Privacy
What Bursar holds on behalf of your firm, why it holds it, and what happens to it.
This page describes how Bursar handles data today. It is not the executed agreement between Bursar and your firm - that document is issued with the engagement and is the one that binds either of us. If you are running a diligence review and need the current executed version, ask and it will be sent.
Whose data this is
Bursar is a service provider to accounting firms. The data Bursar processes belongs to your firm’s clients and reaches us through your firm. Your firm holds the engagement and the client relationship; Bursar produces the books underneath it and is never named to your client.
What is processed
To produce a close, Bursar reads the client’s accounting file, its bank and card feeds, point-of-sale and delivery-platform data where those apply, and the source documents collected during the month. It also holds the contact details of the person at the client who receives document requests, and the accounts of your firm’s own staff who use the dashboard.
What it is used for
One purpose: producing and proving that client’s books, and delivering the close package to your firm. Client financial data is not used as training data. That commitment is stated absolutely because it is meant absolutely - it is not qualified by an exception for aggregated, anonymized or derived use.
How it is protected
- Encrypted with AES-256 at rest and in transit
- Access scoped per firm, per client and per reviewer, resolved from a verified sign-in rather than from the address a request was sent to
- Sign-in through Google or Microsoft single sign-on; Bursar stores no passwords
- Every action on a close written to an immutable audit trail
- Exactly one connected system is ever written to - the client’s accounting file. Feeds and platform connections are read-only
Consent, where the law requires it
Bursar’s production capability includes people outside the United States. Under IRC §7216, disclosing a taxpayer’s return information to a person outside the United States requires that taxpayer’s signed consent, in a prescribed form, before any disclosure occurs. Bursar will not open a close for a client until that consent is recorded, and the consent is stored as the text that was actually agreed together with the date it was signed and the date it expires. A revoked consent is stamped rather than deleted, so the record can still answer whether disclosure was permitted on the day it happened.
Separately, AICPA ET 1.150.040 requires your firm to inform its client that the firm may use a third-party service provider before disclosing confidential client information. That obligation sits with your firm rather than with Bursar, and your firm is not required to name us. If a client objects, Bursar treats the objection as dispositive and refuses disclosure for that client.
Retention and deletion
Data is retained while your firm is a customer and for up to 30 days after offboarding, after which it is deleted. It is yours to export at any point before then. Audit records are retained with the close they belong to, because a close whose trail has been discarded cannot be defended later.
Sub-processors and infrastructure
Bursar runs on infrastructure and services provided by third parties, and uses the accounting platforms’ own APIs to read and write client files. The current list, with what each one processes, is provided on request as part of a security review rather than published here, where it would go stale silently between edits.
Questions and requests
Access, export, deletion and diligence requests all go to hello@trybursar.com. A request that comes from your firm about your firm’s client will be actioned through your firm, since that is where the engagement and the client relationship sit.