Holistiplan Privacy Policy

Last Updated: September 12, 2024

The protection and privacy of your data, including personal data, is very important to Holistiplan (“Holistiplan” or “we”). This Privacy Policy discloses our privacy practices and the possible uses of the information that we gather on https://www.holistiplan.com/ or https://app.holistiplan.com (collectively, the “Site”) or which you otherwise submit to Holistiplan as part of our platform or service (collectively our “Services”).

Consent

By using the Site or Services you consent to the terms of this Privacy Policy. If you do not agree to the terms and conditions of this Privacy Policy, including having your personally identifiable information (“Personal Information” as defined below) used in any of the ways described in this Privacy Policy, you may not be able to use certain parts or features of our Services, and in some instances, this may necessitate the revocation of your subscription or use of the Services.

Consent to Our Terms and Conditions

This Privacy Policy is part of our Terms of Use, and all other terms of using our Site or Services. Please also visit our Terms of Use establishing your consent to the use, disclaimers, and limitations of liability governing the use of the Site or Services.

Access

Holistiplan may assign you a user ID and a password as part of your participation and access to the Services. Your user ID and password may only be used by you. You may not share your user ID and password with anyone else and you are solely responsible for maintaining and protecting the confidentiality of your user ID and password. You are fully responsible for all activities that occur under your user ID and password.

You may also be provided a unique URL or link to upload files or documents (“Files”) to Holistiplan's platform for processing by the platform and use by your advisor. Such files may include Personal Information which is processed and used in accordance with this Privacy Policy. You may also receive a link from your advisor to view data or a report from your advisor.

Personal Information

“Personal Information” refers to information that tells us specifically who you are, such as your name and email.

By voluntarily providing us with Personal Information you are consenting to our use of your Personal Information in accordance with this Privacy Policy. If you provide Personal Information, your Personal Information and all data related to the Service will be stored within the United States. By using the Service, you consent to the transfer to and storage of your Personal Information within the United States.

Information Collected

Holistiplan collects Personal Information in various ways, such as, by your voluntary submissions, through use of the Services, from third parties with your consent, and through cookie and other tracking technology. Holistiplan collects the following information:

Submission of Information
  • We collect your Personal Information that you voluntarily provide as part of your registration process, uploading Files, or from use of the Site and Services.
  • If you are an advisor, the Personal Information we collect is limited to your name, email address, firm name, firm logo file, and the names and email addresses of those employees you set up as users of the Site or Service. We may also ask for contact information and information about your firm to better provide our Services to you.
  • If you are the client of an advisor or using the Service as a direct individual, we collect financial information you or your advisor submits through the Site or Service including tax documents, Files, or other relevant financial documents (“User Submitted Content”). Holistiplan, LLC takes security of this data very seriously. User Submitted Content does not need to include Personal Information. Further, we do not store Social Security numbers or address information in our database. We do store names and non-identifying tax data so we can produce a customized tax report. While Social Security numbers and taxpayer addresses are not stored in our database, scanned images of the tax return or Files you uploaded do remain on the server unless manually deleted by your advisor or automatically deleted in the event of a canceled subscription or application setting. When a tax return record is deleted, all associated data about that tax return is also deleted from our database.
  • We will not sell your Personal Information or any information in the User Submitted Content to any third party. We would only share Personal Information or User Submitted Content for the specific circumstances outlined in the “How Information is Shared” section below.
  • We do not collect or store billing information directly. We use Stripe, Inc., a third-party billing processor which collects and stores your billing information and processes payments for the Services. You can review Stripe's privacy policy here: https://stripe.com/privacy-center/legal
Usage Information

We also use Google Analytics, Pendo and HubSpot, which collect various actions when you are on our Site or use the Services. We may also collect general, non- personal, statistical information about the use of the Site or Services, such as how many visitors visit a specific page on the Site, how long they stay on that page, and which hyperlinks, if any, they click on.

Cookies

Holistiplan may automatically collect non-personally identifiable information and data through the use of cookies. Cookies are small text files a website uses to recognize repeat users, facilitate the user's ongoing access to and use of the Site. The use of cookies helps us improve the quality of the Services we provide to you, by identifying information which is most interesting to you or storing information you may want to retrieve on a regular basis. At any time, you may adjust settings on your browser to refuse cookies according to the instructions related to your browser. You may also get cookies from our advertisers or other third parties with links on the Site as described below. We do not directly control these cookies. The use of advertising cookies sent by third party ad servers is standard in the Internet industry.

