1. Data Controller
TM Advisors Group is the data controller for personal information collected through the Service.
For data protection inquiries, contact info@tmadvisorsgroup.com.
2. Information We Collect
Account information: name, email address, password (hashed), phone number, profile photo, preferred language.
Company information: company name, legal name, tax ID, country, business address, contact persons, industry, entity type.
Financial data: bank account connections (via Plaid — we never see your bank credentials), bank transactions, invoices, expenses, customers, projects, Chart of Accounts entries. This data belongs to you; we host it on your behalf.
Payment information: handled by Stripe. We receive a tokenized reference to your payment method but never the full card number.
Usage data: pages visited, features used, IP address, browser type, device type, timestamps. Collected via standard server logs and product analytics.
Communications: emails, support tickets, chat messages with us.
Cookies: see Section 7 for details.
3. How We Use Your Information
Provide and operate the Service: authenticate you, store and process your data, deliver features.
Billing: process subscription payments via Stripe, manage trials, send receipts.
AI processing: transaction categorization, project matching, tax strategy suggestions. Specific transaction descriptions and metadata may be sent to our AI provider (Anthropic) for processing. We do not allow your data to be used to train third-party models.
Support: respond to inquiries, troubleshoot issues, provide product onboarding.
Product improvement: aggregated and anonymized analytics to understand usage patterns.
Communications: account notifications, billing reminders, security alerts, and (with your consent) product updates and marketing.
Legal compliance: respond to lawful requests, enforce our Terms, prevent fraud and abuse.
5. Sub-processors
Our sub-processors are: Supabase (database, authentication and file storage — United States), Vercel (application hosting and content delivery — global edge network), Plaid (bank account connectivity — United States), Stripe (subscription billing and payment processing — United States), Resend (transactional email delivery — United States), Anthropic (AI categorization and assistance — United States), Google (optional sign-in, and Maps Platform for address lookup, routing and delivery maps — United States) and Twilio (telephony and text messaging — United States).
Each sub-processor is bound by a data processing agreement and receives only the data necessary for its function. We will give at least 30 days' notice before adding a new sub-processor, so that you have time to object or to close your account.
6. Data Retention
Active accounts: we retain your data for as long as your account is active.
After cancellation: we retain financial records for 7 years to comply with tax and accounting regulations, after which they are securely deleted. Other personal information is deleted within 90 days of account closure, unless we are required to retain it for legal compliance.
You may request earlier deletion via info@tmadvisorsgroup.com, subject to our legal retention obligations.
These periods are enforced automatically. A scheduled process runs daily: bank credentials are revoked and destroyed as soon as an account is closed, personal information is deleted ninety days after closure, and remaining records are removed once the seven-year obligation expires. Each deletion is recorded so that it can be evidenced.
This policy is reviewed at least once a year, and whenever the way we handle data changes.
8. International Data Transfers
Your information may be processed in countries other than your country of residence, including the United States. We rely on Standard Contractual Clauses (SCCs) and other lawful mechanisms for international transfers.
By using the Service you consent to your information being processed in the United States and other jurisdictions where our service providers operate.
9. Your Rights
GDPR (EU/EEA): right to access, rectify, erase, restrict processing, object, data portability, withdraw consent, and lodge a complaint with a supervisory authority.
CCPA (California): right to know what personal information we collect, sell, or disclose; right to delete; right to opt out of sale (we do not sell); right to non-discrimination.
LGPD (Brazil): equivalent rights including access, rectification, anonymization, portability, and deletion.
To exercise any of these rights, contact info@tmadvisorsgroup.com. We will respond within 30 days or the timeline required by your jurisdiction.
10. Security
We implement industry-standard administrative, technical, and physical safeguards to protect personal information. These include TLS encryption in transit, encryption at rest, Row-Level Security in the database, role-based access controls, periodic security reviews, and incident response procedures.
No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but commit to notifying affected users and authorities of any breach as required by law (typically within 72 hours for GDPR).
11. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it.
12. AI Processing Disclosure
When you use AI features (transaction categorization, project matching, tax suggestions), relevant transaction data and context may be sent to Anthropic's API for processing.
We have a data processing agreement with Anthropic that prohibits the use of your data for training their models.
AI-generated outputs are suggestions only and require your review. They are not professional financial or legal advice.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated via email and an in-app banner at least 30 days before they take effect.
The most current version is always available at /privacy.
14. Contact
Privacy inquiries: info@tmadvisorsgroup.com
Security issues: info@tmadvisorsgroup.com
General support: info@tmadvisorsgroup.com
15. Text Messaging (SMS) Consent and Data
Businesses that use RunGrid may send text messages to their own customers from a business phone number provided through the Service, for example appointment confirmations and reminders, order and pickup notices, invoice and receipt links, and replies to customers who text the business. A customer receives such messages only after giving that business their mobile number and agreeing to receive texts — in person or by phone, by ticking an unchecked consent box on a booking, order or application page, or by texting START to the business's number.
Message frequency varies. Message and data rates may apply. A customer may opt out at any time by replying STOP to any message, and may reply HELP for help. Opt-out requests are honored immediately across the Service.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. Mobile numbers and consent records are used only to deliver the messages the customer agreed to and to honor opt-out requests, and are processed by our messaging sub-processor (Twilio) solely for delivery.
For questions about text messages from a business, contact that business directly or write to info@tmadvisorsgroup.com.
16. Google Calendar Connection
A user may choose to connect their Google account to RunGrid so that their RunGrid appointments appear in Google Calendar. We request a single permission, "Make secondary Google calendars, and see, create, change, and delete events on them". With it, RunGrid creates one calendar named "RunGrid" in the user's Google account and writes, updates and removes the user's RunGrid appointments on that calendar only. RunGrid does not read, change or delete any other calendar or event in the user's Google account, and does not read their Gmail, contacts or any other Google data. We also receive the Google account's email address, shown to the user so they know which account is connected.
The access tokens Google issues are stored encrypted and used only to keep that calendar in sync with the user's appointments. Data received from Google is not used for advertising, is not sold, is not used to train AI models, and is not shared with third parties, and no person at TM Advisors Group reads it except when the user asks for support, for security purposes, or to comply with the law.
RunGrid's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
The user can disconnect at any time from the Calendar page in RunGrid, which deletes the "RunGrid" calendar from their Google account, returns the permission to Google and deletes the stored tokens. Access can also be removed at any time from the Google account at https://myaccount.google.com/permissions.