1. Scope and Applicability
Prophit.ai currently offers ITMS for United States business use. This policy applies to visitors, prospective customers, customer administrators and users, API users, customer-authorized accounting or tax-service firm personnel, business contacts and prospects, career candidates, customer-designated certificate recipients and uploaders, and people whose information is included in data that a customer submits to ITMS. “Personal information” means information that identifies, relates to, describes, or can reasonably be linked with a person or household. It does not include information that applicable law treats as deidentified or publicly available.
For website, sales, account, and direct relationship information, Prophit.ai generally determines why and how the information is processed. For transaction files, invoices, exemption certificates, customer or vendor records, and other content submitted by or for a customer (“Customer Content”), the customer generally controls the processing and Prophit.ai acts as its service provider or processor. The customer’s agreement with Prophit.ai and the customer’s own privacy notice may also apply.
If your information appears in Customer Content but you do not have a direct Prophit.ai account, contact the organization that collected the information first. We will assist that organization with a verified request as required by law and contract.
2. Personal Information Collection
The information we collect depends on how you and your organization use Prophit.ai.
Account and identity. Name, business email, password hash, verification and password-reset status, login history, role, permissions, organization and location memberships, invitations, and account status.
Organization, onboarding, and billing. Company and legal names, domain, industry, business type, addresses, phone numbers, website, contacts, organization size, tax interests, states of operation, selected plan and modules, onboarding progress, trial dates and activity, subscription status, billing contacts, payment-method brand and last four digits, and payment-provider customer, payment-method, subscription, invoice, and event identifiers or records. Full payment card numbers and security codes are collected directly by the payment provider and are not stored by Prophit.ai.
Tax and business records. Transaction and line-item data; customer and vendor names, identifiers, business contact details, and addresses; products, SKUs, descriptions, amounts, tax, exemptions, nexus, registrations, tax account numbers, federal employer identification numbers, return data, reconciliation records, certificate recipient and signer names, titles, signature information, notification history, and filing-ready outputs.
Documents and files. Invoices, exemption certificates, tax forms, spreadsheets, PDFs, images, attachments, import archives, filenames, extracted text, document metadata, checksums, and generated artifacts.
Workflow and provenance. Source systems and provider object identifiers, import batches, raw snapshots, mappings, transformations, classifications, confidence scores, reason codes, calculations, AI or OCR provider and model metadata, reviewer comments, approvals, overrides, signoffs, status changes, audit events, timestamps, and error records.
Integrations and API. Connected-system account details, authorization tokens or credentials, sync cursors, webhook events and endpoints, API-key identifiers and prefixes, request metadata, transaction codes, response status, latency, and delivery history. Integration credentials and secrets are handled using security controls appropriate to the applicable connection and service.
AI assistant and automation content. Prompts, chat messages, files supplied for analysis, retrieved workspace context, extracted evidence, model responses, citations or source links, scoped conversation history, derived workspace memory, feedback, review decisions, and usage metadata for enabled AI-assisted features.
Sales, support, and feedback. Demo and career inquiry details, company and module interests, name, role or title, work email, support communications, feedback text, screenshots and diagnostic metadata when enabled, survey responses, outreach and email-engagement history, suppression or do-not-contact status, fit or product-interest inferences, and communications preferences. We may also collect business contact, company, and professional information from referrals, public sources, and business-data providers where permitted by law.
Device, usage, and analytics. IP address and server logs, browser and device information, pages and features used, event and route data, referring pages, timestamps, session or authentication information, and locally stored preferences such as active workspace, theme, tours, and layout.
We collect information directly from you, including through customer-created upload links; from customer administrators, customer-authorized professional-service firms, and other authorized users; from files, APIs, webhooks, and systems your organization connects; automatically when you use our services; from service providers and integration partners; and from referrals, public sources, and commercially available business-data sources.
Customer Content may incidentally contain information a customer considers sensitive. Do not submit Social Security numbers, personal financial account credentials, health information, consumer payment card data, or government-portal passwords unless a specific Prophit.ai feature and your agreement expressly require and authorize it.
