GoRefer Trust Center
Privacy Policy
Updated September 2026
GoRefer, Inc. ("GoRefer", "we", "us") is committed to protecting the personal data of our customers, their clients, and all users of the platform. This policy explains what we collect, why, how we protect it, and your rights.
What Data We Collect & Why
Updated September 2026
We collect the minimum data needed to provide the service. All data processing has an identified lawful basis under GDPR Article 6. Supported sensitive intake fields use AES-256-GCM. Documents and other personal data are handled according to the feature that uses them; storage encryption and provider terms are covered on the Security and Sub-processors pages.
| Data Category | Examples | Lawful Basis | Retention Period |
|---|---|---|---|
| Account & Identity | Name, email, phone number, profile photo | Contract | Account and legal-retention policy |
| Tax Professional Data | PTIN, EFIN, firm name, specializations | Contract / Legitimate Interest | Life of firm account |
| Client Personal Data | Name, email, tax year info | Contract | Per retention schedule |
| PII (sensitive) | SSN, EIN, bank account, driving license | Explicit Consent / Legal Obligation | Per retention schedule (encrypted at rest) |
| Usage & Analytics | Page views, feature usage, session duration | Legitimate Interest | 24 months rolling |
| Communications | Support emails, in-app messages | Contract / Legitimate Interest | 36 months |
| Payment Data | Last 4 digits, billing address (card details tokenised by Stripe) | Contract | 7 years (tax/legal requirement) |
How We Use Your Data
Updated September 2026
Service Delivery
Authenticating users and maintaining sessions
Processing tax referrals and commission calculations
Sending transactional emails (referral confirmations, payment notifications)
Enabling AI-powered features (Gio assistant) to assist preparers
Generating reports, exports, and audit trails for firms
Platform Operations
Diagnosing errors and performance issues (Sentry, anonymized logs)
Detecting suspicious activity and fraud patterns
Evaluating product quality under the published no-training policy for customer inputs
Billing reconciliation and subscription management (via Stripe)
Supporting compliance obligations (IRS record-keeping, GDPR audits)
We do not sell your data
GoRefer does not sell, rent, or trade personal data to third parties for marketing purposes. The sub-processor register explains how data flows to our service providers, and you can request the provider terms and agreements that apply.
Your Rights (GDPR & CCPA)
Updated September 2026
EU/EEA residents have rights under the General Data Protection Regulation (GDPR). California residents have similar rights under the CCPA. To exercise any right, contact us at privacy@gorefer.io.
| Right | What It Means |
|---|---|
Right to Access | Request a copy of all personal data we hold about you |
Right to Rectification | Correct inaccurate or incomplete personal data |
Right to Erasure | Delete your personal data (subject to legal retention obligations) |
Right to Restrict Processing | Pause processing while a dispute is resolved |
Right to Data Portability | Export your data in a machine-readable format (JSON/CSV) |
Right to Object | Object to processing based on legitimate interests |
Right to Withdraw Consent | Withdraw previously given consent at any time |
Privacy-request response policy
Response periods depend on the applicable law: GDPR generally requires a response within one month, while CCPA generally allows 45 days; permitted extensions require notice. Identity, scope and legal retention duties are reviewed before completing an export or erasure request.
Cookies & Tracking
Updated September 2026
Essential Cookies
Sign-in (refresh) cookies are HttpOnly, Secure and SameSite=Lax
Sign-in indicator cookies help route you to the right pages; they cannot sign anyone in
Browser storage keeps supported theme and interface preferences
Client-specific storage is listed in the Cookie Policy and extension notice
Analytics & Preferences
First-party usage analytics and marketing-site Meta Pixel have distinct scopes
Sentry error and performance reporting
Marketing consent choices are saved in your browser
Marketing-site analytics and Meta Pixel are disclosed in our Cookie Policy; they do not run inside the signed-in application
International Data Transfers
Updated September 2026
GoRefer is incorporated in the United States. Where we transfer personal data of EU/EEA residents outside the EEA, we rely on:
Standard Contractual Clauses
Transfer terms for each service and provider: available on request
Transfer-impact assessments, where required: ask us for the current scope
Adequacy Decisions
Where the European Commission has issued an adequacy finding for a destination country
Ask us which transfer mechanism applies to UK data
Binding Agreements
The subprocessor register describes known provider data flows
Full DPA available on request via Trust Portal