TaxBasis AI Privacy Notice

Last updated June 10, 2026

Sonnet Money Inc. (“Sonnet Money,” “we,” “us,” or “our”) is committed to protecting the privacy and confidentiality of your personal information. This Privacy Notice explains how we collect, use, process, and disclose personal information on our website and in connection with our services, including the TaxBasis platform available at https://www.taxbasis.ai (collectively, the “Services”).

We comply with the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) (which governs our processing of personal information for users in Ontario and other Canadian provinces), the British Columbia Personal Information Protection Act (PIPA), Quebec's Law 25, the California Consumer Privacy Act (CCPA/CPRA), and other applicable regional privacy laws.

1. PERSONAL INFORMATION WE COLLECT

We collect personal information directly from you, automatically through your interaction with the Services, and from third-party sources.

A. Personal Information You Provide Directly

B. Personal Information Collected Automatically

IP address, operating system, browser type, device type, user settings, click patterns, pages visited, search queries, session duration, and cookies. We use essential cookies to maintain secure sessions.

C. Personal Information from Third-Party Sources

Tax professionals using our platform may upload documents and information on behalf of their clients to generate client summaries. We process this data strictly as a data processor on behalf of the professional customer.

2. HOW WE USE PERSONAL INFORMATION

We use personal information to operate, optimize, answer tax questions, process payments, and prevent fraud. We do NOT sell, rent, or distribute your document data or chat history to train public AI models. Any analysis is confidential.

3. HOW WE DISCLOSE & SUBPROCESS PERSONAL INFORMATION

We share your information only under the following limited circumstances: to confidential service providers supporting hosting and billing, and to third-party API subprocessors.

Third-Party API Subprocessors: We securely transmit query text and chat history to third-party LLM subprocessors solely for answering your tax questions. We do not sell or store your files or chat history for model training. Documents uploaded for OCR are processed locally on our secure servers without transmission to third-party OCR APIs.

4. REGULATORY RIGHTS & YOUR PRIVACY CHOICES

5. DATA SECURITY & RETENTION

Security Disclaimer: We implement administrative, technical, and physical safeguards designed to secure your data. However, no data transmission over the Internet or cloud hosting system is 100% secure. You upload documents and transfer data at your own sole risk.

We retain your personal information and uploaded document data only for as long as your account is active, or as needed to populate your workspace calculations. Document files uploaded to the workspace can be deleted by you at any time. Upon account termination, we delete all associated personal information and files, subject to regulatory retention obligations.

6. CHILDREN'S INFORMATION

The Services are not directed to children under 16, and we do not knowingly collect personal information from children.

7. CONTACT US

If you have any questions or wish to exercise your rights under this Privacy Notice, please contact us at: [email protected].