3. Employment Inquiries
If you contact us through the Prophit.ai Careers page or otherwise inquire about employment opportunities, we may collect your name, company, work email, and the information you include in your message. We use this information to review and respond to your inquiry, communicate with you about potential opportunities, and maintain related business records. Please do not include Social Security numbers, financial account information, health information, or other sensitive personal information in a free-text message unless we specifically request it.
4. Account Registration and Administration
During onboarding, we use account verification, intake responses, plan selection, organization and location setup, module choices, billing steps, and progress metadata to create and configure a workspace. Setup is saved as users advance so they can resume. We may send verification, welcome, password-reset, billing, trial, service, and lifecycle messages.
We track trial activation, use, expiration, payment grace periods, conversion, cancellation, entitlement changes, and related administrative events to operate the customer relationship. Abandoned or expired provisional workspaces may be deactivated and cleaned up after configured recovery periods. A user record may remain discoverable to authorized administrators for recovery, security, audit, or duplicate-account prevention even after provisional workspace access is removed.
Customer administrators control user invitations, organization and location membership, roles, module access, and certain workspace settings. A customer may authorize an accounting, tax, or compliance firm and its permitted personnel to access and act within the customer's workspace. Authorized Prophit.ai operators may manage accounts and entitlements and record those actions in administrative audit logs.
5. Records and Audit Trails
ITMS is designed to preserve traceability. Alongside business records, the platform may retain the originating system, provider and object identifiers, import and retrieval time, file checksum, raw or normalized snapshots, transformation steps, calculation sources, model or OCR metadata, confidence and reason codes, manual edits, review actions, approvals, exports, filing artifacts, and lifecycle status.
We use these records to explain results, support customer review, reproduce or correct processing, prevent duplicate imports, preserve evidence, enforce access and lifecycle rules, troubleshoot errors, and maintain defensible audit trails. Because provenance can be part of a customer’s tax, accounting, security, or contractual record, deactivating or deleting an individual user does not necessarily delete the business records or audit history associated with that user’s actions. Where appropriate, identifiers may be removed, tombstoned, or separated while the underlying business history remains.
6. Purposes for Processing Personal Information
- Provide, configure, and administer the website, ITMS workspaces, modules, APIs, and integrations.
- Import, normalize, validate, calculate, classify, reconcile, extract, link, review, generate, and export customer-requested tax and business records.
- Authenticate users; verify email; manage roles, scopes, entitlements, sessions, and account access.
- Manage onboarding, trials, subscriptions, billing, usage limits, renewals, and customer support.
- Send transactional messages and respond to demos, support, feedback, and other requests.
- Monitor performance, measure website and feature use, troubleshoot, test, and improve our services.
- Protect customers and Prophit.ai; detect abuse, fraud, security incidents, and policy violations; and preserve auditability and system integrity.
- Comply with law, enforce agreements, establish or defend legal claims, and complete transactions.
- Develop business relationships and send business-to-business marketing where permitted. You can opt out of promotional email at any time; service messages may continue while an account is active.
7. Automated Processing and Artificial Intelligence
When enabled, ITMS uses optical character recognition, large language models, and related automation to extract document text, map columns, suggest classifications, summarize or analyze tax information, assist research, triage feedback, and support other requested workflows. Relevant portions of Customer Content and prompts may be processed by third-party AI, OCR, cloud infrastructure, or data-processing providers as needed to provide an enabled feature.
We may store inputs, outputs, evidence, confidence, provider/model metadata, reviewer decisions, and usage information to deliver the feature and preserve provenance. AI-assisted results can be incomplete or inaccurate and are designed for review by authorized users. They are not legal advice and do not replace the customer’s professional judgment or required approval and filing controls.
ITMS uses Customer Content with configured AI providers to perform requested features and does not include a workflow for training a Prophit.ai general-purpose model on Customer Content. A provider's retention or use of submitted content is controlled by the applicable customer agreement, feature configuration, and provider terms and settings. Contact us for the providers and controls applicable to your organization's deployment.
