H&R Block Digital Tax Preparation, Online, and Mobile Application Privacy Practices and Principles
Protecting your information is important to us. The following guidelines set forth our general privacy practices and principles that apply to information we collect through the following products and services:
- our online and software tax preparation products and services
- our websites (including www.hrblock.com and MyBlock?, but not healthcare.hrblock.com)
- our mobile applications that incorporate this Privacy Notice
If you enter into another business relationship with us, our affiliates, or an H&R Block independently-owned, third-party franchisee, including through our nationwide network of offices, we will make you aware of the privacy practices and principles that apply to that particular business or relationship.
Special Note to Parents: Because of the nature of the services we provide, we do not market our services to children under the age of 13, nor do we knowingly collect information from children under the age of 13.
If you have questions or complaints regarding our privacy practices or principles, please contact us by clicking here or calling 1-800-HRBLOCK.
What information do we collect?
We may collect information, including personal information, about you, your spouse, your dependents, or your business when you use our services.
- Contact Information (e.g., name, phone number, address, and email address)
- Social Security Number and other government identification numbers (e.g., EIN, Driver’s License Number and ITIN)
- Date of Birth
- Financial Information (e.g., income, revenue, assets, credits, deductions, expenses, and bank account information)
- Payment Data (e.g., checking, debit and credit card account numbers, balances and payment history)
- Health Information (e.g., health insurance status and financial information related to payment for healthcare services)
- Geo-Location Information
- Website, Mobile Application, and Email Usage Data
- Device Information (e.g., internet protocol (IP) address, unique identifier, app version, operating system, network data, and phone state)
- Login Information
- Demographic Information
Where do we get this information?
You provide us most of the information we collect. We also receive information through certain digital technologies when you interact with us. Finally, other companies and government entities may share information with us.
We collect information directly from you.
We collect information you voluntarily provide as part of using or requesting our services. This information includes information you provide as part of preparing your tax return, electronically filing your tax return, setting up an online account, authenticating your identity, applying for or purchasing a product or service, or applying for employment. It also includes documents you choose to upload to your MyBlock? Account. If you choose not to provide certain information we request, we may be unable to serve you as our products, services, tools or calculators may rely upon this information.
Our websites may offer publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal information (e.g., name and city) from our blog or community forum, you can contact us by clicking here. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.
We collect information when you use our services.
We collect certain information and usage data whenever you interact with us, whether online, through a mobile application, or view an email. This data may include which websites you visit, what you click on, and when you performed those actions. These activities may be performed by us or a service provider acting on our behalf.
We utilize certain web and wireless technologies to collect this information. These technologies include cookies and web beacons. Please see “What types of web and wireless technologies (including Cookies) do we use?” for an in-depth discussion of these technologies and how to opt-out.
The Internal Revenue Service (IRS) or state taxing authorities may require we collect certain personal and system information in connection with preparing or electronically filing your tax return. This may include your name, social security number, IP addresses, and unique device identifiers.
We collect information from other companies and government entities.
In accordance with their privacy notices, our affiliates, our business partners, H&R Block franchisees, and non-affiliated third-parties (including the IRS and credit reporting agencies) may share certain information about you with us.
We also collect information when you request services or information from us or companies with whom we have a business relationship, enter contests or sweepstakes, or complete surveys or polls.
To improve the security of our services, to protect your identity, and to protect your information, we may verify your personal information by matching the information you provide against other publicly available information that we obtain from identification verification companies.
How do we use your information?
We use your information to provide you the products and services you request. We may also use your information, as permitted by law, to service and report on your account and to offer you relevant information, products, or services. These activities may be performed by us or a service provider acting on our behalf.
- Offer you products and services. We may use your information to contact you about products and services offered by us or our affiliate companies. This may include delivery of our or our affiliate's newsletters or publications.
- Geo-Location Uses. We may use your location to provide you a list of nearby H&R Block offices, assess the level of interest in our services in a particular area, and enhance the services we are providing you and other clients. You may at any time revoke our collection of this information by turning this off at the device level and not using our office locator.
