Legal
Privacy Policy
Last updated: September 5, 2026
This policy describes how HeyRoca (“we”, “us”) handles information when you visit heyroca.com, request founding access, or use the staff app and client portal. This draft is not a substitute for review by counsel. Questions: [email protected].
Who this covers
We process information for tax and accounting firms that subscribe to HeyRoca, their staff, and the clients those firms invite to the portal. Firms are the customer. Client tax files are processed on the firm’s instructions. Our Data Processing Addendum applies when we process personal data on a firm’s behalf.
Information we collect
- Account data: names, work emails, firm name, role, and authentication records, including multifactor enrollment and MFA audit events.
- Practice data firms enter or upload: contacts, organizers, documents, messages, appointments, invoices, and e-signature records.
- Sensitive identifiers when a firm stores them: Social Security numbers and EINs, which are encrypted at rest.
- Payment data handled by Stripe. We do not store full card numbers.
- Marketing form data: name, work email, firm size, and optional phone for demo or custom-order requests. We use those submissions to follow up.
- Technical logs: IP address, user agent, and security events such as sign-in, MFA, and e-sign activity.
How we use information
We use this information to operate the workspace, authenticate users (including email one-time codes and authenticator MFA), deliver email (via Resend), process payments (via Stripe), store files in a private object vault (Cloudflare R2), host data in managed PostgreSQL, improve reliability, and respond to support requests. We do not sell personal information.
Sharing
We share information with infrastructure and subprocessors needed to run the service: Stripe, Resend, Cloudflare R2, and managed Postgres. Staff at a firm can see that firm’s records according to their role. We disclose information if required by law or to protect the service.
Retention and deletion
We keep firm data while the subscription is active and for a limited period afterward so the firm can export or reactivate. Firms can request deletion at [email protected]. We will delete or return customer data on request, subject to legal retention needs. Some security logs are retained to investigate abuse.
Security
See our Security page for encryption, MFA, session length, and storage practices. No method of transmission or storage is perfectly secure.
Your choices
Staff and portal users can update profile information in the product. To access, correct, or delete personal information, contact your firm or email [email protected]. If we process data for a firm, we will direct the request to that firm when appropriate.
Children
HeyRoca is not directed to children under 13.
Changes
We will post updates on this page and revise the date above. Continued use after a change means you accept the updated policy.