Infile Legal Policies

Policies for firms using Infile to collect client documents securely.

Terms of Service

Terms governing use of the Infile document collection platform.

Effective July 12, 2026

Privacy Policy

How Infile collects, uses, and protects personal information.

Effective July 12, 2026

Refund Policy

14-day refund policy for all Infile subscription purchases.

Effective July 14, 2026

Cookie Policy

How we use cookies and similar technologies on infile.app.

Effective July 12, 2026

Acceptable Use Policy

Permitted and prohibited uses of Infile for firms and their clients.

Effective July 12, 2026

Security Policy

How Infile protects firm and client data on the platform.

Effective July 12, 2026

Data Processing Agreement

Processor terms when Infile handles personal data on your firm's behalf.

Effective July 12, 2026

Acceptable Use Policy

Effective July 12, 2026

Permitted and prohibited uses of Infile for firms and their clients.

1. Permitted Use

Infile is designed for professional firms - including CPAs, bookkeepers, and advisory practices - to collect documents and information from clients. Permitted uses include:

  • Sending branded document requests and checklists to clients
  • Collecting tax organizers, monthly bookkeeping packages, and onboarding documents
  • Automating client reminders tied to checklist completion
  • Storing and exporting client submissions for legitimate business purposes

2. Prohibited Use

You may not use Infile to:

  • Violate applicable law or professional conduct obligations
  • Upload malware, exploit code, or content intended to disrupt the platform
  • Attempt unauthorized access to accounts, upload links, or firm data
  • Collect information without a lawful basis or required client notice
  • Harass, spam, or send unsolicited bulk messages unrelated to document collection
  • Misrepresent your identity or firm affiliation when contacting clients

3. Client Upload Links

Passwordless upload links are scoped to individual requests. You are responsible for sending links to the correct recipient and revoking or closing requests when no longer needed. Do not publish client upload links in public channels.

4. Enforcement

We may investigate suspected violations and suspend or terminate access where we reasonably believe this policy, our Terms, or applicable law has been breached. Report abuse to support@infile.app.

Security Policy

Effective July 12, 2026

How Infile protects firm and client data on the platform.

1. Security Commitment

Infile is built to handle sensitive client documents for accounting and bookkeeping workflows. We use technical and organizational measures designed to protect confidentiality, integrity, and availability of data processed on the platform.

2. Infrastructure Security

Our security practices include:

  • Encryption in transit using modern TLS for all web and API traffic
  • Encryption at rest for stored files and database records
  • Role-based access controls for firm team members
  • Monitoring and logging of platform activity for abuse detection
  • Regular review of access permissions and production changes

3. Account Security

Firm administrators should assign least-privilege roles, rotate credentials after staff changes, and enable additional account protections where available. Clients accessing passwordless upload links should receive links only from your firm through private channels.

4. Incident Response

If we become aware of a security incident that affects customer data, we will investigate promptly, take steps to contain and remediate the issue, and notify affected customers where required by law or contractual obligations.

5. Reporting Security Issues

To report a vulnerability or security concern, contact support@infile.app with sufficient detail for us to reproduce and investigate the issue. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to respond.

Data Processing Agreement

Effective July 12, 2026

Processor terms when Infile handles personal data on your firm's behalf.

1. Roles and Scope

When your firm uses Infile to collect documents from clients, you typically act as the data controller for client personal data. Infile acts as a data processor when handling that data to provide document collection, storage, reminders, and export functionality.

2. Processing Instructions

We process personal data only to deliver, secure, support, and improve the services, and as otherwise documented in our Privacy Policy, Terms, or required by applicable law. We do not sell client personal data.

3. Subprocessors

We may use vetted subprocessors - such as cloud infrastructure and email delivery providers - to operate the platform. Subprocessors are subject to contractual obligations consistent with this DPA. A current subprocessor list is available on request at support@infile.app.

4. Data Subject Requests

Where required, we will assist your firm in responding to data subject access, correction, deletion, or portability requests relating to data processed through Infile, subject to applicable law and your instructions.

5. Data Retention and Deletion

Upon termination of your account or upon verified instruction, we will delete or return personal data within a reasonable period, except where retention is required for legal, billing, audit, or security purposes.

6. Executed DPA

Enterprise customers may request a signed Data Processing Agreement. Contact support@infile.app to request the current DPA template or discuss EU/UK Standard Contractual Clauses where applicable.

Questions about these policies? Contact our team or email support@infile.app.