Privacy Policy
Last updated: 1 April 2026
TheTaxpert ("we", "our", "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights as a user of our compliance management platform.
1. Information We Collect
We collect the following categories of information when you use TheTaxpert:
- Identity data: Full name, PAN number, Aadhaar (where applicable), date of birth
- Contact data: Email address, mobile number, postal address
- Financial documents: Form 16, Form 26AS, GST returns, bank statements, and other compliance documents you upload
- Transaction data: Payments made for services on the platform
- Usage data: Pages visited, features used, browser type, IP address, and device information
- Communications: Messages exchanged with our team through the platform
2. How We Use Your Information
- To create and manage your platform account
- To deliver the compliance and tax filing services you have requested
- To extract data from uploaded documents for processing (automated + human review)
- To send you service updates, deadline reminders, and important notifications
- To improve platform functionality and user experience
- To comply with applicable laws, regulations, and audit requirements
- To prevent fraud, unauthorized access, and misuse of the platform
3. Legal Basis for Processing
We process your data on the following legal bases under the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian law:
- Consent: Where you have explicitly agreed to data processing
- Contract performance: To fulfill services you have requested
- Legal obligation: Where we are required to process data by law
- Legitimate interest: For platform security, fraud prevention, and service improvement
4. How We Store and Protect Your Data
Your data is stored on secure cloud infrastructure provided by Supabase, hosted within compliant data centers. We implement the following security measures:
- Encryption of data at rest and in transit (TLS 1.2+)
- Row-level security policies to ensure each user only accesses their own data
- Role-based access controls for our team members
- Regular security audits and vulnerability assessments
- Secure file storage with signed URLs for document access
5. Data Sharing
We do not sell your personal data. We share data only in the following limited circumstances:
- TheTaxpert team and staff: Assigned professionals on our platform who process your filings
- Infrastructure providers: Supabase (database and storage), Vercel (hosting)
- Payment processors: Secure payment gateways for processing fees
- Legal requirements: Where disclosure is required by law or regulatory authority
All third-party providers are bound by data processing agreements and are required to protect your data.
6. Data Retention
We retain your data for as long as your account is active and for a period of 7 years thereafter, in line with Indian tax law requirements. Uploaded financial documents are stored permanently as part of your Lifetime Document Vault unless you request deletion. You may request deletion of your account and associated data at any time, subject to legal retention requirements.
7. Your Rights
Under applicable Indian data protection law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data (subject to legal obligations)
- Withdraw consent for non-essential processing
- Raise a grievance with our Data Protection Officer
8. Cookies
We use essential session cookies for authentication and platform functionality. We do not use third-party advertising cookies. You may disable cookies in your browser settings, but this may affect platform functionality.
9. Children's Privacy
Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.
10. Contact Us
For privacy-related queries or to exercise your rights, contact us at:
info@thetaxpert.com
TheTaxpert, India