Business policy
Privacy Policy
This policy explains the limited information collected on the public site and the separate controls that apply to payment, financial-account connection, client-portal, and tax-record workflows.
1. Business identity and scope
The Purposeful Dollar, LLC (“TPD,” “we,” “us,” or “our”) provides financial-record reconstruction, source-document normalization, administrative tax workpapers, and related coordination services. This policy applies to tpd.missionreadycontracting.org and TPD qualification-request, payment-launch, and authorized account-connection workflows.
2. Information collected on the public site
The public intake may collect only the information shown on the form: first and last name, email, phone, requested service, tax years involved, a short description, and preferred contact method. The public site also processes limited security data needed to prevent abuse, such as a short-lived keyed digest derived from a network address. We do not retain the raw address in the application database.
The public form must not be used to send an SSN, EIN, tax return, bank or routing number, account credential, password, PIN, MFA code, tax document, or other sensitive financial record.
3. Information collected after secure onboarding
After an engagement is established, TPD may receive client identity and contact information, source documents, tax and financial records, engagement and invoice records, communications, workpapers, and professional-review materials through approved restricted systems. Those records are not stored in or served from the public presentation layer.
4. Payments through Stripe
When an engagement or invoice identifies Mission Ready Contracting, LLC (“MRC”) as prime contractor and payment administrator, MRC is the Stripe account holder and merchant for that payment while TPD performs the listed bookkeeping or tax-record reconstruction services. Stripe processes the card, contact, billing, receipt, and fraud-prevention information entered in Checkout. Authorized MRC payment-operations personnel and authorized TPD reconciliation personnel may access only the payment information needed for support, accounting, or reconciliation. The restricted reconciliation system retains provider identifiers; opaque client, engagement, and invoice references; a non-sensitive service code; amount and currency; invoice version and expiry; an idempotency key; timestamps; payment status; and reconciliation status. Neither MRC nor TPD places SSNs, EINs, tax-return data, bank numbers, passwords, or tax-document contents in Stripe metadata.
5. Optional account connection through Plaid
If enabled for an engagement, a client may separately authorize Plaid Transactions access for reconstruction. The consent workflow identifies the requested transaction data, the reconstruction purpose, the approved products, the applicable history window, and how to revoke access or request deletion. Plaid Link handles bank authentication; TPD does not receive the client’s online-banking password.
For the current reconstruction use case, TPD requests Transactions only, with up to 730 days of available history. Plaid Auth is not enabled, Plaid does not initiate payments or withdraw money for TPD, and TPD does not request account or routing numbers through this workflow. Plaid access tokens remain server-side and are encrypted before restricted storage.
6. How information is used
- Respond to intake and establish a non-authorizing intake reference.
- Perform the services authorized in the applicable engagement.
- Reconstruct, normalize, index, and reconcile source records.
- Prepare and transmit authorized workpaper packages for client and tax-professional review.
- Process and reconcile invoices and payments.
- Maintain consent, access, security, audit, retention, and deletion records.
- Prevent fraud, abuse, unauthorized access, and technical failure.
- Meet applicable legal, professional, accounting, and recordkeeping requirements.
7. When information is disclosed
TPD may disclose information only as permitted for the engagement and applicable law, including to service providers supporting hosting, secure storage, payment processing, account connection, communications, and professional tax review; to an engaged CPA, EA, attorney, or tax preparer where authorized; at the client’s direction; or when required by law. Service providers receive only the information needed for their role.
Tax-return information is not used or disclosed for an unrelated purpose merely because it is available to TPD. Where a separate consent is required, TPD records that consent before the use or disclosure.
8. Partners are separate entities
Bulletproof Tax Co. may provide tax-professional review or final preparation through an applicable separate engagement. For a qualifying MRC-prime engagement, Mission Ready Contracting, LLC may contract with the client and receive payment through its Stripe account while TPD performs the identified reconstruction scope. These relationships do not create shared legal identity, merge internal bank records, transfer professional authority, or provide unrestricted access to TPD client records. Each recipient’s access depends on role, engagement, authorization, and need.
9. Security practices
TPD’s required operating model separates public content, restricted business material, authenticated client operations, encrypted tax and financial records, and secrets. Technical controls include encrypted transmission, restricted access, server-side validation, rate limits, audit records for sensitive actions, payment-webhook verification, encrypted Plaid access tokens, and secrets management. A restricted written information-security program must be created and approved before protected client-data workflows are enabled in production; this public website does not itself establish or verify that program. No security method eliminates all risk.
10. Retention and deletion
Records are retained only for the engagement, operational, security, accounting, dispute, professional, or legal period that applies to the record class. A Plaid disconnection immediately blocks future TPD access and starts provider-side Item removal, which may remain pending while the removal is retried. It does not automatically delete transaction records already delivered for the engagement. A client may request deletion separately; TPD will identify what was deleted and any portion that must remain for a documented purpose.
Former-client information remains subject to the same confidentiality and access controls while retained.
11. Choices and requests
Clients may request access correction, revoke Plaid access, request deletion, or ask questions about a disclosure or service provider. TPD may verify identity and authority before acting on a request. Do not include sensitive records in an ordinary email request.
12. Policy versions
TPD may update this policy as systems, providers, services, or legal requirements change. The effective date identifies the published version. Material changes will be presented through an appropriate client or engagement channel when required.
Policy questions
Use the policy-support channel and include only your name and engagement or invoice reference. Do not email tax documents or banking credentials.
