Privacy Policy
1. What we collect
Account data. When you sign in, we (via our database provider, Supabase) store your email address, account status, and subscription tier. If you pay for a plan, our payment processor, Stripe, holds your billing details (card, name, billing address) — we never see or store your full card number.
Your ledger. The bets, sessions, W-2G entries, and tax-liability figures you enter or import are processed entirely in your browser and saved only in that browser's local storage. This data is never sent to, or stored on, our servers. Clearing your browser data, using a different browser, or switching devices means that data is gone unless you've exported a backup yourself.
Support chat messages. If you use the chat assistant in the corner of the page, the text you send (and the assistant's replies) is sent to OpenAI's API to generate a response. A chat message is, by definition, uploaded so it can get an answer. Your ledger data is never included in that request.
Email auto-sync (beta). If you choose to use this feature, you forward bet-confirmation emails to a personal address tied to your account. That email — its subject, sender, and body — is received by our inbound-email provider (Parseur) and briefly stored on our server so our automated parser can pull out a candidate date, amount, and book/platform for you to review. It stays there only until you either add it to your ledger (at which point the parsed fields are copied into your browser's local storage, same as a CSV import, and the server copy is deleted) or dismiss it (deleted immediately, nothing added). We don't read these emails ourselves, don't use them for anything besides showing them back to you for review, and don't retain them past that review step. This is the one place your betting activity itself — not just account or chat data — touches a server; it only happens if you choose to forward something.
Email check-ins & CPA share link (opt-in, Pro). These two features are off by default. If you turn either one on, the app sends our server the handful of numbers it already computed for you in your browser — your estimated taxable gambling income, and the estimated federal, state, and combined tax added by it — along with your filing status, state, and tax year for context. Your bet-by-bet ledger is never part of that request; these features have no access to it at all. We use the synced number(s) only to send the check-in email(s) you asked for (via Resend) and/or to show a read-only summary page to whoever holds your share link. Turning both features off deletes the synced numbers from our server immediately, not just the emails/link.
Usage and technical data. Like most web services, our hosting provider (Netlify) and payment processor (Stripe) automatically log standard technical data such as IP address, browser type, and request timestamps for security, fraud prevention, and reliability purposes.
2. How we use it
- To create and maintain your account, and to determine which plan features to unlock.
- To process payments and manage subscriptions, through Stripe.
- To respond to support chat questions, through OpenAI's API.
- To keep the Service secure and working reliably.
- To email you about your account — sign-in links, billing receipts and issues, and material changes to the Service. We don't send marketing email unless you ask us to.
3. Who we share it with
We don't sell your personal data. We share the minimum necessary with the vendors that run the Service on our behalf:
- Supabase — authentication and the account/subscription-status database.
- Stripe — payment processing and subscription billing.
- OpenAI — generating support chat replies (only the chat text you send, never your ledger).
- Parseur — receiving confirmation emails you choose to forward for email auto-sync (parsing itself is done by our own code, not Parseur's).
- Resend — sending priority-support and (if you opt in) email check-in messages on our behalf.
- Netlify — hosting the site and its backend functions.
We may also disclose information if required by law, or to protect the rights, safety, or property of SBCG Tax Experts or our users.
4. Data retention
We keep account data for as long as your account is active, plus a reasonable period afterward for legal, tax, and dispute-resolution purposes (billing records in particular are retained as required by Stripe and applicable law). Your ledger data isn't ours to retain — it lives in your browser and is deleted whenever you clear it.
5. Your choices and rights
- Access or delete your account data: email support@sbcgtaxexperts.com and we'll process the request, including deleting your account record and canceling any active subscription.
- Delete your ledger: use the "Clear all" button in the app, or clear your browser's local storage — no need to contact us, since we never had a copy.
- Delete a pending synced email: click "Dismiss" on it in the Email auto-sync panel — it's removed from our server immediately, without being added to your ledger.
- Delete a synced tax estimate: turn off both email check-ins and the CPA share link in the app — the synced numbers are deleted from our server right away, and any existing share link stops working immediately.
- Cancel billing: use "Manage billing" in the app to cancel or update your subscription directly through Stripe.
Depending on where you live, you may have additional rights under laws like the GDPR or state privacy laws (e.g., CCPA) — contact us and we'll do our best to accommodate applicable requests.
6. Cookies and local storage
We use essential cookies/local storage for signing in (via Supabase Auth) and for saving your ledger locally. We don't use third-party advertising or tracking cookies.
7. Children's privacy
The Service is not directed to, and we don't knowingly collect data from, anyone under 18.
8. Changes to this policy
We may update this policy from time to time; the "last updated" date above reflects the current version.
9. Contact
Questions about this policy or your data: support@sbcgtaxexperts.com.