This Privacy Policy explains how AskAccountant collects, uses, stores, shares, and protects personal information when you use our marketplace platform. It applies to clients, accounting professionals, administrators, and visitors who interact with AskAccountant services in the Philippines.
1.Scope and Controller
AskAccountant operates a professional services marketplace that connects clients with independent accounting professionals. This Privacy Policy applies to information collected through our website, authenticated workspaces, consultation rooms, messaging tools, payment flows, optional calendar integrations, and related support channels.
For privacy inquiries or requests relating to this Policy, contact us using the details in the Contact section below.
2.Information We Collect
We collect information you provide directly, information generated through your use of the Platform, and information received from service providers that help us operate the Platform.
- Account and identity information such as name, email address, phone number, password hash, role, authentication method, email verification status, and sign-in activity.
- Profile information such as business name, business type, TIN, professional biography, credentials, license numbers, accreditation details, rates, availability, languages, location, and profile media.
- Booking and consultation information such as selected services, schedule, attendance events, consultation chat, video room participation metadata, reviews, no-show records, rescheduling history, and support tickets related to bookings.
- Service request and engagement information such as proposals, milestones, progress updates, invoices, payment status, completion acceptance, dispute window actions, dispute submissions, and uploaded deliverables.
- Communication and document data such as in-platform messages, files uploaded to engagements or document vaults, and metadata associated with those files.
- Automated moderation records such as blocked-message indicators, policy violation categories, confidence scores, and limited message previews retained for administrator review.
- Payment and finance information such as transaction amounts, invoice references, refund records, payout entitlement ledger entries, payout batch references, platform fee snapshots, and PayMongo payment references. Full payment card details are processed by PayMongo and are not stored by AskAccountant in plain form.
- Verification and compliance information submitted for CPA, BOA, BIR, SEC, or other credential review.
- Technical and usage information such as device type, browser, IP address, log events, session identifiers, audit log metadata, and security-related activity.
- Optional push notification subscription data such as device endpoint, browser, operating system, and encryption keys used to deliver web push alerts.
- Marketing contact form submissions such as name, email, message content, IP address, and user agent.
- Google account profile information such as name, email address, and profile image when you choose Google sign-in.
- If you connect Google Calendar, Google account and authorization information such as your Google account identifier and email address, granted OAuth scopes, encrypted access and refresh tokens, token expiration, connection status, and synchronization or webhook metadata.
- Connected-calendar information such as calendar identifiers, display names, time zones, access roles, primary-calendar status, and your choices about which calendars should be checked for conflicts and which writable calendar should receive AskAccountant booking events.
- External calendar scheduling metadata from calendars you select for conflict checking, including provider event identifiers, start and end times, time zone, all-day, recurring-event and original-start indicators, busy or free status, cancellation status, and provider update time. AskAccountant does not intentionally store the titles, descriptions, locations, attendee identities, attachments, or other content of your unrelated external calendar events for conflict checking.
- Calendar export records linking an AskAccountant booking to the event created in your selected external calendar, including provider event identifiers, synchronization status, version, timestamps, and error information.
3.How We Use Information
- Create and manage user accounts, profiles, and authenticated sessions.
- When you choose Google sign-in, use the name, email address, and profile image Google provides to create or locate your AskAccountant account, authenticate you, populate your account profile, and treat the Google-provided email address as verified.
- Facilitate discovery, bookings, consultations, proposals, invoices, payments, payouts, and service engagements.
- Send transactional notifications such as booking confirmations, reminders, payment updates, dispute notices, and account messages.
- Verify accountant credentials, publish listings, and enforce marketplace policies.
- Provide customer support, investigate issues, and resolve eligible platform disputes.
- Maintain financial, audit, and operational records required for platform administration.
- Detect, prevent, and respond to fraud, abuse, security incidents, and policy violations.
- Improve platform performance, reliability, and user experience.
