Legal
IOLTA Guard handles trust accounting records for law firms. This policy explains what we collect, why we collect it, and the controls you have over it.
Effective July 20, 2026
Scope and roles
This policy applies to ioltaguard.comand the IOLTA Guard application (together, the “Service”). It covers two different kinds of information, and the distinction matters:
Account Data is information about you as our customer — your name, email address, firm name, and billing details. We are the controller of this data and decide how it is used.
Service Data is the content your firm enters into the application — client names, matters, ledger entries, bank transactions, and reconciliations. Your firm is the controller of this data. We are a processor acting on your instructions, and we do not use it for any purpose other than operating the Service for you.
Your firm is responsible for its own obligations to its clients, including the duty of confidentiality under your state's rules of professional conduct.
And where it comes from
A note on bank connections. IOLTA Guard imports bank data from statement files that you upload. We do not ask for, and do not store, your online banking username or password.
Purposes of processing
We do not use your Service Data for advertising, and we do not use it to train machine learning models. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Service providers and legal requests
We share information only with vendors that help us operate the Service, and only to the extent they need it. Each is bound by contract to protect it and to use it for no other purpose.
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Subscription billing and payment processing | Name, email, billing address, and payment card details (entered directly with Stripe) |
| Email delivery provider | Transactional email — verification, password resets, alerts, and billing notices | Name and email address |
| Cloud hosting and database provider | Running the application and storing your data | All Service Data, encrypted at rest and in transit |
We may also disclose information when:
Security measures
No system is perfectly secure. If a breach affects your data, we will notify you and any required regulator within the timeframes the law requires.
Retention and deletion
While your subscription is active, we retain your data so the Service works. State bar rules generally require attorneys to keep trust account records for five to seven years, so we are deliberate about giving you time to export before anything is deleted.
If your subscription is canceled:
Reactivating your subscription at any point before deletion restores your data intact.
We retain a limited set of records beyond this period where the law requires it — for example, billing and tax records. Backups are purged on a rolling schedule.
Export your data at any time.Firm administrators can download a complete CSV archive — transactions, clients, matters, bank accounts, and reconciliations — from the billing page, whether or not the subscription is active.
Access, correction, and deletion
Depending on where you live, you may have the right to:
To exercise any of these, email info@ioltaguard.com. We will verify your identity and respond within the period the applicable law requires, generally 30 to 45 days.
If your request concerns Service Data belonging to a law firm we serve, we will refer you to that firm, which controls the data, and assist them in responding.
Some information cannot be deleted on request. Audit log entries are immutable by design, because their integrity is what makes them useful as a compliance record.
What we set and why
We use cookies that are strictly necessary to run the Service: a session cookie that keeps you signed in, and security cookies that protect against cross-site request forgery. These cannot be disabled without breaking sign-in.
We do not use advertising cookies, and we do not permit third parties to track you across other sites through our Service.
Not directed to minors
IOLTA Guard is professional software for law firms and is not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.
United States
IOLTA Guard is operated in the United States and your data is stored and processed there. If you access the Service from outside the United States, you are transferring your information into the United States, where privacy laws may differ from those of your jurisdiction.
How we notify you
We may update this policy as the Service evolves. We will revise the effective date above, and for material changes we will notify account administrators by email or in-app notice before the change takes effect.
Reach out and a real person will answer. If you are evaluating IOLTA Guard for your firm and need a data processing agreement or a security review, ask us.
Prefer a form? Contact us here.