Legal

Privacy Policy

This Privacy Policy explains how Untangly, Inc. (“Untangly,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use our practice management platform, including the company portal for accounting and tax firms and the client portal for their clients.

Last updated: September 5, 2026

1. Who we are

Untangly is a multi-tenant SaaS practice management platform for accounting and tax firms. We provide:

  • Company Portal — used by firm owners, admins, and staff to manage clients, projects, documents, communications, scheduling, billing, and settings.
  • Client Portal — used by a firm’s individual and business clients to view work, upload documents, chat with the firm, sign documents, book meetings, and manage their profile.

Contact for privacy matters: privacy@untangly.ai. General contact: hello@untangly.ai. Security: security@untangly.ai.

2. Roles and responsibilities

For data that firms store about their clients and practice (client records, documents, messages, invoices, and similar content), the firm is the data controller (or equivalent under applicable law). Untangly acts as a data processor (or service provider) processing that data on the firm’s instructions to provide the Service.

For account, billing, support, and marketing data we collect directly about firm users and website visitors, Untangly is the controller.

Client portal users interact with Untangly because their firm invited them. Their firm’s own privacy notice and engagement terms also apply to how the firm uses their information.

3. Information we collect

3.1 Account and profile information

  • Firm users (company portal): name, email address, password or authentication credentials, role (owner, admin, member), permissions, organization affiliation, profile photo, and preferences.
  • Client users (client portal): name, email address, authentication credentials, profile photo, contact details, and other profile fields their firm asks them to maintain.
  • Organization data: firm name, branding (logo, colors), subdomain, optional custom domain, business email configuration, and subscription/billing details.

3.2 Client and practice content (Customer Data)

Firms and their users may upload or create content in Untangly, which may include personal and sensitive information about individuals and businesses, such as:

  • Client identity and contact details (including for person and business clients)
  • Tax identifiers and similar government or regulatory identifiers that a firm chooses to store
  • Addresses, notes, relationships, and status information
  • Projects, tasks, deadlines, assignments, and activity logs
  • Documents, file requirements, versions, review status, and eSignature records
  • Messages, email threads linked to clients or projects, and chat attachments
  • Meeting and booking details, calendar sync metadata, and RSVP status
  • Service entries, invoices, payment status, and related billing records

We process Customer Data only to provide, secure, support, and improve the Service as described in this Policy and our agreements with the firm.

3.3 Communications and support

If you contact us (for example at hello@untangly.ai or security@untangly.ai), we collect the content of your message, contact details, and related metadata needed to respond.

3.4 Payment information

Subscription payments and client invoice payments that run through Untangly are processed by Stripe. Card and bank payment details are handled by Stripe and are not stored on Untangly servers. We receive limited billing metadata (for example plan, status, amounts, and invoice references) needed to operate subscriptions and payment features.

3.5 Integrations you connect

With your authorization, we may access data from third-party services you connect, including:

  • Google (Gmail, Google Calendar, Google Meet, and related APIs): email messages, threads, labels/read state as needed for inbox features, calendar events, and meeting metadata, solely to provide the connected features you enable.
  • Microsoft (Outlook / Microsoft 365): email and calendar data needed for connected inbox and scheduling features.
  • Other providers you choose to connect for video meetings, calendars, or accounting tools, as described in the product at connection time.

You can disconnect integrations in product settings. Disconnecting stops new access; previously synced content already stored in Untangly remains subject to the firm’s retention and deletion choices unless otherwise deleted.

3.6 Usage, device, and technical data

  • Log data such as IP address, browser type, device information, timestamps, pages or screens viewed, and diagnostic events
  • Cookies and similar technologies on our marketing site and application (see Section 8)
  • Security and fraud-prevention signals (for example failed sign-in attempts)

3.7 Marketing site visitors

On untangly.com we may collect information you submit (demo requests, newsletter signup, contact forms) and standard analytics/technical data about site visits.

4. How we use information

We use information to:

  • Provide, operate, maintain, and improve the company portal, client portal, and related features
  • Authenticate users, enforce permissions, and protect accounts
  • Sync and display connected email, calendar, and related integration data as authorized
  • Send transactional messages (invitations, password resets, OTPs, booking confirmations, product notices)
  • Process subscriptions and facilitate client payments via Stripe
  • Provide customer support, onboarding, and migration assistance
  • Monitor reliability, prevent abuse, detect security incidents, and comply with law
  • Send optional product updates or marketing communications where permitted (you may unsubscribe)
  • Create aggregated or de-identified insights that do not identify you or your clients

We do not sell Customer Data. We do not use Customer Data to train generalized AI/ML models for third parties. We do not use Gmail or Google user data for advertising.

