1. Controller and contact details
The controller responsible for the processing described in this policy is:
TaxRouter UG (haftungsbeschränkt)
Lange Reihe 14
20099 Hamburg
Germany
Email: info@taxrouter.com
Managing Director: Marius Glauer Privacy contact: info@taxrouter.com
2. Scope
This policy explains how we process personal data when you visit the TaxRouter website, create or use an account, use a TaxRouter workspace, connect a supported marketplace or accounting integration, contact us, or otherwise interact with our services.
TaxRouter is intended for business customers and tax professionals. A customer may act as controller for personal data uploaded or synchronized into its workspace. Where TaxRouter processes that data solely on the customer's documented instructions, the separate Data Processing Addendum applies.
3. Categories of data
Depending on how you use the service, we may process:
- account and identity data, such as name, business email address, authentication information, roles, and multi-factor authentication status;
- organization and contract data, such as business name, address, billing details, subscription, contract records, and acceptance evidence;
- marketplace, tax, and accounting data authorized by the customer, including transaction, settlement, order, shipment, invoice, VAT, and reconciliation information;
- integration data, such as connection identifiers, authorization status, scopes, synchronization history, and error information;
- support and communication data, including messages, attachments, and contact requests;
- usage, device, and security data, such as IP address, timestamps, browser information, audit events, and security logs; and
- payment-related data received from payment providers. TaxRouter does not intend to store full payment-card details.
We obtain data from you, your organization, authorized users, integrations you connect, service providers, and automatically from the website and application. Where Article 14 GDPR applies because data was not obtained directly from you, the source is ordinarily your organization, an authorized user, or an integration connected by the customer. The categories, purposes, and legal bases are described in this policy. We provide the required information within the statutory period, at the latest at first communication or first disclosure where applicable, unless a statutory exception applies.
4. Purposes and legal bases
We process personal data to:
- provide accounts, workspaces, integrations, synchronization, reconciliation, exports, support, and other contracted functions (Article 6(1)(b) GDPR where the data subject is the contracting individual; otherwise Article 6(1)(f) GDPR based on our and the Customer's legitimate interests in administering and performing the business contract);
- take steps requested before entering into a contract (Article 6(1)(b) GDPR);
- invoice customers, keep legally required records, respond to authorities, and comply with tax, commercial, and data-protection obligations (Article 6(1)(c) GDPR);
- secure the service, prevent abuse, troubleshoot errors, maintain audit trails, and improve reliable operation (Article 6(1)(f) GDPR; our legitimate interests are service security, integrity, and efficient operation);
- communicate with business contacts about the service and respond to enquiries (Article 6(1)(b) or (f) GDPR, depending on the context); and
- send optional communications or use optional technologies where consent is required (Article 6(1)(a) GDPR and applicable telecommunications law). Consent may be withdrawn at any time with effect for the future.
5. Website technologies
We currently use only technologies necessary to provide the requested service:
- authentication and session cookies, including temporary OAuth state cookies, for secure sign-in and integration authorization;
- a locale cookie for language selection and a last-organization cookie for restoring workspace context, each retained for up to one year; and
- temporary browser session storage for invitation and post-authentication redirects, which is cleared with the browser session or after the redirect is completed.
TaxRouter does not currently use optional analytics or marketing cookies on the website or application. If this changes, we will update this policy and obtain consent where required.
6. Marketplace and integration data
When an authorized user connects Amazon Seller Central or another supported integration, we process only the data made available within the granted authorization and needed for the enabled TaxRouter workflow. We do not use marketplace data for advertising, resale, unrelated profiling, or direct-to-consumer fulfilment operations.
Customers are responsible for ensuring that they are authorized to connect an account and instruct TaxRouter to process the data. Integration providers may process personal data independently under their own terms and privacy policies.
7. Recipients and subprocessors
Personal data may be available to authorized users of your organization, TaxRouter personnel who require access for their duties, professional advisers, public authorities where legally required, and service providers used to operate TaxRouter. Service providers acting as processors are contractually bound to appropriate data-protection and confidentiality obligations.
The current approved Subprocessor List identifies our processors: Vercel for hosting, serverless delivery, logs, and object storage; PlanetScale for the production PostgreSQL database and backups; and Resend (Plus Five Five, Inc.) for authentication, account, support, and service emails.
Payment providers and connected marketplace or accounting platforms generally process data as independent controllers or customer-directed recipients under their own terms. They are not TaxRouter subprocessors merely because data is exchanged with their services.
8. International transfers
Production hosting, object storage, and database processing are configured for Frankfurt. Vercel and PlanetScale may use limited support or subprocessor access outside the EEA; such transfers are protected by applicable standard contractual clauses or another valid safeguard. TaxRouter emails sent through Resend are dispatched from Ireland using the eu-west-1 region. Resend's primary processing operations and the storage of account data, email metadata, logs, and API records take place in the United States on the basis of the EU-U.S. Data Privacy Framework where applicable and standard contractual clauses. Information or a copy of the applicable safeguards may be requested at info@taxrouter.com, subject to lawful confidentiality restrictions.
9. Retention and deletion
We retain account, workspace, integration, and contract-operational data for the term of the customer relationship and as needed to provide the service. After termination, customers have 30 days to export their data; production copies are then deleted within the following 30 days and restricted backup copies expire within 90 days, unless a legal retention duty applies.
Commercial and tax records are retained for the applicable statutory period: generally ten years for books and certain tax records, eight years for invoices and accounting vouchers, and six years for commercial correspondence and other records. Support and contact records are ordinarily retained for up to three years after the matter is closed unless they remain necessary for a contract or legal claim. Security logs are ordinarily retained for up to twelve months unless a longer period is required for an investigation or by law.
Amazon customer personally identifiable information and source records required to calculate or remit taxes, produce tax invoices, substantiate accounting records, or meet another documented legal obligation are retained for the applicable statutory period. These records remain tenant-scoped, access-restricted, and are used only for the documented legal purpose. Other Amazon data follows the retention period applicable to its purpose and any customer instructions consistent with law. Data is deleted or placed into a compliant restricted archive when the applicable period expires.
10. Security
We maintain technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. Further information is contained in the approved Security Overview and Technical and Organizational Measures.
11. Your rights
Subject to the legal requirements, you may have rights to access, rectification, erasure, restriction, data portability, and objection. Where processing is based on consent, you may withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority. The supervisory authority responsible for our Hamburg establishment is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany; datenschutz-hamburg.de.
To exercise a right, contact info@taxrouter.com. We may need information to verify your identity and authority to make the request.
12. Obligation to provide data and automated decisions
Data marked as required is necessary to create an account, enter into or perform the contract, secure the service, or comply with legal obligations. Without it, we may be unable to provide the relevant function.
TaxRouter does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for individuals.
13. Changes to this policy
We may update this policy when our processing or legal obligations change. The published version will show its effective date. Where required, we will provide additional notice before a material change takes effect.