Back to homePrivacy
Privacy policy
Last updated: 15 May 2026
Controller and contact
TaxLi provides the TaxLi product. Registered business name, company number, VAT status and trading address must be confirmed before live customer payments — update src/config/company.ts. Privacy requests can be sent to support@taxli.co.uk.
Information TaxLi collects
TaxLi may collect account details, contact details, Self Assessment return data, tax-year selections, income source selections, uploaded documents, support messages, review requests, payment metadata and technical usage information needed to run and protect the service.
How we use it
We use your information to provide the preparation workspace, save your draft return, calculate draft estimates, generate return packs, handle support, manage review requests, improve reliability and keep the service secure.
Lawful basis to confirm
Before launch, TaxLi should confirm and document the final lawful bases for each processing purpose. The working position is that core account, return workspace, return pack, support and billing processing is mainly needed to provide the service, meet legal obligations, keep the service secure, and handle customer requests. Final legal/privacy review is still required.
HMRC and filing
Launch 1 does not directly submit your return to HMRC. If HMRC connection features are enabled in a later launch, token handling and consent wording must be reviewed before production use.
Documents and return data
Self Assessment data can include sensitive financial information. Access should be limited to you, authorised support/admin users, and any accountant review workflow you request.
Payments
When live payments are enabled, payment details should be processed by the payment provider. TaxLi should store only the minimum payment metadata needed for access, receipts, refunds and support.
Cookies and browser storage
TaxLi uses essential browser storage for sign-in, security, tax-year preference, onboarding drafts and app reliability. Analytics or advertising cookies should not be enabled until cookie consent and privacy wording are production-ready.
Hosting and processors
TaxLi stores core application data in Google Cloud services configured for the europe-west2 (London) region. Payment processing is provided by Stripe. Email notifications are provided by Resend. Final production hosting and data processor evidence should be reviewed before launch.
Retention and deletion
Return data should be retained only for as long as needed to provide the service, meet legal obligations, resolve support issues and preserve records you ask us to keep. You can ask us to delete a tax year, close an account, or export personal data. Some limited payment, fraud-prevention, support or legal records may need to be retained where required or justified.
Your rights
UK users may have rights to access, correct, delete, restrict or export personal data, object to certain processing, and withdraw consent where consent is used. Contact support@taxli.co.uk or raise an in-app support ticket for privacy requests. We may need to verify your identity before exporting or deleting sensitive tax data.
Data exports and deletion requests
For Launch 1, privacy requests are handled manually through support. Include your account email, the tax year affected, the request type, and whether you want account data, return data, support messages, review requests, or billing metadata included. Do not send UTR or National Insurance numbers by email unless support specifically asks through a safe route.
Legal review
This privacy policy is a Launch 1 working version and must be reviewed against the final production hosting, analytics, support, payment, processor and data retention setup before accepting real customer payments.
TaxLi Launch 1 is preparation software, not direct HMRC filing software.