Haven Global Privacy Policy

Last Updated: December 19, 2020

Introduction and Overview

Haven leverages technology responsibly to empower small businesses to contribute to prosperity around the world, and we believe that everyone has a right to privacy. At Haven, we view privacy as a key part of the value that we deliver to our customers.

Scope of This Privacy Policy and Our Role

As a financial services and technology company, we’re providing this Global Privacy Policy (which we’ll refer to as the “Privacy Policy”) to explain how we collect, use, and share information when you interact with us and our offerings, services, and experiences. This Privacy Policy is global in nature, meaning that it applies to all websites and offerings of Haven and any of its affiliates, and it describes our privacy practices when we process:

(i) Personal information for the purposes of preparing a tax return or other tax filing or in connection with the preparation of a tax return or other tax filing (collectively, “Tax Preparation Information”);

(ii) Personal information for the purposes of providing the benefits of the Haven platform, which is, collectively, all of Haven’s services, sites, experiences and software (including through our mobile, web, and desktop applications) by Haven Software LLC and its affiliates and subsidiaries other than Tax Preparation Information (collectively, the “Haven Platform”); and/or

(iii) Personal information as necessary to manage, run, and improve our business.

Haven Software LLC determines the purposes and means of the processing of personal information (the “Information Controller”). Haven Software LLC may share your personal data with other affiliates of Haven to process as joint controllers for the purposes set out in this Privacy Policy. If you have any questions about the processing of your personal data, please contact us in the section “How to Contact Us” below.

This Privacy Policy does not apply where Haven processes personal information as a service provider on behalf of a customer or entity who acts as the Information Controller. When we act as a service provider, the Privacy Policy of the relevant Information Controller and our agreements with such business or entity will govern our processing of personal information.

In certain circumstances, there may be more than one Information Controller processing your information. For example, your employer or a financial partner may also act as an Information Controller. In these situations, we act as an independent Information Controller over our processing activities--meaning that we make determinations over how your personal information will be processed independently from the other Information Controller. The other Information Controller may have their own obligations under applicable information privacy law, and you may need to speak with the other Information Controller directly for questions on how they process your personal information.

The Haven Platform

The Haven Platform and Your Information

When we say “platform,” we mean that when you choose to share data with us, or bring over information from third parties (like a bank or loan provider), we use that data together, not just within the individual offering(s) you’re using.

The personal information we use in this centralized way is all the information that Haven knows about you. It includes your credentials; your name and contact details; payment information; information about your activities, your interests and preferences; insights about your finances or your business; the content you place in our Platform; and information we have collected about you from third-party sources.

Organizational Account Information

Some experiences and services within the Haven Platform allow you to interact with an organization (such as your employer). If you are granted access to an organization or household account (for example, a business's account in Haven), the owner of the organization or a designated administrator may control and administer details of your account, for example, by deciding your access rights; making decisions about your personal information (such as details about your payroll); or requiring you to take certain actions (for example, use location tracking to clock in for a shift). If your access rights are amended by the owner or designated administrator, then you may lose access to the information that is in the control of the organization.

Your use of the Haven Platform as part of an organization’s account may be subject to the organization’s policies, which may be different from this Privacy Policy. We are not responsible for the privacy or security practices of other organizations, and you should consider both the organization's policies and whether you are comfortable enabling the organization with access to your information prior to connecting to their services.

Information We Collect

Information We Receive From You

The personal information that we receive about you depends on the context of your interactions with Haven, how you configure your account, and the choices that you make, including your privacy settings. Personal information that you provide may also depend upon what services or experiences you use, your location and applicable law.

Creating an Account

We collect information when you create an account, interact with the Haven Platform or activate a subscription. Personal information may include your contact information (such as your name, address, phone number, and e-mail), profile photo, billing information (your payment information), usernames, social media accounts, and credentials.

Identification Information

We collect information to verify your identity, including your name, social security number, social insurance number, driver’s license numbers, and government-issued identification details, for example, in order to help you file your tax return or validate payroll.

Customer Support, Product Research, Training, and Feedback

We may collect personal information when you reach out to us for support, give us feedback, participate in optional surveys, product research, or training and you choose to share.

Social and Community Content

We receive content you post on our social media pages and our community pages.

Device Information

We may collect information about your device such as Internet Protocol (“IP”) addresses, log information, error messages, device type, and unique device identifiers. For example, we may collect IP addresses from you as part of our sign in and security features.

Content

We may receive information about your business, finances, expenses, invoices, financial statements, details of your financial transactions, inventory, payroll details, payment details, tax return details, details about your customers or vendors or employees, income and wage information, and/or investment information.

