bills, transactions and journal entries.
From services you connect: from Plaid, your accounts’ name, type and last digits, balances and transactions; from Stripe, your payment account status and the payments, payouts and fees on your invoices; from Google, if you sign in with Google, your name, email, profile photo and account identifier.
Generated when you use the Service: IP address, browser and operating system, sign-in times, security events, trusted devices, and server and audit logs. Cookies and browser storage are explained in the Cookie Policy. We use no analytics or advertising tools.
3. How we use it
- To provide the Service: bookkeeping, invoices, payments, reconciliation, payroll estimates and tax worksheets.
- To process your subscription and your customers’ payments.
- To send service emails: verification codes, sign-in alerts, receipts, renewal reminders and, on your behalf, invoices and reminders to your customers.
- Security: preventing fraud and abuse, limiting sign-in attempts, two-step verification, inactivity sign-out and audit logs.
- Support, legal compliance and troubleshooting.
We make no automated decisions with legal effects on you. We do not use your financial data for advertising or to train artificial-intelligence models.
5. Plaid
Finaxel uses Plaid Inc. to gather your data from financial institutions. By connecting a bank, you grant Finaxel and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from your financial institution, and you agree to Plaid transferring, storing and processing it in accordance with the Plaid End User Privacy Policy. We store the access token Plaid gives us encrypted; we never receive your bank password.
7. How long we keep it
- For as long as your account is active.
- If you close your account or ask us to delete it, we delete or de-identify your data within 30 days, except what the law requires us to keep (for example, billing records, up to 7 years) and the security logs we need.
- Backups are overwritten on a cycle of about five weeks.
- You must keep your own accounting, tax and payroll records for the periods the law requires (the IRS requires at least 4 years for employment taxes): export them before closing your account.
8. Security
- Encrypted connections over HTTPS.
- Passwords stored with bcrypt; bank tokens and email credentials encrypted with AES-256-GCM.
- Optional two-step verification, sign-in attempt limits, sign-in alerts for administrators and sign-out after 3 hours of inactivity.
- Isolation between organizations, per-module permissions and an audit log.
- Card data never passes through our servers (Stripe processes it).
No system is completely secure. If a breach affecting you occurs, we will notify you as the law requires.
9. Your rights
Depending on where you live (for example California, Virginia, Colorado, Connecticut, Texas or Oregon), you may have the right to: know what data we hold and get a copy; correct it; delete it; receive it in a portable format; opt out of its sale, “sharing” or targeted advertising (we do none of the three); and limit the use of sensitive information (we only use it to provide the Service). We will not discriminate against you for exercising them.
- How: email contactfinaxel@gmail.com. We verify your identity through your account email. An authorized agent may act for you with signed permission.
- Timing: we respond within 45 days (extendable by another 45 with notice).
- Appeals: if we deny your request, reply with the subject “Appeal” and we will review it within 45 days; if we still disagree, you may contact your state attorney general.
- California (“Shine the Light”): we do not share personal information with third parties for their own direct marketing.
10. Data about your customers, vendors and employees
We process this data on your behalf and only to provide the Service to you. If one of those people wants to exercise their rights, they should contact you; we will help you respond. You are responsible for informing them and having a legal basis to enter their data.
11. Children
Finaxel is a business service and is not directed at anyone under 18. We do not knowingly collect data from children under 13; if we learn we have, we delete it.
12. Users outside the US
The Service is intended for United States businesses. Data may be processed in the United States and in other countries where our providers operate.
13. Changes to this policy
We will post any change on this page with its new date. If a change is material, we will notify you by email or in the app before it takes effect.
14. Contact
- Operator: Finaxel
- Email: contactfinaxel@gmail.com
- Website: http://localhost:3000