Privacy Policy
Last updated: April 20, 2025
1. Introduction
Balance Beam Bookkeeping & Tax (“Balance Beam,” “we,” “our,” or “us”) is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website at balancebeamtax.com, use our client portal at portal.balancebeamtax.com, or engage with our bookkeeping, tax preparation, and IRS resolution services.
By using our website or services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our services.
2. Information We Collect
Information you provide directly:
- Name, email address, phone number, and mailing address
- Business name, entity type, and tax identification information
- Financial records, bank statements, and tax documents you upload to the portal
- Social Security Number (last 4 digits only in plain text; full SSN stored only in AES-256 encrypted form if required for tax filing)
- Payment information processed through Stripe (we do not store full card numbers)
- Electronic signatures and IP addresses captured during service agreement signing
- Messages and communications sent through the portal or contact form
Information collected automatically:
- IP address, browser type, and operating system
- Pages visited, time spent on pages, and referring URLs
- Device identifiers and session data
- Cookies and similar tracking technologies (see Section 7)
Information from third parties:
- Contact and lead information from GoHighLevel CRM when you submit a form or inquiry
- Scheduling data from OnceHub when you book a consultation
- Payment confirmation data from Stripe
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve our bookkeeping, tax preparation, and IRS resolution services
- Create and manage your client portal account
- Prepare and file tax returns and financial reports on your behalf
- Process payments and send invoices
- Send service-related communications, task reminders, and document requests
- Respond to your inquiries and provide customer support
- Comply with legal obligations, including IRS regulations and California state tax law
- Detect and prevent fraud or unauthorized access
- Send marketing communications (you may opt out at any time)
4. How We Share Your Information
We do not sell your personal information. We may share your information with:
- Service providers who assist in operating our business (Stripe for payments, Resend for email delivery, MongoDB Atlas for database hosting, Pinecone for AI knowledge base, Vercel for website hosting)
- GoHighLevel CRM for lead management and client communication workflows
- Anthropic and OpenAI for AI-assisted responses in the client portal (no personally identifiable financial data is sent to AI providers)
- The IRS, state tax agencies, and other government bodies as required to perform your tax services or comply with legal obligations
- Professional advisors (attorneys, accountants) under confidentiality agreements
- Law enforcement or regulatory authorities when required by law or to protect our rights
All third-party service providers are contractually required to protect your information and may only use it to perform services on our behalf.
5. Data Security
We implement industry-standard security measures to protect your information, including:
- TLS/HTTPS encryption for all data in transit
- AES-256 encryption for sensitive financial identifiers stored at rest
- Access controls limiting data access to authorized staff only
- Secure cloud infrastructure (MongoDB Atlas, Vercel) with regular security updates
- OTP-based authentication for staff portal access
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
6. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Tax records and financial documents are retained for a minimum of seven (7) years in accordance with IRS recordkeeping requirements. You may request deletion of non-essential data at any time by contacting us (see Section 10).
Client records are never permanently deleted from our systems — inactive accounts are flagged as inactive while the underlying record is preserved for legal and audit purposes.
7. Cookies and Tracking
Our website uses cookies and similar technologies to enhance your experience. These include:
- Essential cookies required for portal authentication and session management
- Analytics cookies to understand how visitors use our site (aggregated, non-identifiable data)
You can control cookie settings through your browser. Disabling essential cookies may prevent you from accessing the client portal.
8. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect and how it is used
- Right to request deletion of your personal information (subject to legal retention requirements)
- Right to opt out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at dave.rios@balancebeamtax.com. We will respond within 45 days.
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will delete it.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes your acceptance of the updated policy.