Privacy Policy

Last updated: April 17, 2026

Who We Are

HostClear is a product of WholesaleBridge LLC ("we," "us," "our"), a Wisconsin limited liability company. HostClear is a CPA-facing dashboard for short-term rental financial operations, available at hostclear.io. It is the professional companion to FinlyFetch (finlyfetch.io), the host-facing product. This policy covers the data we collect from CPAs and accountants who use HostClear, as well as the client data made visible to you by your host clients.

What We Collect

We collect only what's necessary to provide our service:

  • Waitlist signup: Your email address, collected via our waitlist form. Used solely to notify you when HostClear launches. Not shared with third parties.
  • CPA account information:When the product launches — your name, email, firm name, and firm details provided during onboarding.
  • Client access grants: Records of which FinlyFetch host organizations have granted you read-only access to their data, and when those grants were issued or revoked.
  • Billing information:If you upgrade to a paid HostClear tier, Stripe processes your payment. We retain only billing metadata (plan, renewal date, invoice history) — never card numbers.
  • Usage data: Standard web analytics (page views, feature usage) to improve the product. No advertising trackers.

How We Use Your Data

  • To provide, maintain, and improve HostClear services
  • To display the financial data of the host clients who have granted you access
  • To generate aggregate and per-client reports (QuickBooks CSV, Schedule C/E summaries, 1099 packages) at your direction
  • To produce AI-generated year-end narrative flags for your professional review
  • To process billing for paid HostClear plans via Stripe
  • To communicate product updates and support responses

We do notsell your data or your clients' data. We do not use financial data for advertising. We do not share data with third parties except as required to provide the service (e.g., Stripe for billing, Anthropic for AI-generated summaries, Resend for email).

Your Clients' Data

HostClear operates on an explicit-grant trust model. You see client data only when a host has actively granted your CPA account access to their FinlyFetch organization.

  • Read-only by default:You can view and export client financial data. You cannot modify your client's books through HostClear.
  • Revocable at any time: Your client can revoke your access from their FinlyFetch dashboard immediately. Revocation takes effect at the next request.
  • No secret access: Thereadonly_cparole cannot read encrypted vault references or contractor tax identification numbers (TINs). You see classified financial data, never the underlying secrets.
  • Filing always requires client approval: 1099-NEC filings are prepared in HostClear but submitted only after your client approves. Nothing is filed autonomously.
  • Audit trail: Every access event, export, and filing action is logged to an immutable audit record visible to your client.

How We Protect Your Data

  • Encryption at rest: Sensitive data (TINs, API keys, OAuth tokens) is encrypted using Supabase Vault (pgsodium). Never stored in plain text.
  • Encryption in transit: All connections use TLS. No exceptions.
  • Access control:Row-level security on every database table. Organization isolation and role enforcement happen at the database level via verified JWT claims — not in application code alone.
  • Audit trail: Every financial operation and every CPA access event is logged with an immutable audit record.
  • No PCI scope: We never see or store credit card numbers. Stripe handles all payment card data.
  • SOC2-ready architecture: The system is built with audit readiness in mind from day one.

Data Retention

  • Client financial records (visible to you): 7 years (IRS minimum retention requirement), governed by the host's FinlyFetch account
  • CPA account data: Until you close your HostClear account, then deleted within 30 days
  • Access grant history: Retained indefinitely as part of the audit record
  • Audit events: 7 years
  • Waitlist emails: Until launch, then deleted unless you create an account

Third-Party Services

HostClear integrates with the following services to provide our product:

  • Supabase— Database and authentication
  • Stripe— Billing and subscription management
  • Anthropic (Claude API)— AI-generated narrative summaries and year-end flags. Anthropic does not train on your client data.
  • TaxBandits— 1099-NEC preparation, invoked only at client direction
  • Resend— Transactional email
  • Vercel— Website hosting

Each service processes only the data necessary for its function. We do not send your complete client portfolio to any single third party.

Your Rights

  • Access: Request a copy of your CPA account data at any time.
  • Correction: Request correction of inaccurate account data.
  • Deletion:Request deletion of your CPA account. Access grants from clients will be revoked automatically. Client financial records remain with the host's FinlyFetch account.
  • Export:Download client-granted financial data in standard formats (CSV, PDF) at any time, subject to the client's active grant.
  • Opt out: Unsubscribe from marketing communications at any time. Service communications (security alerts, billing, client grant changes) cannot be opted out of while your account is active.

Professional Responsibility

HostClear is infrastructure, not advice. We organize data, surface patterns, and generate reports. Every professional judgment — classification decisions, filing positions, deduction eligibility, Schedule C vs. Schedule E posture — stays with you and your client. HostClear does not give tax, legal, or financial advice, and AI-generated narratives are flagged for your review, never presented as conclusions.

Cookies

We use essential cookies for authentication and session management. We do not use advertising cookies or third-party tracking cookies. Analytics, if implemented, will use privacy-respecting tools that do not track individuals across sites.

Children's Privacy

HostClear is a professional tool for licensed accountants and is not intended for use by anyone under 18. We do not knowingly collect data from minors.

Changes to This Policy

We may update this policy as our product evolves. Material changes will be communicated via email to registered CPA users. The "last updated" date at the top reflects the most recent revision.

Contact

Questions about this policy or your data? Email us at privacy@hostclear.io

WholesaleBridge LLC
Mt Pleasant, Wisconsin