Last Updated: July 19, 2026
TaxReceipt.app is operated by SMB Operations Inc. ("we," "us," or "our"). We provide a software-as-a-service (SaaS) platform that helps charities, nonprofits, and the accountants who serve them generate, manage, and deliver tax receipts.
This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our website at taxreceipt.app and related services (collectively, the "Service").
When you create an account, we collect:
When you create an organization, we collect:
When you import data to generate receipts, the information you upload is stored in our system. This may include donor names, addresses, email addresses, donation amounts, donation dates, and other fields you choose to import. You are the data controller for this information — we process it on your behalf to provide the Service.
Payments are processed by Stripe. We do not store your credit card number, bank account details, or other payment instrument information on our servers. We retain only a Stripe customer identifier and billing history metadata (amounts, dates, product descriptions) for your account records.
We automatically collect:
We do not use third-party analytics services (such as Google Analytics) or advertising trackers on our website.
We use the information we collect to:
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
The Service integrates with third-party platforms. When you connect an integration, we access only the data you authorize, and only for the purposes described below.
If you connect your QuickBooks account, we access your accounting data (income accounts, deposits, payments, sales receipts, and customer information) to import donation records for receipt generation. We store encrypted OAuth tokens to maintain your connection. You can disconnect QuickBooks at any time from your data source settings, which revokes our access.
We use Google OAuth for sign-in authentication, which provides us with your name, email address, and profile picture via the userinfo.email scope. Two further Google permissions are requested only if you choose to use the corresponding feature, and each is described separately below.
If you choose to import donor data from Google Sheets, TaxReceipt.app requests the https://www.googleapis.com/auth/drive.file scope. This is Google's per-file scope: it grants access only to the specific files you choose through the Google file picker. It does not grant access to your Google Drive as a whole, and we cannot see files you have not selected.
We use this scope only to:
We do not:
If you choose Gmail as your email delivery provider, TaxReceipt.app requests the https://www.googleapis.com/auth/gmail.send scope. This scope grants send-only access — it does not permit reading, modifying, or deleting messages in your Gmail account.
We use this scope only to:
We do not:
You can revoke TaxReceipt.app's access to your Google account at any time by disconnecting the Gmail provider in your Organization Settings, or from your Google Account permissions page.
TaxReceipt.app's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you configure Outlook as your email provider, we use the Microsoft Graph API to send receipt emails on your behalf. We do not access your mailbox, calendar, or other Microsoft data.
We use Stripe to process payments. Stripe collects and processes your payment information under its own privacy policy. We receive webhook notifications about payment events (successful purchases, subscription changes) but do not receive or store your payment card details.
You may configure additional email providers (SendGrid, Mailgun, AWS SES, or custom SMTP) to deliver receipt emails. When you do so, your email provider credentials are encrypted at rest using AES-256 encryption. Recipient email addresses and email content are transmitted to your selected provider for delivery.
Our Service is hosted on Google Cloud Platform (GCP). Your data is stored in GCP Cloud SQL (managed PostgreSQL) and Cloud Run (serverless containers) in the us-central1 region (Council Bluffs, Iowa, USA). GCP provides infrastructure-level encryption at rest and in transit.
We implement the following security measures to protect your data:
While we take reasonable measures to protect your information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.
Your account data, organization data, templates, and receipt records are retained in our database until you delete them or request account deletion. Soft-delete mechanisms are used where possible to allow recovery from accidental deletions.
Generated receipt PDF files are subject to the following retention schedule:
The automated PDF cleanup process runs daily at 2:00 AM UTC.
You may request deletion of your account and all associated data through the Data Privacy settings in your account. Account deletion has a 30-day grace period during which you can cancel the request. After the grace period, your data is permanently and irreversibly deleted.
We strongly recommend exporting your data before requesting deletion, especially if you are required to maintain tax records for the legally mandated retention period in your jurisdiction (e.g., 7 years in Canada and the United States).
We send transactional emails that are necessary for the operation of the Service, including account verification, password resets, receipt delivery confirmations, PDF expiration warnings, and subscription-related notifications. These emails cannot be opted out of while your account is active.
New users receive an onboarding email series to help them get started with the Service. You can unsubscribe from these emails at any time using the unsubscribe link in each email or by updating your notification preferences in your account settings.
Our onboarding and product emails may contain a small tracking pixel to measure whether emails are opened and which links are clicked. This helps us understand whether our communications are useful. Receipt delivery emails sent on your behalf to your donors may also include tracking for delivery confirmation purposes. You can disable marketing email tracking by unsubscribing from marketing emails.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
You can view a summary of all data we hold about you through the Data Privacy section of your account settings. This includes counts of your receipts, organizations, templates, and stored PDFs.
You can export all of your data as a downloadable ZIP file containing CSV files (user data, organizations, receipts, templates, subscriptions) and your generated PDF files, along with a metadata file describing the export.
You can request permanent deletion of your account and all associated data. Deletion is subject to a 30-day grace period, after which all data is irreversibly removed. You will be reminded of any tax record retention obligations before confirming deletion.
You can update your personal information, organization details, and other data at any time through your account settings and organization settings pages.
You can unsubscribe from marketing communications at any time. You can disconnect any third-party integration (QuickBooks, Google Sheets, Gmail, Outlook) from your settings to revoke our access to that service. You can close your account at any time.
To exercise any of these rights, use the in-app tools described above or contact us at care@smboperations.ca.
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
Our Service is hosted on Google Cloud Platform in the United States (us-central1 region). If you are located outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We rely on Google Cloud's compliance certifications (SOC 1/2/3, ISO 27001, and others) and contractual safeguards to protect transferred data.
SMB Operations Inc. is based in Ontario, Canada, and complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the policy was most recently revised. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or our data practices, please contact us:
© 2026 SMB Operations Inc. All rights reserved.