8. Disclosure of Personal Information
We may disclose information to the following recipients for the purposes described in this policy:
- Your organization and authorized users. Workspace content, activity, roles, and records are available according to organization, location, and administrator permissions.
- Customer-authorized professional-service firms. A customer's accounting, tax, or compliance firm and its permitted personnel may access and act within client workspaces according to the applicable engagement, role, and access settings.
- Infrastructure and service providers. Hosting, database, storage, security, observability, email, customer support, issue tracking, software development, content delivery, and backup providers process information for us. Feedback, diagnostics, and optional screenshots may be processed by providers that help us investigate and resolve product issues.
- AI, OCR, and data-processing providers. Providers process selected content when an enabled feature requires extraction, classification, address validation, or analysis.
- Billing and analytics providers. Payment providers such as Stripe process checkout and subscription information. Analytics providers may process website and application route, interaction, conversion, and device data when configured.
- Business operations providers. Sales-intelligence, CRM, communications, advertising, recruiting, and research providers may process business contact, career inquiry, prospecting, outreach, campaign, and engagement information for Prophit.ai's business operations.
- Customer-directed integrations. We exchange information with systems a customer connects or directs us to use, such as accounting platforms, webhooks, API endpoints, tax-content or address providers, and other customer-designated recipients. Customers may also direct us to send certificate links, notices, documents, or filings to customers, vendors, signers, advisers, and authorities.
- Browser-delivered services. Fonts, content-delivery networks, mapping or address autocomplete, analytics, and similar resources may receive device, network, page, or address- interaction information when your browser loads or uses them.
- Professional advisers and authorities. We may disclose information to auditors, insurers, lawyers, accountants, regulators, courts, law enforcement, or other parties when reasonably necessary to comply with law, protect rights and safety, or establish or defend claims.
- Corporate transactions. Information may be disclosed in connection with financing, due diligence, a merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate protections.
We may disclose aggregated or deidentified information that cannot reasonably identify a person. We do not disclose Customer Content for unrelated third-party advertising.
10. Data Retention and Deletion
We retain information for the time reasonably necessary to provide the services, maintain the customer relationship, follow customer instructions, preserve provenance and tax or business records, meet security and operational needs, enforce agreements, and comply with legal obligations. The period depends on the type of information, the sensitivity and purpose of processing, customer configuration and contract, legal limitation periods, and whether the information is needed for an unresolved issue.
- Account and onboarding records are generally retained while the account or customer relationship is active and for a period afterward based on security, support, contractual, and legal needs.
- Customer Content is retained according to the customer relationship and instructions, but tax, accounting, filing, provenance, audit, security, and billing records may require longer retention.
- Technical logs, telemetry, temporary processing records, and similar operational information are retained for periods appropriate to security, service delivery, troubleshooting, and legal needs.
- Information may remain in backups or disaster-recovery systems for a limited period after it is removed from active systems and is deleted or overwritten through ordinary recovery processes.
Account archiving removes live access and may replace active identifiers while preserving restricted history. Permanent deletion can be delayed or unavailable when durable customer records still reference the account. We may retain information subject to a legal hold or other exception permitted by law.
11. Information Security
We use administrative, technical, and organizational safeguards designed for the nature of the information we process, including access controls, authentication measures, restricted administrative functions, audit records, and protections for supported credentials and stored information. No security measure or transmission method is completely secure, and we cannot guarantee absolute security.
Protect your device, use a unique password, clear site data after using a shared device, limit user and integration permissions, and notify us promptly if you suspect unauthorized access. Do not send passwords, API keys, payment card details, or other secrets through support email or free-text fields.
12. Privacy Rights and Requests
Depending on your location and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information; to learn about collection and disclosure; to opt out of certain sale, sharing, targeted advertising, or profiling; to limit certain uses of sensitive personal information; and to appeal a denied request. You may also opt out of promotional email without affecting service messages.
