Privacy Policy
Effective Date: January 1, 2024 | Last Updated: September 4, 2026 (policy audited against the code)
At Take Flight Business ("we," "our," or "us"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website takeflightbs.com or use our services. By accessing or using our website, you agree to this Privacy Policy.
If you have any questions or concerns about this Privacy Policy, please contact us using the information provided in Section 10 below.
1. Information We Collect
A. Personal Information
We may collect personal information that you voluntarily provide to us when you:
- Complete a contact form or request a consultation
- Ask to be contacted, or reply to messages we send about your account
- Use our tax savings calculator or other interactive tools
- Engage with our services
This personal information may include:
- Name, email address, phone number, and company information
- Billing and payment information when you engage us for services
- Business details provided through our tools (e.g., revenue, entity type)
B. Non-Personal Information
We may collect non-personal information automatically when you visit our website. This information may include:
- IP address, browser type, device type, and operating system
- Information about how you interact with our website (e.g., pages visited, time spent)
We collect this information using cookies, web beacons, and similar technologies. See Section 4 for more details on our use of cookies.
2. How We Use Your Information
We may use the information we collect for the following purposes:
- To provide services: Process your requests and deliver services you have requested
- To communicate: Respond to inquiries, send service-related updates, and provide information about our services
- To improve our website and services: Analyze usage trends to enhance user experience
- To keep you informed about your own account: Send reminders about outstanding items and updates about services you have engaged. We do not currently send newsletters or promotional mail; if that changes, it will be opt-in.
- To comply with legal obligations: Fulfill any legal or regulatory requirements
3. Client Portal — Additional Data Practices
If you create an account in our secure client portal at /portal, additional information is collected, used, and shared as described below. As a provider of bookkeeping and accounting services that handles your financial data, we treat ourselves as a "financial institution" under the Gramm-Leach-Bliley Act (GLBA) and follow the safeguards outlined in IRS Publication 4557 and the FTC Safeguards Rule. Tax returns are prepared by a licensed preparer we coordinate with.
A. Account & profile data
- Email address, name, password (stored hashed by Firebase Authentication), MFA factor (phone number if you enroll a second factor)
- Business information you provide during onboarding (entity type, service interest, revenue range, business address)
B. Tax & financial data (handled by integrated providers)
- TaxDome. When linked, your tax documents, signed forms, and organizer responses live in TaxDome. We do not store these in our own database — we display references to items in your TaxDome workspace and provide a single-sign-on link.
- QuickBooks Online. If you choose to connect QuickBooks, we receive OAuth tokens that let us read your Profit & Loss, Balance Sheet and chart of accounts, and write customers, vendors, invoices, bills and payments from this portal into your QuickBooks company. Where a record differs, QuickBooks is treated as the winner and we stop rather than overwrite. Your QuickBooks password never reaches our servers; the tokens are stored in our database, which is encrypted at rest by our cloud provider, and you can revoke them at any time from your portal.
- Stripe. Payment card numbers, ACH details, and payment authorization are collected by Stripe's hosted checkout. Take Flight never sees or stores card data — our PCI scope is the lowest tier (SAQ-A). We retain payment metadata (amount, date, engagement reference) for accounting and tax purposes.
- E-signature. Engagement letters and scope changes are agreed by click-to-accept inside this portal (see D below). We do not currently use a third-party e-signature provider; if a document ever requires identity-verified signing, we will name the provider before using it.
- Plaid (optional, when used). If you connect a bank account, Plaid's Link UI collects your bank credentials directly — they never reach our servers. We store an access token, the account name, type and last four digits, current and available balances, and the transaction records Plaid returns. The token is stored in our database, which is encrypted at rest by our cloud provider.
- AI model provider (optional, only with your consent). If you switch on AI-assisted transaction categorization under Profile › Privacy & data, the bank description, merchant name, amount, direction, date and the bank's own category guess for each uncategorized transaction are sent to an AI model provider so a model can propose a bookkeeping category. Your name, business name, account numbers, balances and documents are never sent. This is off by default and off for every client who has not consented. See Section 3.E.
C. In-portal messages and attachments
Messages you send through the portal, including any files you attach, are stored in our Firestore + Storage infrastructure with strict access controls — only you and our staff can read them. Messages are encrypted in transit and at rest. Retention is 7 years post-engagement-termination to match IRS records-retention guidance.
D. Engagement & consent records
When you accept an engagement letter via click-to-accept, we record: the consent text shown, the timestamp, your IP address, and your browser user-agent string. This serves the "intent to be bound" requirement under E-SIGN and UETA for non-IRS digital signatures.
E. AI-assisted categorization consent
AI-assisted transaction categorization is off by default. It is used on your transactions only after you switch it on under Profile › Privacy & data in the portal, where the exact wording you agree to is shown in full. When you do, we record the consent text shown, the timestamp, your IP address, and your browser user-agent string, and our servers refuse to send any of your transactions to the AI model provider unless a current consent is on file. A proposal from the model is never recorded in your books until a member of our staff has reviewed it. You can withdraw consent at any time in the same place; withdrawal takes effect immediately for any further transactions.
F. Audit logs
For compliance with IRS Publication 4557 and the FTC Safeguards Rule, we log security-relevant events including sign-in attempts, MFA enrollments, role changes, document accesses, and webhook events from integrated providers. Audit logs are retained for 7 years and are accessible only to designated admins.
G. What we do NOT do in the portal
- We do not sell or share any portal data with advertisers, data brokers, or marketing partners.
- We do not use AI services on identifiable customer data without your explicit consent.
- We do not retain tax documents past the IRS 7-year retention window without your written instruction.
4. Sharing Your Information
We do not sell or rent your personal information to third parties. However, we may share your information in the following situations:
- With service providers: We may share information with trusted third-party service providers who assist us in delivering our services (e.g., payment processors, IT service providers).
- For legal purposes: We may disclose your information if required by law, regulation, or legal process, or if we believe disclosure is necessary to protect our rights or the safety of others.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
5. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small data files stored on your device that help us understand how you use our site.
Types of cookies we use:
- Essential cookies: Required for basic site functionality, such as remembering your cookie choice and keeping you signed in to the client portal.
- Analytics cookies: Help us understand how visitors interact with our website (Google Analytics and Firebase Analytics). These are set unless you decline on the cookie banner; declining stops them entirely.
We do not use advertising or marketing cookies. We run no ad pixels, remarketing tags, or cross-site advertising trackers.
If you choose Decline on our cookie banner, we do not load analytics at all — no Google Analytics or Firebase Analytics data is collected from your visit. You can change your mind by clearing this site's data in your browser, which brings the banner back. You can also control cookies through your browser preferences.
6. Data Security
We take reasonable measures to protect your personal information from unauthorized access, use, or disclosure. Our security measures include:
- SSL/TLS encryption for data transmitted through our website
- Secure cloud infrastructure with access controls
- Regular security assessments
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access and correction: You have the right to access and correct the personal information we hold about you.
- Data deletion: You may request that we delete your personal information, subject to legal obligations.
- Opt-out: You may opt out of receiving marketing communications at any time by using the unsubscribe link in our emails or contacting us directly.
- Do Not Track: Our website does not currently respond to "Do Not Track" browser signals.
8. Third-Party Links
Our website may contain links to third-party websites or services that are not operated by us (e.g., QuickBooks for accounting software, or a scheduling tool if we link to one). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
9. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. If we make significant changes, we will post a notice on our website and update the "Effective Date" above. Your continued use of our website after any changes indicates your acceptance of the revised policy.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Take Flight Business
Use our contact form and mark your message "Privacy" so it reaches the right person.
See also: SMS Terms & Conditions