Third-Party Service Content

We receive information about you when you sign into a third-party service with your account or when you connect your account to a third-party service. For example, you may choose to connect your account with your bank accounts. To sync your financial account information, we must access your financial account information.

Usage Information

We may collect usage information such as the pages you viewed, the features you use, your browser type, and details about any links with which you interact.

Location Information

Certain features in the Haven Platform may collect your precise location information, device motion information, or both, if you grant permission to do so in your device settings. For example, if you use our time-tracking service.

Expert Advice

The Haven Platform provides many opportunities for you to connect with live experts, including, for example, accountants or tax preparers. When you interact with these experts, we may receive information about the questions you ask, the details of your accounts, and the guidance provided to you.

Camera, Contacts, and Push Notifications

Certain features may have access to your camera, contacts, and push notification services if you grant permission in your device settings.

Information From Cookies and Other Technologies

Haven and our service providers may use commonly used tools such as cookies, web beacons, pixels, local shared objects and similar technologies (collectively, "Cookies") to collect information about you (“Cookie Information”) so we can provide the experiences you request, recognize your visit, track your interactions, and improve your and other customers' experience. You have control over some of the information we collect from Cookies and how we use it.

Information Stored Locally

Some of our web-enabled desktop services and offerings synchronize with the information on your computer or mobile device. In doing so, we may collect information such as device information, product usage, and error reports. We may also store personal information locally on your device.

Biometric Information

Certain parts of the Haven Platform make use of biometric personal information (“Biometric Information“). Biometric Information can be subject to additional laws and regulations.

We collect Biometric Information from you when you enroll in our biometric identity program and automatically as part of our anti-fraud protection, authentication, and customer support activities. These identifiers may include facial recognition information, voiceprints, and key-stroke information, as well as mathematical representations of your biometric identifier, such as the template maintained for comparison. We use Biometric Information to identify and authenticate you, and for security and similar purposes. We share Biometric Information with third-party service providers who assist with our information technology, security, and ant-fraud programs, our professional advisors, and as required by law or regulation. Haven does not sell your Biometric Information.

When we collect Biometric Information, you will receive a specific notice and consent request at the time of that collection. You are not required to consent to the collection of Biometric Information in order to use our services, although some functionality may not be available if you decline, and you may withdraw your consent at any time.

Haven will retain Biometric Information until the purposes for which it was collected have been satisfied or three years from your or your organizational account manager’s last interaction with Haven, whichever comes first.

Information Provided by Others

Our platform is designed to help you connect with other people and organizations. As a result of those connections, others may be able to input information about you. For example, your employer may input information about your salary and work activity in order to process their payroll. You may also be able to input or process information about others, for example, if you are an account administrator. If you input information about others into our platform, you must only do so if you have first received the appropriate rights and permissions to do so, including by getting advanced written consent, if required by applicable law.

Other Information Sources

We may also get information about you from others where permitted by applicable law. We protect and process information obtained from those parties as described in this Privacy Policy, consistent with any additional restrictions imposed by the source of the information. Our sources may vary over time and depend upon how you use the Haven Platform. For example, we receive information from:

Your Service Providers

If you choose to sync a non-Haven account/service with your account, we will receive information from that account/service according to your settings with that account/service. For example, if you connect a point of sale application to your account, we may receive details of your business’s sales records.

Supplemental Information and Identity Verification Providers

Service providers who help us verify your identity and the specifics of your business, supplement the information you have provided, and ensure the accuracy of your information. For example, we use third-party service providers to validate your mailing address and phone number and provide additional details about your business. These providers may include, for example, your financial institution, telecommunications provider, or e-mail provider.

Customer Support Providers

Service providers provide us with information about you or your interaction with the Haven Platform for troubleshooting purposes. For example, we may obtain support information or technical issues you have raised with these third parties.

Credit Bureaus and Other Third Parties

Many of our features rely on information about you that we receive from third parties. Our partners may provide information such as employment or income data or vehicle or driver information so that we can give you more personalized recommendations.

Other Users

As described above, we may get information about you from other users, such as your accountant, bookkeeper, tax preparer, your spouse, your head of household, or your employer. We may also collect such information through features like member referral programs.

Risk Management, Cybersecurity and Anti-Fraud Providers

We may receive information from service providers who help us assess risks associated with our offerings, including to help combat fraud and illegal activity and to help protect your personal information.

Content Providers

We may receive information from software providers that make user-generated content from their service available to others, such as local business reviews or public social media posts.

Communication Providers and Social Networks

If you give us permission, we may collect information from e-mail providers, communication providers and social networks.

