Data Processing Addendum

Effective Date: September 24, 2026

This forms part of the Terms of Service and governs the processing, by Journey Tax Inc. (operator of Journey.tax, the "Processor," "we," "our," or "us"), of personal data and tax return information that a firm ("Firm") submits to the Service.

1. Roles and Frameworks

  • The Firm is the controller of client data and, where applicable, a "financial institution" under the GLBA.
  • Journey Tax Inc. is the processor / service provider, and acts as the Firm's auxiliary service provider in connection with tax return preparation for purposes of IRC § 7216 / Treas. Reg. § 301.7216-2.

2. Purpose Limitation and § 7216

We process Firm and client data solely to provide the Service to the Firm and on the Firm's documented instructions. We will not use or disclose tax return information except as necessary to provide the Service or as the Firm directs, consistent with § 7216. We will not use client data for our own marketing, analytics unrelated to the Service, or to train third-party AI models.

3. AI / OCR Subprocessing

The Service may send documents the Firm uploads to a third-party AI provider for optical character recognition and data extraction. Where the Firm uses the bookkeeping features, the Service may also send the date, description and amount of a bank transaction, together with the account names in that client's chart of accounts, to the same provider in order to suggest a category for the transaction. We commit that:

  • this processing occurs with providers located in the United States (which keeps the Firm outside § 7216's offshore-disclosure requirements);
  • the documents, the extracted data and the transaction details are processed only to provide the feature the Firm has used;
  • for category suggestions we send only the date, description and amount of the transaction and the account names, and never the client's name, address, email address or telephone number, and never an export of the ledger; and
  • the data is not used to train the provider's models, under terms at least as protective as this Addendum.

4. Subprocessors

We engage the following subprocessors to provide the Service. We will maintain this list and give the Firm advance notice before adding or replacing a subprocessor, and will bind each to data-protection obligations no less protective than this Addendum.

SubprocessorFunctionLocation
SupabaseCloud hosting and databaseUnited States
LovableApplication build and hosting platform, which operates the infrastructure the Service runs onUnited States
RailwayHosting for the automated document-processing service that performs optical character recognition on uploaded tax documentsUnited States
IntuitQuickBooks Online accounting data, where a Firm connects a QuickBooks companyUnited States
OpenAIAI-assisted drafting and summarization, optical character recognition of uploaded tax documents, and suggested categories for bank transactions in the bookkeeping featuresUnited States
PlaidBank and card transaction feeds, where a client authorizes a connection to their financial institutionUnited States
ResendOutbound transactional emailUnited States
PostmarkInbound email delivery, where a Firm has connected an inbound addressUnited States
TwilioSMS notificationsUnited States
StripePayment processing for firm subscriptions and client invoicesUnited States

OpenAI processes the contents of documents uploaded to the Service, including scanned tax forms, for the purpose of extracting their data. Where a Firm uses the bookkeeping features, OpenAI also receives the date, description and amount of a bank transaction and the account names in that client's chart of accounts, in order to suggest a category; it does not receive the client's name, address, email address or telephone number, and it does not receive an export of the ledger. Data sent to the OpenAI API is not used to train their models and is not retained for logging, but is held for up to 30 days for abuse monitoring. Firms will receive advance notice of any subprocessor changes.

Plaid provides the bank and card transaction feed used by the bookkeeping features. The client authorizes the connection to their own financial institution through Plaid's own screens, and the client's banking credentials are entered there and never reach the Service. Journey Tax Inc. is Plaid's customer of record for the connection. What comes back is the account name, mask, type and balance, and the date, description and amount of each transaction, which is written into the Firm's ledger. The connection is read only and cannot move money. The access token Plaid issues is stored encrypted on a table that no application role can read, and is used only by the Service's own background sync. When the client disconnects, we instruct Plaid to remove the connection and we delete the stored token. Transactions already written into the Firm's ledger remain part of the Firm's books and are retained and deleted with the rest of the Firm's data under Section 8. Firms that do not use the bookkeeping features are not affected.

Postmark receives email sent to a Firm's connected inbound address and passes it to the Service. That includes the sender, the subject, the message body and any attachments, so a document a client sends by email reaches the Service through Postmark. Firms that do not connect an inbound address are not affected.

5. Security (Safeguards Rule Alignment)

We maintain an information security program with administrative, technical, and physical safeguards consistent with the FTC Safeguards Rule and IRS Publication 4557, including encryption in transit and at rest, role-based access controls, multi-factor authentication for administrative access, time-limited signed URLs for document access, logging, and monitoring.

6. Firm Oversight and Information

To support the Firm's own Safeguards Rule vendor-oversight duties, we will provide, on reasonable request, summary information about our security practices, subprocessors, and relevant certifications or assessments.

7. Breach Notification

We will notify the Firm of a confirmed personal-data or tax-return-information breach affecting the Firm's data without undue delay, and no later than 72 hours after we confirm it, including the nature of the incident, the data involved, and the steps taken, to the extent known.

8. Data Return and Deletion

On termination or on the Firm's request, we will make the Firm's data available for export for 30 days, after which we will delete or return it within 60 days, except for copies we are required by law to retain or that exist in routine backups, which are deleted on their normal cycle.

9. International Transfers

We process Firm and client data in the United States and will not transfer it outside the United States without the Firm's instruction and any additional § 7216 consents that such transfer would require.

10. Compliance

Both parties will comply with applicable data-protection and tax-confidentiality laws, including GLBA, the FTC Safeguards Rule, and IRC § 7216/§ 6713.

Journey.tax is operated by Journey Tax Inc., 8470 Enterprise Cir, Lakewood Ranch, FL 34202 · 727-362-6858 · admin@journey.tax