How We Use the Information

We use the information we collect for: (1) personalizing your experience; (2) communication and marketing; (3) research and development of features and products; (4) safety and security; (5) legal rights and business interest; and (6) where you provide consent for a specific purpose. How we use the information we collect also depends in part on which Standard Services you use, how you use them, and any preferences you have communicated to us. Below are the specific purposes for which we use the Personal Information we collect about you.

  1. To provide the Site and Services and personalize your experience: We use Personal Information to provide a more personalized experience, authenticate you or your device when you log in, to provide customer support and to operate and maintain the Services.
  2. Communication: We use your Personal Information to send certain communications via email, including responding to your comments, questions and requests, providing customer support, and sending you technical notices or updates, security alerts, and administrative messages.
    1. We use HubSpot, Inc. (officially doing business as “HubSpot”) to collect emails, manage email subscriber lists and to send emails to our subscribers. When you provide your email or additional information when signing up for our newsletters such Personal Information is sent directly to HubSpot. You can read HubSpot's privacy policy here: https://legal.hubspot.com/privacy-policy
    2. You can control whether you want to receive these communications by opting-out whenever you receive such a communication from Holistiplan by using the included opt-out link in any such communication.
  3. For research and development: We are always looking for ways to make our Site and Services smarter, faster, better integrated, more secure and useful to you. We use collective learnings about how people use our Site and Services and feedback provided to us to troubleshoot and to identify trends, usage, activity patterns and areas for integration and improvement.
  4. For safety and security: We use information about you and your use of the Site and Services to verify accounts and activity, to monitor suspicious or fraudulent activity and to identify violations of our policies.
  5. To protect our legitimate business interests and legal rights: Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business.
  6. With your consent: We use information about you where you have given us consent to do so for a specific purpose not listed above. For example, we may publish testimonials or featured customer stories with your permission.

How Information is Shared

Note - This section describes Personal Information pertaining to subscribers (i.e. firms and advisors using Holistiplan). User Submitted Content, (i.e. client tax return information) will never be disclosed to any outside party unless we are compelled to do so by law, regulation, subpoena, or government request in connection with litigation.

For Personal Information other than User Submitted Content, we do not disclose Personal Information to third parties, except when one or more of the following conditions is true:

  • We have your permission;
  • The disclosure assists in fulfilling the purpose for which the personal information was obtained;
  • The Personal Information to be disclosed is otherwise publicly available through no fault of Holistiplan;
  • The disclosure is reasonably related to the sale or other disposition of all or part of our business or assets;
  • The disclosure is for our own marketing purposes; or
  • The disclosure is to outside businesses to perform certain services for us, such as maintaining our Services, mailing lists, data analysis, processing orders, and delivering the Services.

The disclosure is, in our sole discretion, desirable for the establishment or maintenance of legal claims or legal compliance, to satisfy any law, regulation, subpoena or government request, or in connection with litigation.

We may also disclose aggregate visitor data in order to describe the use of the Services to our existing or potential business partners or other third parties, or in response to a government request.

Security Measures

We use various service providers to host the Site, host the technology used to provide the Services and store and secure the data we collect. We ensure a variety of security measures are implemented by such service providers, including firewalls, Secure Socket Layer (SSL) technology, encryption and authentication tools, to help protect your information.

Specifically, the following service providers are used for the Site and Services:

  • We host the Site and data with Amazon's secure data centers and the Amazon Web Service (“AWS”) technology. You can learn about Amazon's security here: https://aws.amazon.com/security/
  • We use a third party called Sentry.io for its automatic debugging service. When certain errors or logged events occur in the Holistiplan environment, logs are sent to, processed, and stored at Sentry.io. Personal Information is scrubbed prior to transfer to Sentry.io by anonymizing known fields/locations of such data, as well as pattern matching. Certain limited identifying user information used for diagnostics and troubleshooting are preserved and sent to Sentry.io, such as IP Address, browser type, and computer OS.
  • Newsletters and product emails: Data related to our Newsletters is stored in HubSpot's system. You can review HubSpot's security practices here: https://legal.hubspot.com/privacy-policy
  • Billing is managed through our integration and use of the Stripe payment platform. We do not collect or store billing information. Your billing information is stored and processed by Stripe. You can learn about Stripes security standards and practices here: https://stripe.com/docs/security/stripe