Joint Offering Partners

We may offer co-branded services or experiences or engage in joint-marketing activities with others, including through our conferences or live events.

Publicly Available Sources

We collect information from publicly available sources, such as open government databases.

Government Agencies

We receive information from government agencies, including from various tax agencies.

Required Information

Some services and experiences in the Haven Platform require you to provide information for it to function. If you do not wish to provide the required information, you may not be able to use certain features.

How We Use Personal Information

We collect and process personal information from you only where:

  • We have your consent to do so;

  • We need the personal information to perform a contract with you or provide a service to you;

  • Provide you with the benefits of the Haven Platform and operate our business;

  • The processing is in our legitimate business interests in those jurisdictions where legitimate business interest is a legitimate basis for processing; and/or

  • We need to comply with legal requirements, including applicable laws and regulations.

Personal information is used to operate our business for the following purposes that are required to originate and maintain our relationship with you, including but not limited to:

  • Provide you with the Haven Platform and create your account;

  • Improve our products and services;

  • Run and manage our business, including resolving billing and financial disputes;

  • Evaluate your eligibility for financial offers, products, and services;

  • Provide features to you, such as your free credit reports and scores;

  • Connect you with experts and other users;

  • Communicate with you, such as sending you electronic notifications concerning your financial privacy;

  • Advertise and market our services and experiences;

  • Personalize your experience and tailor recommendations and offers presented to you, including through the development of insights about you and your needs;

  • Provide you with support and resolve disputes;

  • Conduct research, including by partnering with academic institutions;

  • Comply with our legal and regulatory requirements;

  • Authenticate your identity, including through the use of Biometric Information;

  • Protect the rights, property, safety, or security of the Haven Platform, our customers, employees, or others and prevent fraudulent or illegal activity;

  • To exercise our rights in the course of judicial, administrative, or arbitration proceedings;

  • To enforce, remedy, or apply our Terms of Service or other agreements; and/or

  • For other purposes that are compatible with the disclosed purposes if and where this is permitted by applicable law.

To provide you with valuable personalized advice, recommendations, and experiences, we may process your personal information using automated and manual (human) methods. Our automated methods include artificial intelligence (AI) and a range of technologies that help our services learn and reason to improve our ability to personalize and enhance your experience in the Haven Platform.

How We Share Your Information

We may share your information in the following circumstances:

With Your Consent

Except for as outlined below, we only share your information with third parties when you have directed us to do so.

When You Connect With a Haven Platform Partner

You may be provided with offers, products, and services from third-party companies who integrate with our Haven Platform (each, a “Platform Partner”). If you choose to interact with a Platform Partner, apply for their services or offerings, or otherwise link or sync your account to a Platform Partner’s product or service, you consent and direct Haven to share your information, including personal information, information about your business, and/or information about your employer’s business, to the Platform Partner providing the service or offering. For example, when we send your personal information to partners in order to generate offers for you to review, when we send your application information directly to our partners, or when we send you to the partner’s site for you to provide the information directly to them.

In some cases, if you click through to go to a Platform Partner’s site, you will automatically be sending your personal information to that Platform Partner. When this happens, you will still have to submit your application on the Platform Partner’s site. Remember that any information you provide to a Platform Partner, whether through us or on your own, will be subject to their privacy practices and terms and conditions.

When You Connect to Your Social Media Account

Some of our features enable you to connect to a social media account or share information on social media platforms, like Facebook and Twitter. Any information you choose to share on social media may potentially be visible to a global audience and will be subject to the social media provider's privacy policies (not this Privacy Policy). You should take care only to share information on social media that you are comfortable sharing.

For Research

With appropriate controls, we may share information with third parties, such as academic institutions, governments, and non-profit organizations, for research purposes or to publish academic or policy-related materials. We only share information in a way that would not allow any individual to be identified without their consent.

For Joint Features, Sales, Promotions, and Events

We may share your information with third-party companies who are jointly providing features, sales initiatives, promotions, or events with us.

With Financial Services Providers

We may share personal Information with collection agencies, credit bureaus, loan service providers, and payment card association members. We may also share your personal information with other companies, lawyers, credit bureaus, agents, government agencies, and card associations in connection with issues related to fraud, credit, defaults, or debt collection.

When You Publicly Post the Information

We may provide opportunities for you to publicly post reviews, questions, comments, suggestions, or other content, which may include personal information, such as your name or user name. Anything you share in a public forum is public, and you should think carefully before you decide to share.

