Privacy policy
Last updated August 18, 2026
This policy explains what Brightline Tax LLC (“Brightline”, “we”, “us”) collects when a firm uses brightline.tax, why we collect it, who we share it with, and what we do not do with it. It covers our public marketing pages and the signed-in application.
Who we are and how to reach us
Brightline Tax LLC is a Connecticut limited liability company. Privacy questions, access and deletion requests go to privacy@brightline.tax; general support is support@brightline.tax.
Two kinds of data, treated differently
Account data is about the people at your firm who sign in — we are the controller of it. Customer Data is what your firm puts into the product: client records, compensation studies, duty allocations and saved research. Your firm controls that; we process it on your instructions to provide the service, and for no other purpose.
What we collect
Account data — name, email address, job title, firm role, and authentication records including two-factor enrolment status. Customer Data — whatever your firm enters or uploads, including client names and contact details, entity and compensation information, and the text of research questions and answers. Billing data — plan, subscription status and billing contact. Card details go directly to Stripe and are never stored by us. Operational data — sign-in times, IP address, browser and device information, request logs and error reports, used to run and secure the service. Marketing-page data — see Advertising below.
How we use it
To provide, operate, secure and support the service; to authenticate users and prevent abuse; to process payments and manage subscriptions; to send transactional messages such as invitations and acknowledgment links; to diagnose errors and improve reliability; to enforce our terms; and to comply with law. We may produce aggregated or de-identified statistics that do not identify you, your firm or any client.
What we do not do
We do not sell Customer Data. We do not use Customer Data to train artificial intelligence models, and our AI processor is contractually prohibited from training on it. We do not share Customer Data between firms. Every table in our database is scoped to a single firm and enforced by row-level security. We do not use Customer Data for advertising or use it to build advertising audiences.
Wage data
Compensation figures are derived from the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics survey — public data loaded into Brightline in advance. Pricing a duty sends no request to any third party carrying your client’s details.
Service providers we use
We share data with the processors below, each of which receives only what its function requires and is bound to use it solely to provide services to us:
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication and file storage | All firm and account data |
| Vercel | Application hosting and delivery | Request and log data |
| Anthropic | AI processing for research answers and duty analysis | The text of what you submit for analysis |
| Stripe | Payment processing and subscription billing | Billing contact and payment details |
| Mailgun | Transactional email (invitations, acknowledgment links) | Recipient name and email address |
| Sentry | Error monitoring | Diagnostic and error data |
| Meta Platforms | Advertising measurement on our public marketing pages | Page-view events and identifiers — see the Advertising section |
We may also disclose data where required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of assets — in which case this policy continues to apply until replaced.
Advertising on our marketing pages
Our public marketing pages include the Meta pixel, which sends page-view events and online identifiers such as cookie identifiers and IP address to Meta Platforms so we can measure our advertising and reach similar audiences. Under some state privacy laws this is treated as “targeted advertising” and may be treated as a “sale” or “sharing” of personal data.
The pixel runs on the public marketing pages only. Customer Data is never sent to Meta. You can opt out by emailing privacy@brightline.tax, by using your browser’s tracking controls or a Global Privacy Control signal, or through the ad preferences Meta provides.
Cookies
We use cookies that are strictly necessary to sign you in and keep your session secure, and — on the marketing pages only — the advertising and analytics cookies described above. Blocking necessary cookies will prevent the application from working.
Security
Data is encrypted in transit and at rest by our infrastructure providers. Access is restricted to what is needed to operate the service, every table is scoped to a single firm by row-level security, and two-factor authentication is available and can be required firm-wide. No system is perfectly secure, and we cannot guarantee absolute security.
Retention and deletion
Customer Data is retained while the account is active and for 90 days after cancellation, after which it is deleted or de-identified. Backups age out on their own cycle within a further 30 days. Billing records are kept as long as tax and accounting law requires. A firm may request export or deletion at any time by writing to privacy@brightline.tax; we will act within 45 days, or tell you why we cannot.
Your rights
Depending on where you live you may have rights to access, correct, delete or obtain a portable copy of personal data about you, to opt out of targeted advertising, and to appeal a refusal. Residents of Connecticut have these rights under the Connecticut Data Privacy Act; residents of California, Colorado, Virginia and other states have comparable rights under their own laws. We will not discriminate against you for exercising them.
Requests about Customer Data should go to the firm that entered it — your firm is the controller of its own client records, and we will refer you to them or act on their instruction. To exercise any right, or to appeal, email privacy@brightline.tax. We may need to verify your identity before acting.
Children
The service is for accounting professionals and is not directed to anyone under 18. We do not knowingly collect personal data from children.
Where data is processed
We operate in the United States and our providers may process data in the United States and elsewhere. If you access the service from outside the United States, you understand that your data will be processed in the United States, where data protection law may differ from your own.
Changes to this policy
We may update this policy. Material changes will be notified by email or in-product before they take effect, and the “Last updated” date above will change.