- List the calendars available in a connected account, check selected calendars for scheduling conflicts, prevent overlapping bookings, and display consolidated availability.
- Create, update, or cancel AskAccountant booking events in the writable calendar you select and keep those events synchronized with booking changes.
- Maintain and troubleshoot calendar authorization, incremental synchronization, and provider webhook notifications.
- Comply with legal obligations and respond to lawful requests from authorities.
5.Service Providers and Storage
AskAccountant uses third-party providers for hosting, database storage, email delivery, optional Google sign-in and Google Calendar integration, secure file storage, PayMongo payment processing, Daily.co video consultation rooms, and optional web push delivery.
Uploaded documents and files may be stored in Cloudflare R2 or similar secure object storage with access controls and presigned upload flows. Application data is stored in MongoDB or equivalent managed database infrastructure. Public profile or article assets may be served through configured public storage URLs where applicable.
Transactional email may be sent through Resend, SMTP, or another configured email provider. These providers process information on our behalf according to their own terms and security practices.
We require appropriate safeguards for operational providers handling personal data on our behalf.
6.Google Sign-In
Google sign-in is optional. When you choose it, Google provides AskAccountant with basic Google account information that you authorize, such as your name, email address, profile image, and a Google account identifier used during authentication. AskAccountant uses this information to create or locate your local account, sign you in, populate your profile, and treat the Google-provided email address as verified. Google does not provide your Google password to AskAccountant.
Google sign-in is separate from the optional Google Calendar integration. Using Google sign-in alone does not give AskAccountant permission to access your Gmail, Google Drive, Google Calendar, contacts, or other Google services. Any additional Google Calendar access is requested separately through a distinct authorization flow and permission screen.
The name, email address, and profile image received through Google sign-in may be retained as part of your AskAccountant account for as long as described in the Retention section. Removing AskAccountant from your Google Account may prevent future Google sign-in, but it does not automatically delete your local AskAccountant account or records. You may request or initiate deletion of your AskAccountant account through the methods described in this Policy.
Google processes authentication information under its own privacy policy, terms, and account controls.
7.Google Calendar Integration
Connecting Google Calendar is optional. If you choose to connect it, Google presents the permissions requested by AskAccountant and you authorize Google to provide the associated data and calendar-management access. The current integration requests basic account identification and Google Calendar access that permits the Platform to view calendars and events and to create, update, or cancel events.
AskAccountant uses this access only to provide user-facing calendar features: listing calendars, checking selected calendars for busy times, preventing scheduling conflicts, synchronizing availability, and writing AskAccountant booking events to the calendar you select. We do not use Google Calendar data for advertising, marketing profiles, credit decisions, or unrelated analytics, and we do not sell it.
For external events that were not created by AskAccountant, the Platform is designed to retain only the limited scheduling metadata needed for conflict detection, rather than event titles, descriptions, locations, attendee identities, attachments, or unrelated event content. AskAccountant booking events written to Google may include the consultation label, the other participant's display name, booking reference, scheduled time, and a link back to the relevant booking page.
Synchronization may occur when you connect or save preferences, when availability is checked, through scheduled reconciliation, or after Google sends a calendar change notification. Google webhook notifications identify the connected synchronization channel and prompt AskAccountant to retrieve updated scheduling metadata; they do not contain the full calendar event content.
You may change which calendars are used for conflict checking and which writable calendar receives AskAccountant booking events from calendar settings. You may also disconnect the integration through the Platform or remove AskAccountant's access through your Google Account.
When you disconnect through AskAccountant, we revoke available Google authorization credentials, stop future synchronization, and delete the external event timing records associated with the connection. We may retain limited connection history, calendar preferences, booking-event links, synchronization status, and security or audit records where reasonably necessary for troubleshooting, recordkeeping, fraud prevention, or legal compliance.