With Service Providers or Agents

We share personal information with our service providers or agents who provide services on our behalf for the purposes described in this Privacy Policy. Service providers or agents are required to implement reasonable privacy and information protection controls to maintain the privacy and security of information provided to them consistent with the privacy practices outlined in this Statement. Service providers or agents may include companies that assist us with our advertising, marketing, and sales efforts, help us with our technology offerings (such as a hosting, security, or anti-fraud providers), and help us run our business.

For Mergers and Acquisitions

If we are involved with a merger, asset sale, financing, liquidation, bankruptcy, or the acquisition of all or part of our business to another company, we may share your information with that company and its advisors before and after the transaction date, including in connection with due diligence activities.

No Sale of Personal Information to Third Parties

We do not and will not sell personal information to third parties. We do share personal information with third parties for the business purposes described in this Privacy Policy.

With our affiliates and subsidiaries and your right to limit information sharing. We may share your information with our affiliates and subsidiaries for everyday business purposes as described in this Privacy Policy, including for marketing purposes. Certain laws may provide you with the right to limit our information sharing activities in certain circumstances. Please review these rights in the “Country and Region-Specific Terms” section below.

Cookies and Other Tracking Technologies

You can find information on changing your browser settings to opt-out of Cookies in your browser settings. In certain countries, you may also be able to make changes to your cookies settings by using our Cookie preferences tool. If you disable some or all of the Cookies, the service, or parts of the service, may not work.

For advertising and analytics. Haven may use advertising networks and other providers to display advertising on our Haven Platform or to manage our advertising on other sites. Our advertising partners may place Cookies on unaffiliated websites in order to serve advertisements that may be relevant to you based on your browsing activities and interests and determine the effectiveness of such advertisements. See also the “Country and Region-Specific Terms” section below for additional pages.

The Haven Platform is not currently configured to respond to browsers’ “Do Not Track” signals because at this time no formal “Do Not Track” standard has been adopted.

For Legal Reasons

We may share your information with third-parties for legal reasons without your consent, and as permitted by law, including:

  • When we reasonably believe disclosure is required in order to comply with a subpoena, court order, or other applicable law, regulation, or legal process;

  • To protect the rights, property, or safety of Haven, HavenTax, the Haven Platform, our customers, or others;

  • To protect or defend against attacks;

  • To enforce, remedy, or apply our Terms of Service or other agreements;

  • To prevent fraud, cybersecurity attacks, or illegal activity;

  • For debt collection; and/or

  • With regulatory agencies, including government tax agencies, as necessary to help detect and combat fraud and/or protect our customers, users, and/or the Haven Platform, or in required institutional risk control programs.

Your Information Rights and Choices

Your Rights

At Haven, we believe that you have rights to information that pertains to you, your household, and/or your business. If another person has input or processed information in the Haven Platform on behalf of you, your family, or your business (and we are processing such information as an Information Controller), you may ask to receive a copy of your information, even if you do not have an account with us.

Depending on where you live, you may have certain state- or nation-specific rights with respect to your personal information that we collect and process.

For specific information on what steps you can take to manage your privacy, please see the “Country and Region-Specific Terms” section for your country, below.

Verification

To help protect privacy and the security of your information, you may be asked to provide additional information to verify your identity and/or ownership rights prior to us exercising your data rights. If we are unable to verify your identity or ownership rights to the data, we may not be able to provide you with data rights until you are able to provide us with proper documents.

Information Retention

Unless you specifically ask us to delete your personal information, we retain your personal information as long as it is necessary to comply with our data retention requirements and provide you with services and the benefits of the Haven Platform. However, even if you request a deletion, we may be required to maintain your information for as long as necessary to:

(i) comply with our legal or regulatory compliance needs (e.g. maintaining records of transactions you have made with us);

(ii) to exercise, establish or defend legal claims; and/or

(iii) to protect against fraudulent or abusive activity on our service.

This means we may keep different information for different periods. If your account is canceled because you haven’t used it in a long time, we may delete this information immediately.

There may be occasions where we are unable to fully delete, anonymize, or de-identify your information due to technical, legal, regulatory compliance or other operational reasons. Where this is the case, we will take reasonable measures to securely isolate your personal information from any further processing until such time as we are able to delete, anonymize, or de-identify it.

International Data Transfers

Unless you have provided us with consent to transfer your information, U.S. Tax Preparation Information shall be processed and stored in the United States in accordance with applicable law.

With the exceptions noted above, you agree and Haven reserves the right to store and process your personal information in the United States and in any other country where Haven or its affiliates, subsidiaries, or service providers operate facilities in accordance with and as permitted by applicable laws and regulations. Some of these countries may have data protection laws that are different from the laws of your country (and, in some cases, may not be as protective).

