Legal
Data Security Notice
Your tax documents are among the most sensitive records you own. Here is how we protect them.
Encryption
All traffic to RainTax+ is served over HTTPS/TLS. Documents and account records are encrypted at rest by our infrastructure provider.
Private document storage
Uploaded documents are stored in a private storage bucket that is never publicly readable. Files are served only through short-lived, expiring signed links generated for your authenticated session.
Access controls
Row-level database security restricts every record to the client who owns it and to the specific staff members whose role and case assignment require access. Clients can never see another client's records, and preparers can only see cases assigned to them.
Staff roles are stored separately from user profiles and can only be granted by an administrator. Users cannot change their own role.
Monitoring and audit trail
Sign-in attempts, document access, assignments, quote and payment changes, signatures, filing actions, and role changes are recorded in an internal audit log retained for review.
Email safety
Notification emails identify only the event and your client ID. Social Security numbers, return figures, and document contents are never emailed. Case-specific communication happens inside the secure portal.
Your responsibilities
Use a unique password, keep your email account secure, and sign out on shared devices. Never send tax documents by unsecured email or text message.
Template notice
This notice is a plain-language summary and is provided as a template. It should be reviewed by qualified legal counsel before production use.
This page is provided for general information about how RainTax+ operates and is not legal or tax advice.