Disconnecting AskAccountant or revoking Google access does not necessarily delete AskAccountant booking events already written to Google Calendar. You may delete those events directly in Google Calendar. Removing access through Google may also prevent AskAccountant from deleting or updating events it previously created.
Google processes information under its own privacy policy and account controls. Your use of Google Calendar remains subject to Google's terms and policies.
Google API Limited Use
AskAccountant's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8.Data Security
We implement administrative, technical, and organizational measures designed to protect personal information, including access controls, hashed credentials, secure transport, and restricted administrative access.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to reduce risk and respond to incidents affecting Platform data.
9.Retention
We retain personal information for as long as your account is active, as needed to provide the Platform, and as required to resolve disputes, maintain financial records, enforce our Terms, or comply with applicable law.
Google sign-in profile information retained in your local AskAccountant account, such as your name, email address, and profile image, follows the same account-retention and deletion practices as comparable information supplied directly to AskAccountant.
Booking records, invoices, payment records, ledger entries, payout batch records, dispute records, moderation logs, audit logs, and finance snapshots may be retained for longer periods where necessary for accounting, tax, fraud prevention, or legal compliance.
Calendar authorization credentials are retained while the integration is connected and are encrypted at rest. External calendar event timing records are retained while needed to provide synchronization and conflict checking and are deleted when the calendar connection is disconnected through the Platform. Limited connection, preference, booking-link, synchronization, security, or audit records may be retained where reasonably necessary for legitimate business or legal purposes.
You may delete your account from client or accountant settings. Account deletion requests anonymize your profile and sign you out. Deleting an account does not automatically delete all records where retention is required by law or legitimate business need, including financial, dispute, and audit records tied to completed transactions. You may also contact us at the email address below for privacy requests.
10.Consultations, Messaging, and Documents
Consultations may be conducted through Daily.co video consultation infrastructure and supported by in-platform chat and attendance tracking.
Messages, consultation metadata, attendance events, and documents shared through the Platform may be stored so that users can continue engagements and so AskAccountant can provide support or review eligible disputes.
Automated systems may scan in-platform messages and consultation chat for contact-sharing or off-platform solicitation patterns. Blocked messages may remain visible only to the sender and may generate moderation records reviewed by administrators.
Confidentiality obligations may also apply between clients and accountants under professional standards or separate agreements. AskAccountant is not a party to those professional confidentiality duties except as needed to operate the Platform.
11.Disputes and Administrator Access
If a booking or service-request dispute is opened, AskAccountant administrators may access relevant account, message, booking, invoice, payment, document, attendance, moderation, and activity records to investigate and resolve the matter according to Platform rules.
Administrator access for dispute review is limited to what is reasonably necessary for support, fraud prevention, compliance, and dispute resolution.
Off-platform communications
Information shared outside AskAccountant, such as through personal email, phone calls, or messaging apps, is not automatically collected or protected by this Policy. Use Platform messaging and documented engagements when you want records available for support or dispute review.
13.Your Rights Under the Data Privacy Act of 2012
Subject to applicable law, you may have the right to access, correct, update, or request deletion of your personal information, object to certain processing, withdraw consent where processing is consent-based, and file a complaint with the National Privacy Commission.
To exercise these rights, contact us at the email address below. We may need to verify your identity before responding and may decline requests where retention is required by law or legitimate business need, including records needed to support completed transactions, disputes, refunds, tax reporting, and audit obligations.
14.Children's Privacy
AskAccountant is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us so we can review and take appropriate action.
15.Cross-Border Processing
AskAccountant is operated in the Philippines, but some service providers may process data in other countries where they maintain infrastructure. When this occurs, we take reasonable steps to ensure appropriate safeguards consistent with applicable law.
16.Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we may notify registered users by email or in-app notification.
Continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the revised Policy.
17.Contact
For privacy inquiries, data subject requests, or questions about this Policy, contact us at support@askaccountant.ph.
For terms governing use of the Platform, see our Terms of Service.
Questions about these terms? Contact our support team.