When we transfer, store or process personal information outside of your jurisdiction, we take appropriate safeguards to require that your personal information remain protected in accordance with this Privacy Policy and applicable law. We may use contracts or the European Commission approved Standard Contractual Clauses to help ensure your information is protected.

Security of Your Personal Information

We use physical, technical, and organizational safeguards designed to protect your information. However, despite these controls, we cannot completely ensure or warrant the security of your information.

Changes to Our Privacy Policy

From time to time we may change or update our Privacy Policy. We reserve the right to make changes or updates at any time. If we make material changes to the way we process your personal information, we will notify you by posting a notice in our platform or on a community post; by sending you a notification; or by other means consistent with applicable law.

You can see when this Privacy Policy was last updated by checking the “last updated” date displayed at the top of this Privacy Policy. Please review this Privacy Policy periodically to stay informed about how Haven protects your privacy.

Collection and Use of Children’s Personal Information

Our services are not intended for or directed to children. We do not knowingly collect personal information from children. If you believe we may have information from a child, please contact us.

Country and Region-Specific Terms

Additional terms may apply to you based upon the country you reside in or the products you use. Please click the country or region that applies to you to learn more about additional terms and rights that may apply to you.

United States

If you are a resident of the United States, you may have the following rights:

U.S. Tax Preparation Information

We understand that your Tax Preparation Information is special. Except as necessary to provide you with tax preparation services or as authorized by law, we will not disclose your Tax Preparation Information--including to Haven’s affiliates and subsidiaries--unless  you consent.

We will only use your Tax Preparation Information to provide you with tax preparation services or as authorized by law, unless you consent that we can use and/or share it for other purposes.

If you agree to share your Tax Preparation Information outside of our tax products to be used for purposes other than tax preparation services, including by sharing it with the Haven Platform, your Tax Preparation Information will be handled in accordance with this Privacy Policy.

Vermont

If you are a Vermont resident, you may have the following rights:

Haven group companies will not share your non-public personal information with unaffiliated third parties unless you authorize us to make those disclosures without your consent, other than as permitted by law. Further, Haven group companies’ consumer offerings will not share credit reports with our affiliates without your consent.

California

If you are a California resident, you may have the following rights:

Access. You may have the right to access:

• the categories of personal information we have collected about you,
• the sources from which that information was collected,
• the business or commercial purpose for collecting your personal information,
• the categories of third parties with whom we share your personal information,
• the specific pieces of personal information we have collected about you,
• the categories of personal information we sold about you,
• the categories of third parties to whom we sold personal information about you, and
• the categories of personal information we disclosed for a business purpose.

Deletion. You may have the right, under certain circumstances, to request that we delete the personal information you have provided to us.

Non-discrimination. You have the right to be free from discrimination related to your exercise of any of your California privacy rights.

Verification. In order to protect your personal information from unauthorized access or deletion, we may require you to verify your credentials before you can submit a rights request. If you do not have an account with us, or if we suspect that your account has suffered fraudulent or malicious activity, we may ask you to provide additional personal information for verification. For Credit Karma members, we may require that you confirm certain pieces of personal information that we have on file and/or log into your Credit Karma account. If we are subsequently unable to confirm your identity, we may refuse your rights request.

Authorized agents. You may use an authorized agent to submit a rights request. If you do so, the agent must present signed written authorization to act on your behalf, and you may also be required to independently verify your identity or your legal authority or ownership of the personal information with us.

Please note that we may claim legal exemptions for certain types of personal information from all or certain parts of the CCPA pursuant to various CCPA exemptions.

What you can do to manage your privacy

You have choices when it comes to managing the privacy of your personal information.

Update your privacy settings. You may update your privacy settings by visiting your account settings.

Manage marketing communications from us. To update your marketing communication preferences, you can go to the marketing preference tools in your account settings. You may also click unsubscribe at the bottom of the marketing e-mails.

Request a copy of your personal information. You may request a copy of your personal information by contacting Haven.

Correct your personal information. You can edit and correct your personal information at any time by changing it directly in our products and services.

Delete your personal information. You may request for us to delete your personal information by contacting Haven.

Cookies and other tracking technologies. You may be able to opt-out of interest based advertising by contacting Haven.

Your Right to Limit Information Sharing: You have the right to limit our sharing of your information to both affiliates and third-parties for marketing purposes. You may be able to limit our information sharing by contacting Haven.

How to Contact Us

If you have questions or comments about this Privacy Policy or our practices, please contact us.

You can submit Haven privacy questions by contacting Haven.

You can also contact us through the following country and regional channels.

United States

Haven Software LLC
7391 Oakland Hills Court
Indianapolis, Indiana  46236
Attention: Privacy

© 2021 Haven Software LLC