Skip to content

GoRefer Trust Center

Privacy Policy

Updated September 2026

GoRefer, Inc. ("GoRefer", "we", "us") is committed to protecting the personal data of our customers, their clients, and all users of the platform. This policy explains what we collect, why, how we protect it, and your rights.

GDPR rights & policies
Privacy rights policy
PII Encrypted

What Data We Collect & Why

Updated September 2026

We collect the minimum data needed to provide the service. All data processing has an identified lawful basis under GDPR Article 6. Supported sensitive intake fields use AES-256-GCM. Documents and other personal data are handled according to the feature that uses them; storage encryption and provider terms are covered on the Security and Sub-processors pages.

Data CategoryExamplesLawful BasisRetention Period
Account & IdentityName, email, phone number, profile photoContractAccount and legal-retention policy
Tax Professional DataPTIN, EFIN, firm name, specializationsContract / Legitimate InterestLife of firm account
Client Personal DataName, email, tax year infoContractPer retention schedule
PII (sensitive)SSN, EIN, bank account, driving licenseExplicit Consent / Legal ObligationPer retention schedule (encrypted at rest)
Usage & AnalyticsPage views, feature usage, session durationLegitimate Interest24 months rolling
CommunicationsSupport emails, in-app messagesContract / Legitimate Interest36 months
Payment DataLast 4 digits, billing address (card details tokenised by Stripe)Contract7 years (tax/legal requirement)

How We Use Your Data

Updated September 2026

Service Delivery

  • Authenticating users and maintaining sessions

  • Processing tax referrals and commission calculations

  • Sending transactional emails (referral confirmations, payment notifications)

  • Enabling AI-powered features (Gio assistant) to assist preparers

  • Generating reports, exports, and audit trails for firms

Platform Operations

  • Diagnosing errors and performance issues (Sentry, anonymized logs)

  • Detecting suspicious activity and fraud patterns

  • Evaluating product quality under the published no-training policy for customer inputs

  • Billing reconciliation and subscription management (via Stripe)

  • Supporting compliance obligations (IRS record-keeping, GDPR audits)

We do not sell your data

GoRefer does not sell, rent, or trade personal data to third parties for marketing purposes. The sub-processor register explains how data flows to our service providers, and you can request the provider terms and agreements that apply.

Your Rights (GDPR & CCPA)

GDPR Art. 15–22

Updated September 2026

EU/EEA residents have rights under the General Data Protection Regulation (GDPR). California residents have similar rights under the CCPA. To exercise any right, contact us at privacy@gorefer.io.

RightWhat It Means
Right to Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure
Delete your personal data (subject to legal retention obligations)
Right to Restrict Processing
Pause processing while a dispute is resolved
Right to Data Portability
Export your data in a machine-readable format (JSON/CSV)
Right to Object
Object to processing based on legitimate interests
Right to Withdraw Consent
Withdraw previously given consent at any time

Privacy-request response policy

Response periods depend on the applicable law: GDPR generally requires a response within one month, while CCPA generally allows 45 days; permitted extensions require notice. Identity, scope and legal retention duties are reviewed before completing an export or erasure request.

Cookies & Tracking

Updated September 2026

Essential Cookies

  • Sign-in (refresh) cookies are HttpOnly, Secure and SameSite=Lax

  • Sign-in indicator cookies help route you to the right pages; they cannot sign anyone in

  • Browser storage keeps supported theme and interface preferences

  • Client-specific storage is listed in the Cookie Policy and extension notice

Analytics & Preferences

  • First-party usage analytics and marketing-site Meta Pixel have distinct scopes

  • Sentry error and performance reporting

  • Marketing consent choices are saved in your browser

  • Marketing-site analytics and Meta Pixel are disclosed in our Cookie Policy; they do not run inside the signed-in application

International Data Transfers

Updated September 2026

GoRefer is incorporated in the United States. Where we transfer personal data of EU/EEA residents outside the EEA, we rely on:

Standard Contractual Clauses

  • Transfer terms for each service and provider: available on request

  • Transfer-impact assessments, where required: ask us for the current scope

Adequacy Decisions

  • Where the European Commission has issued an adequacy finding for a destination country

  • Ask us which transfer mechanism applies to UK data

Binding Agreements

  • The subprocessor register describes known provider data flows

  • Full DPA available on request via Trust Portal