Scope and contact
Tomas Financial LLC operates the public website, client portal, and related bookkeeping, tax-preparation, reporting, scheduling, support, and billing workflows described in this notice.
Privacy questions and requests can be sent to privacy@tomasfinancial.com. Do not send Social Security numbers, tax documents, bank records, or other sensitive financial information by ordinary email.
Information we collect
The categories collected depend on the feature or service you choose. They may include:
- Contact and account data: name, email, phone number, authentication identifiers, session information, and communication preferences.
- Business and engagement data: business name, entity and industry details, service selections, team relationships, tasks, messages, appointments, and support requests.
- Financial and tax records: connected-account data, bookkeeping records, reports, invoices, expenses, tax-organizer information, tax identifiers, and documents submitted through protected workflows.
- Billing data: subscription, invoice, and payment-status information. Stripe stores and processes payment-card details.
- Technical and usage data: device and browser details, route activity, performance signals, error context, and consent-dependent analytics.
Public contact and fit forms are not designed for financial or tax documents. Submit sensitive records only through the protected portal workflow requested for your engagement.
How information is used
We use information to:
- assess service fit and respond to inquiries;
- authenticate users and control access to companies, records, and team features;
- deliver contracted bookkeeping, tax-preparation, reporting, and support workflows;
- process subscriptions, invoices, and approved connected-account activity;
- send service messages, document requests, reminders, and appointment communications;
- operate, secure, troubleshoot, and improve the application; and
- meet applicable recordkeeping, legal, tax, and dispute requirements.
We do not sell personal data for monetary consideration. We do not use personal data for targeted advertising or automated decisions that produce legal or similarly significant effects.
AI-assisted processing
The AI Policy explains the operating boundaries for these features in one place.
AI Call Assistant
The optional AI Call Assistant supports business-call intake, lead capture, routing, and scheduling handoff. It does not receive or analyze connected bank-account data, bank feeds, tax records, or financial reports, and it does not prepare or advise on bookkeeping or tax work.
Receipt-image extraction
If a user chooses the receipt-scanning feature and submits an image, the image is sent to OpenAI to extract proposed receipt fields. The scanner does not connect to or retrieve information from bank accounts, bank feeds, QuickBooks, tax records, or financial reports. Extracted values remain subject to user or team review before they should be treated as bookkeeping records. Manual expense entry remains available.
Do not use the receipt scanner if you do not want the submitted image processed by OpenAI. The receipt scanner and the AI Call Assistant are separate features.
Service providers
We use service providers to operate the application. Their processing is also governed by their own terms, privacy notices, contracts, and configured retention settings. Key providers include:
- Clerk: authentication, account identity, sessions, and managed identity settings.
- Supabase: application database, authorization controls, and private file storage.
- Stripe: subscription billing, payment methods, and optional Financial Connections.
- Intuit QuickBooks: authorized accounting-data synchronization and supported writeback.
- UploadThing: legacy and supported document-upload storage workflows.
- Vercel: application hosting and consent-dependent analytics and performance tools.
- Sentry: error monitoring, performance traces, and sampled session replay.
- Resend: transactional email delivery.
- Cal.com and connected calendar providers: appointment scheduling and calendar handoff.
- Retell AI: optional call intake, routing, scheduling handoff, and related call records.
- OpenAI: receipt-image extraction when a user submits an image to the receipt scanner.
- Upstash: rate limiting and abuse-prevention controls.
Information may be processed in the United States or other locations where a provider operates. The provider used for a particular workflow depends on the feature and configuration active at that time.
QuickBooks Online connection
A QuickBooks connection is optional and uses Intuit's OAuth authorization flow. Supported synchronization can read company information, accounts, transactions, and reports needed for the connected workflow.
When an authorized administrator explicitly initiates a supported workflow, the application can write approved journal entries, invoices, bills, or expenses back to QuickBooks. The interface and engagement scope determine which actions are available.
Disconnecting removes the local QuickBooks connection record and the application's QuickBooks data cache. Other bookkeeping, report, audit, or engagement records remain subject to their own retention rules. The application also requests revocation from Intuit. If provider revocation cannot be confirmed immediately, the local connection remains removed and provider-side revocation may require follow-up.
Retention and deletion
Retention varies by data type, active engagement, provider, legal obligation, tax-record requirement, backup lifecycle, and dispute or legal-hold need. We do not promise one universal retention period for every record.
The account-deletion workflow is available in Settings under Data & Privacy and uses identity reverification. Active application data is scheduled for deletion within 30 days, subject to required legal, tax-record, backup, and provider retention. Provider cleanup that cannot complete immediately is retained in a retryable workflow rather than being silently abandoned.
A readable account-data export is also available from Data & Privacy settings. The export format and included fields depend on the records available to the authenticated account.
Your choices
Depending on your location and applicable law, you may have rights to access, correct, export, delete, restrict, or object to certain processing. You can also:
- manage profile, security, notification, and communication settings;
- review or end active sessions through the managed identity profile;
- disconnect supported accounting or financial connections;
- reset analytics consent from Data & Privacy settings; and
- request assistance at privacy@tomasfinancial.com.
We may need to verify identity and authority before completing a request. Some records may be retained when required by law, contract, tax-record obligations, security, backups, or dispute preservation.
Visit Data & Privacy settings after signing in to use available self-service controls.
Security
The application uses encrypted network connections, scoped authorization checks, database Row-Level Security where applicable, encrypted storage for selected sensitive identifiers and provider tokens, rate limiting, monitoring, and audit controls.
No internet service can guarantee absolute security. Keep account credentials private, enable available multifactor authentication, review active sessions, and report suspected unauthorized access promptly.
Changes to this notice
We may update this notice when product behavior, providers, legal requirements, or data practices change. The date at the top identifies the current version presented on this site.
Questions or requests can be sent to privacy@tomasfinancial.com.