5. Google API services and Limited Use

Untangly’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, when you connect Google services:

  • We access Google user data only to provide and improve user-facing features that are prominent in the Untangly interface (for example unified inbox, client/project linking of email, and calendar scheduling sync).
  • We do not transfer Google user data to third parties except as necessary to provide or improve those features, for security, to comply with law, or with your consent, and subject to Google’s Limited Use rules.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans to read Google user data unless you give us permission for support, it is necessary for security/compliance, or we are required by law — and then only under appropriate controls.
  • We store Google-derived data with encryption in transit and at rest, and with access controls consistent with our security practices described on our Security page and in this Policy.

6. How we share information

We may share information with:

  • Within your organization: firm staff see Customer Data according to roles and permissions configured by the firm. Client portal users see only data scoped to their client relationship.
  • Service providers (subprocessors): hosting, email delivery, analytics, error monitoring, payment processing (Stripe), and similar vendors who process data on our instructions under confidentiality and security obligations. A current subprocessor list is available on request at security@untangly.ai.
  • Integration partners you enable: Google, Microsoft, and other providers you connect, under their terms and your authorization.
  • Legal and safety: when required by law, legal process, or to protect the rights, safety, and security of Untangly, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.

We do not sell personal information as that term is commonly understood under US state privacy laws.

7. Data location, security, and retention

7.1 Location

We host firm data with regional intent aligned to our product commitments: US firm data is hosted in the United States; Canadian firm data is hosted in Canada, where offered. Support, subprocessors, and backups may involve limited processing consistent with providing the Service and applicable law.

7.2 Security

We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, optional multi-factor authentication for firm users, audit logging, and backup/recovery practices. No method of transmission or storage is 100% secure; we work continuously to reduce risk. See Security for a plain-language overview.

7.3 Retention

We retain Customer Data for as long as the firm’s subscription and account require, and thereafter for a limited period to allow export, resolve disputes, enforce agreements, and meet legal obligations. Deleted items may be recoverable by firm admins for a limited window (for example approximately 30 days) before permanent deletion from active systems, subject to backup cycles.

Account and billing records are retained as needed for finance, tax, and compliance. Marketing preferences are retained until you unsubscribe or we no longer need them.

8. Cookies and similar technologies

We use cookies and similar technologies that are necessary to run the Service (session, authentication, security) and, on the marketing site, may use analytics cookies to understand traffic and improve content. You can control cookies through your browser settings; disabling necessary cookies may prevent sign-in or core features from working.

9. Your choices and rights

Depending on your location and role, you may have rights to:

  • Access, correct, or update personal information
  • Export data (firms may export Customer Data in usable formats)
  • Request deletion, subject to legal and operational exceptions
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based (for example disconnecting an integration or unsubscribing from marketing)
  • Appeal a decision, where required by applicable law

Firm users and firms: many profile updates can be made in-product. For broader access, export, or deletion of Customer Data, contact us or manage deletion through organization admin tools. Because firms control Customer Data, client-level requests about client records are often handled by the firm; we will assist the firm as required.

Client portal users: update your profile in the portal where available, or contact your firm. You may also contact privacy@untangly.ai; we may need to involve your firm to fulfill requests about Customer Data.

Residents of the European Economic Area, United Kingdom, Canada (including under PIPEDA and applicable provincial laws), California, and other jurisdictions may have additional rights. We will not discriminate against you for exercising privacy rights.

10. Children’s privacy

Untangly is built for professional accounting and tax practices and their adult clients. The Service is not directed to children under 16 (or the higher age required in your jurisdiction), and we do not knowingly collect personal information from children for Untangly accounts. If you believe a child has provided us personal information inappropriately, contact privacy@untangly.ai.

11. International transfers

If you access the Service from outside the country where your data is hosted, your information may be processed in the United States, Canada, or other locations where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms (such as standard contractual clauses or equivalent safeguards).

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we will provide additional notice as appropriate (for example email or in-product notice). Continued use of the Service after the effective date constitutes acceptance of the updated Policy, except where applicable law requires otherwise.

13. Contact us

Untangly, Inc.
169 Enterprise Boulevard, Suite 300
Markham, ON L6G 0E7
Canada
Privacy inquiries: privacy@untangly.ai
Security: security@untangly.ai
General: hello@untangly.ai

Related documents: Terms of Service · Security