Privacy Policy
Last updated: July 4, 2026
Rumo, Inc. ("Rumo") provides a practice operating system for accounting firms. This policy explains what information we collect, how we use it, and the choices you have. It applies to Rumo's marketing site, web application, and client portal (collectively the "Service").
What data we collect
- Account information — name, email, phone, role, firm name, and authentication credentials, including MFA enrollment data.
- Customer content — clients, engagements, tasks, documents, invoices, and messages that firm users and their invited clients submit to the workspace.
- Client tax documents — W-2s, 1099s, K-1s, prior-year returns, and similar records that clients upload through the portal or that firm staff import on their behalf.
- Usage information — log data, device and browser identifiers, IP address, timestamps, and product analytics needed to operate and secure the Service.
- Support information — messages, screenshots, and diagnostic context you send when requesting help.
- Payment information — handled by our payment processor; Rumo does not store full card numbers.
How we use data
- To operate, secure, and improve the Service the customer signed up for.
- To communicate about accounts, product changes, billing, and security events.
- To meet legal obligations, including GLBA Safeguards Rule expectations, and to respond to lawful requests from regulators.
- To prevent abuse, investigate suspected violations, and enforce our Terms.
We do not sell personal information. We do not use customer content to train third-party generative AI models.
Customer tax document handling
Tax documents are treated as sensitive customer content. They are stored encrypted at rest, transmitted over TLS, scoped to a single firm's workspace, and accessible only to firm users the customer has authorized and to the client contacts the firm has invited to the portal. Access to individual documents is logged in the audit trail so firms can review who opened what, and when.
Security safeguards
We use encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, mandatory MFA for administrative roles, encrypted backups in a separate region, and continuous infrastructure monitoring with alerting for anomalous activity. For a fuller summary see our Security overview.
Data retention
Customer content is retained for the life of the subscription and a short reasonable period afterward for backup and dispute resolution (currently up to 30 days after account closure). Audit-log records are retained for seven years to support IRS Pub 4557 and firm compliance obligations. Log data used for security investigations is typically retained no longer than 12 months unless required by law or by an active investigation.
Data deletion and access requests
Firm administrators can update or delete most account and client data directly from the app. To request export, correction, or deletion outside the product, email privacy@rumopro.com from an address associated with the account. We verify identity before acting on requests and respond within 30 days.
Client portal users should direct requests concerning their tax data to the firm that invited them; Rumo will cooperate with the firm as a data processor.
Subprocessors
We share data only with vendors we contract to help run the Service (cloud hosting, database, object storage, email delivery, payment processing, error monitoring, and similar). We require each subprocessor to protect data at least to the same standard we do. A current subprocessor list is available on request at privacy@rumopro.com. During the pilot we publish updates by email at least 30 days before onboarding a new material subprocessor.
California (CCPA/CPRA) and other U.S. state privacy laws
Depending on where you live, you may have rights to know, access, correct, delete, and limit the use of certain personal information, and to opt out of "sales" or certain "sharing" as those terms are defined by applicable state law. Rumo does not sell personal information and does not share it for cross-context behavioral advertising. To exercise state privacy rights, contact privacy@rumopro.com. We will not discriminate against you for exercising your rights.
International users (GDPR and equivalents)
Rumo operates from the United States and stores customer content in U.S. data centers. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States. Where the GDPR or a similar framework applies, Rumo acts as a data processor for Customer Data on behalf of the firm that engages it, and as a data controller for account and marketing data. A data processing addendum is available on request.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced by email or in-app notice at least 15 days before they take effect.
Contact
Privacy questions: privacy@rumopro.com.
Support: support@rumopro.com.
This pilot version is provided for transparency during early customer evaluations and is subject to attorney review before general availability. It is not a substitute for legal advice.