← Back to home

Privacy Policy

Last updated: July 16, 2026

Who we are

Firmside ("we," "us," or "our") operates the marketing website at firmside.co and the Firmside platform at app.firmside.co. This policy explains what data we collect, how we use it, and who we share it with.

What we collect

Account data: When you sign up, we collect your email address, name, and password (handled securely by Supabase Auth). You may also sign in with Google, in which case Google shares your email and name with us.

Firm and team data: We store your firm name, contact email, brand color, and optional logo. We also store email addresses and roles for team members you invite.

Client data: We store the names, industry, fiscal year settings, and financial data you upload or email for each client, including profit & loss and balance sheet records, account mappings, and budgets.

Inbound email data: If you use our email ingestion feature, financial report attachments sent to your Firmside inbound address pass through Postmark's servers before being stored in our database. Sender names, email addresses, and subject lines are also stored.

Billing data: We store references to your Stripe customer and subscription. Payment card details are handled entirely by Stripe and never touch our servers.

Marketing attribution: If you arrive via a referral link or campaign URL (for example, with `ref` or standard UTM parameters), we store that attribution information locally in your browser and associate it with your account when you sign up. We may also ask how you heard about us during firm setup; that answer is stored with your firm record.

Usage and analytics data: We use PostHog, a product-analytics tool, to understand how visitors use our marketing website and whether signup steps are completed. On the marketing site, PostHog is configured to keep its analytics identifier in memory only and not to use analytics cookies for tracking. We capture page views and intentional signup-related events (for example, clicks on “try free” and related calls to action). On the app, PostHog is limited to signup and account-setup pages (sign in, sign up, create your firm, and the OAuth callback); we do not use it to track the client hub, dashboards, or other product screens after setup. When you are on those signup/setup pages while signed in, we may link analytics events to your account using your user ID (not your email). Events we send may include page paths, event names (such as signup button clicks and firm-creation completion), basic device and browser information, marketing referral or UTM parameters when present, on firm creation a firm identifier, and, rarely, technical error codes from expected signup/setup failures (not error messages or financial data). We do not send client financial data to PostHog, only marketing and signup-funnel usage events. We do not use PostHog for advertising or cross-site tracking. We configure PostHog to anonymize IP addresses. PostHog may still use coarse location signals as part of analytics processing.

How we use your data

We use your data to operate the Firmside platform: provide client dashboards, process uploaded financials, send invitations, and manage your subscription. Separately, we use PostHog analytics on our marketing site and signup flow to understand traffic and whether signup steps are completed so we can improve them. We do not sell your personal information, share it for cross-context behavioral advertising, or use it for advertising.

Sale and sharing

We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising. Because we do not sell or share personal information in those ways, we do not offer a “Do Not Sell or Share My Personal Information” link.

Who we share data with

  • Supabase — our database and authentication provider. All account and client data is stored on Supabase infrastructure.
  • Stripe — our payment processor. We share your firm name and email when creating a billing account.
  • Postmark — our email delivery and inbound email provider. Invite emails and inbound financial attachments pass through Postmark.
  • Google — only if you choose Google OAuth to sign in.
  • PostHog — our product-analytics provider. We send marketing page views and signup-funnel events to PostHog, and on the app only events from signup and account-setup pages. For signed-in users on those setup pages, events may be linked to your account using your user ID (not your email). PostHog is configured to keep its analytics identifier in memory only and not to use analytics cookies for tracking, and we do not send it client financial data.

Cookies and local storage

We do not use advertising cookies or cross-site tracking cookies. We use your browser's local storage to maintain your session, remember basic UI preferences, and store marketing attribution parameters (such as referral source and UTM tags) until you complete signup. For product analytics we use PostHog, configured to keep its analytics identifier in memory only and not to use analytics cookies for tracking; outside the signup and setup pages it stores a local flag recording that analytics capture is switched off, which is a setting rather than an identifier. No data is shared with third parties for advertising purposes.

Your rights and data requests

If you want to cancel your subscription, you can do that yourself from the Billing section in your account settings, using the billing portal inside the app.

To request access to, correction of, or deletion of your personal information and account, contact us at support@firmside.co. We will respond within one week. We will not discriminate against you for exercising these rights.

You may use an authorized agent to submit a request on your behalf. The agent must provide proof that you authorized them to act for you, and we may still ask you to verify your identity directly.

California residents

If you are a California resident, you may have the right to know what personal information we collect, request a copy, ask us to correct inaccurate information, and ask us to delete personal information we hold about you, subject to legal exceptions.

In the preceding 12 months, we collected the following categories of personal information for business purposes:

  • Identifiers — such as name and email address (account, team, and billing contact data).
  • Commercial information — such as subscription tier and Stripe customer references.
  • Professional and client-related information — such as firm name, branding, and financial reports you upload or email for client dashboards.
  • Internet or other electronic network activity — session data, basic UI preference data, and marketing attribution data stored locally in your browser, plus product-analytics events (such as marketing page views and signup-funnel events) processed by PostHog. On signup and account-setup pages in the app, those events may be linked to your account using your user ID. PostHog is configured to keep its analytics identifier in memory only and not to use analytics cookies for tracking; we do not use advertising or cross-site tracking cookies.

We collect this information from you directly, from your use of the platform, from Google when you choose Google sign-in, and from our service providers (for example, Stripe for billing). We use it only to operate Firmside as described in this policy. We disclose it to our service providers listed above so they can help us run the platform. We do not sell or share personal information for cross-context behavioral advertising.

If you are a California resident and have questions about these rights, contact support@firmside.co.

Who the service is for

Firmside is intended for accounting firms operating in the United States.

Data processor notice

Firmside acts as a data processor on behalf of accounting firms and financial advisors who use our platform. If you are a client of a firm using Firmside and have questions about how your financial data is handled, please contact your advisor directly. We process that data solely on their instruction.

Children's privacy

Firmside is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal information, please contact us at support@firmside.co and we will delete it promptly.

Data security

All data is encrypted in transit and at rest. Access to client data is enforced by row-level security policies so users can only access data belonging to their own firm. Our infrastructure is hosted on Supabase, which is SOC 2 Type 2 certified. For more information on Supabase's security practices, see supabase.com/security.

Data retention

We retain your data for as long as your account is active. When you request deletion or your account is terminated, we delete or de-identify personal information within a reasonable period, except where we must retain limited information to comply with law, resolve disputes, or enforce our agreements (typically no longer than 90 days unless a longer period is required by law).

Changes to this policy

We may update this policy as the product evolves. We'll note the date of the last update at the top of this page.

Contact

support@firmside.co