Third Party Websites and Links

Our Site and Services do not currently contain any third-party links. In the future our Site and Services may contain links to other sites operated by third parties. Holistiplan does not control such other sites and is not responsible for their content, their privacy policies, or their use of any information. Holistiplan does not support or endorse any third party unless Holistiplan expressly states such support or endorsement. Any information submitted by you to these third parties is subject to that third party's privacy policy. In addition, if you click on links, which take you to third party websites, you may be subject to the third parties' privacy policies. While we support the protection of our customer's privacy on the Internet, Holistiplan expressly disclaims any and all liability for the actions of third parties, including but without limitation to actions relating to the use and/or disclosure of Personal Information by third parties.

Personal Rights

You are, as data-owner and user of the Site and Service, entitled to (i) access your Personal Information and be informed about the way in which your information is treated, (ii) rectify your Personal Information in case it is not up-to-date, it is inaccurate or incomplete, (iii) ask for your data to be removed if you consider that it is not used in accordance with the applicable principles, duties and obligations, and (iv) object to the processing of your Personal Information for specific purposes. These rights are known as “Personal Rights”.

How to Exercise Your Personal Rights

If you decide to exercise your Personal Rights, your request should be emailed to info@holistiplan.com, together with the following information and documentation:

  • Your ID information and, if applicable, the information of your legal representative. For legal representative, please attach a copy of his/her power-of-attorney.
  • A clear and precise description of the Personal Information about which the Personal Rights are to be exercised, as well as the right or rights that are to be exercised.
  • An address where you desire to hear and receive Holistiplan's response and any future communications and/or notifications, or, in its case, your desire to receive our response and/or future notifications or responses via email, providing us with your email address.
  • If you prefer to correspond via email, you must expressly state your desire to receive Holistiplan's response through an email communication, specifying the corresponding email address.

Holistiplan will issue a response within a timely manner following receipt of your request, which will be informed to you using your selected method. Once you receive our response you will have a 20-business day period to respond to our communication. In the event you need to speak with us or in the event you disagree with our response please contact us at info@holistiplan.com along with a phone number for us to reach you, in order for Holistiplan to discuss with you any issue. In case you do not reply to our response within the afore mentioned period we will understand in good faith that you agree with our conclusion.

If your request refers to your right to access data, Holistiplan will provide you with copies of the information and/or scanned documents.

Holistiplan may refuse the exercise of your Personal Rights in instances permitted by the laws and regulations of the Territories which are applicable to your use and shall inform you about such decision. The refusal may be partial, in which case Holistiplan will carry out the access, rectification, cancellation, deletion, or objection in the corresponding part.

Revocation of Your Consent to The Treatment of Personal Information

You, as data-owner, can revoke your consent to the treatment of your Personal Information in accordance with the procedure set forth above “How to Exercise your Personal Rights”, in the understanding that once we receive your request to revoke your consent, we will issue our response within a five-day period.

Children's Privacy

As set forth in the Terms of Use, the Site and Services are not to be used and are not intended for use by individuals under the age of 18.

Governing Law

This Privacy Policy and the privacy practices of Holistiplan will be subject exclusively to the laws of the state of Texas, without reference to its choice of law provisions.

Changes to Privacy Policy

Holistiplan may update this Privacy Policy from time-to-time in our sole discretion. It is your responsibility to review the Privacy Policy for any changes each time that you use the Site or Services and you are bound by such changes. Your use of the Site or Services following us posting a new or updated privacy policy on our Site signifies that you agree to and accept the Privacy Policy as modified.

How to Contact Us

All requests, questions, concerns, or complaints about your Personal Information or this Privacy Policy, please contact us at the following: info@holistiplan.com. If you are a California Citizen wishing to request removal of your private data, you may contact us at info@holistiplan.com or [1-(866)-271-3119]