Submit a request to support@prophit.ai with “Privacy Request” in the subject line. Describe the right you want to exercise and your relationship with Prophit.ai. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted, but we may require proof of authorization and direct verification. We will not discriminate against you for exercising a privacy right. Where applicable law specifies a deadline, we generally respond within 45 days and will notify you if a permitted extension is needed.
If your request concerns Customer Content, we may direct it to the relevant customer or ask for the organization and workspace needed to locate the information. Rights may not apply to information about a legal entity, deidentified information, or particular information that an applicable statutory exception permits or requires us to retain. Business records that identify an individual are not excluded solely because they relate to a business relationship.
To appeal a denied request, email support@prophit.ai with “Privacy Appeal” in the subject line and explain why you believe the decision should be reconsidered. We will respond within the period required by applicable law. If an appeal is denied, our response will explain any further complaint method required by your state, including how to contact the appropriate state attorney general where applicable.
13. Supplemental U.S. State Privacy Disclosures
The following summarizes categories Prophit.ai may have collected during the preceding 12 months. The examples, sources, purposes, recipients, and retention criteria are described more fully in Sections 2, 6, 8, and 10.
Identifiers and customer-record information. This includes names, work email, account and provider IDs, IP address, contact details, signatures, tax account numbers, and similar records received directly, from customers or integrations, automatically, or from public and commercial business sources. We use this information for account administration, requested tax workflows, billing, security, support, and business operations, and disclose it as needed to authorized organizations, professional-service firms, customer-directed recipients, and service providers.
Commercial, professional, and employment-related information. This includes company, role or title, products and services, transactions, subscriptions, career inquiries, professional history, outreach, and engagement information from direct interactions, customers, integrations, referrals, public sources, and business-data providers. We use it to deliver and bill for ITMS, provide support, recruit, develop business relationships, and conduct B2B marketing.
Internet or electronic network activity and approximate location. This includes IP-derived or postal location, browser and device data, routes, features, events, referrals, session information, and logs collected automatically from the website, application, APIs, and browser-delivered services. We use it for authentication, security, service delivery, diagnostics, analytics, and conversion measurement.
Visual, sensory, document, and signature information. This includes uploaded images and documents, optional feedback screenshots, extracted text, certificate signatures, and related metadata provided by users, customers, upload-link recipients, or connected systems. We use it for requested document, certificate, OCR, support, and audit workflows.
Inferences. This includes workflow classifications, confidence scores, tax or product suggestions, prospect fit, and product-interest inferences generated from Customer Content, product use, or business data. We use it for requested tax automation, review and provenance, service improvement, and business relationship development.
Sensitive personal information. This includes account login credentials and sensitive identifiers or records that a customer includes in Customer Content. Prophit.ai does not request consumer-sensitive content except where a specific feature and agreement authorize it. We use this information for authentication, security, and the customer-requested service, and do not knowingly use or disclose it to infer unrelated personal characteristics.
We do not sell personal information for money and do not offer financial incentives in exchange for personal information. When configured, we disclose identifiers and internet or electronic network activity to analytics providers for website and application analytics. Depending on the applicable law, provider configuration, and contract, that disclosure may be treated as sale, sharing, or targeted advertising. We do not disclose Customer Content for unrelated cross-context behavioral advertising and do not knowingly sell or share the personal information of people under 16. Contact us to exercise an applicable opt-out or limitation right.
14. Children’s Privacy
Prophit.ai is a business-to-business service and is not directed to children under 18. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us so that we can investigate and take appropriate action.
15. Third-Party Websites and Services
Our website and services may contain links to third-party websites, applications, plug-ins, or services. This Privacy Policy does not apply to the privacy practices of those third parties, and Prophit.ai is not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party website or service you use.
16. Changes to This Privacy Policy
We may update this policy to reflect changes in our services, practices, providers, or legal obligations. We will post the revised policy with a new “last updated” date and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
17. Contact Information
Questions, complaints, and privacy requests may be sent to:
Prophit.ai, Inc.Email: support@prophit.ai
For product documentation, see the Prophit.ai documentation library.
