Trust & Transparency

Security & Data Handling

A plain-language description of how Hashbooks approaches account access, client records, website forms, and third-party systems.

Access Accountability

Hashbooks keeps a clear point of accountability for client access, bookkeeping work, and communication. Any specialist or service-provider access needed for a particular engagement must be disclosed and agreed with the client.

Account Access

Accountant invitations, delegated user roles, and read-only connections are preferred where a platform supports them. Clients should not send banking passwords or one-time authentication codes by email or through the website forms. Access is limited to the systems and functions needed for the agreed bookkeeping scope.

Platform Security

QuickBooks Online, Xero, ADP, Gusto, BILL, Odoo, Finale Inventory, banks, and other client-selected platforms operate their own security controls. Hashbooks does not claim that every platform is risk-free and does not claim SOC 2 certification. The exact systems used and their access method are documented during onboarding.

Website Forms & Analytics

Website proposal and contact forms collect only the details needed to respond to an inquiry. Server-side validation, same-origin checks, anti-automation fields, and request throttling are applied. Google Analytics and Meta Pixel are optional and load only after the visitor selects “Accept All” in the cookie banner.

Records, Retention & Deletion

Client bookkeeping records remain subject to the engagement agreement, applicable legal requirements, and the retention settings of the client-selected platforms. Access should be removed after an engagement ends, subject to any agreed transition period. Visitors and clients can request access, correction, or deletion of eligible personal information by email.

Incident & Vulnerability Reporting

Report a suspected data incident or website vulnerability to contact@hashbooks.site. Include the affected page or system, the time observed, and a safe description of the issue. Do not include client financial data or exploit a vulnerability.

Last reviewed: August 30, 2026. Security controls can vary by client platform and engagement; this page should be updated whenever those practices change.

Contact