- Mobile Devices. When you use a mobile device, we may ask your permission to dial a phone number, access your camera or photo library, access the internet, access your calendar, push notifications to you, read and write to internal and external storage, wake/lock your mobile device, and authorize in-app purchases.
- MyBlock? Account. We may use your information to set up an online account or authenticate your identity. We may use your email address as your online username.
- Security Enhancements. We may use publicly available information to verify your personal information in order to improve the security of our services, protect your identity, and protect your information.
- Unique Identifiers. We may assign you a global unique identifier (GUID) when you use our services. The GUID is a unique alphanumeric combination. The GUID allows us to match your information, which may include personal information, with data collected through our other products and services. Generally, we use this information to help us better understand your use of our products and services.
- Calculators and Tools. When you use our calculators and other tools, we may collect non-identifiable data, such as the number of people that use a certain tool. We may also set cookies or clear gifs based upon your use so that you do not have to re-enter your information in a later visit and to help us customize offers and tools to your particular interests. For our calculators and other tools that require registration or ask for your contact information, we may contact you directly with relevant services and offers.
Who do we share your information with?
We do not sell or rent your information without your consent. We may, however, share your information with your consent or as permitted by law, as set forth in this Privacy Notice.
We may disclose your information as described below:
- Third-Parties. We do not sell or rent your personal information to third-party direct marketers. Additionally, we do not share your personal information with non-affiliated third-parties for marketing purposes except as permitted by applicable law or with your consent.
- Affiliates. As permitted by law, we may provide information we collect to our affiliates. Our affiliates may use this information to market additional products and services to you.
- Business Partners. We work closely with a variety of business partners. We may offer products jointly with our business partners. You will be able to recognize when a business partner is associated with your transaction when its logo appears or is shown with our logo. We may share information that is related to such transactions with that business partner.
- Service Providers. Where permitted by applicable law, we may disclose your personal information to service providers who perform business functions on our behalf, services such as data processing and analysis, contest supervision, and direct mail or email production. We may also share your personal information, and a record of any transactions you conduct on our websites or offline with us with a third-party advertising partner and its service providers in order to deliver you advertising tailored to your interests when you visit certain other websites. Data shared in this way is made pseudonymous. We require all service providers to have written contracts with us that specify appropriate use of your personal information, require them to safeguard your personal information, and prohibit them from making unauthorized or unlawful use of your personal information.
- Joint Marketing Arrangements. Where permitted by law, we may provide information we collect to joint marketers with whom we have a marketing arrangement. We require all joint marketers to have written contracts with us that specify appropriate use of your personal information, require them to safeguard your personal information, and prohibit them from making unauthorized or unlawful use of your personal information. If a state law (or other law) requires us to give you the right to opt-out prior to any disclosure of your personal information for joint marketing, we will not disclose your personal information for such purposes without providing such opt-out or obtaining your consent to such disclosure.
- Franchisees. Certain H&R Block products and services are provided via a system of retail offices operated directly by independently owned, third-party franchisees. In order to serve you, and only where permitted by law, we may share your information with these franchisees.
- Communications with the IRS and State Taxing Authorities. The IRS and state taxing authorities may require or request we disclose certain personal and system information in order to process or electronically file your tax return. This information may include, but is not limited to, your name, social security number, IP addresses, unique device identifiers, bank account numbers, and tax return preparation user activity metrics (e.g., time to complete the tax return).
- Persons Who Acquire Our Assets or Business. If we sell or transfer any of our business or assets, certain information about our clients may be a part of that sale or transfer. In the event such sale or transfer results in a material change to this Privacy Notice, we will notify you. The notification procedure will be the same as the procedure we use to notify you of a change to this Privacy Notice as described below.
- As Required or Permitted by Law. We may disclose your information to affiliated or non-affiliated third-parties when we have a good faith belief that such disclosure is required or permitted by law. This may occur in connection with a court order, legal process, or other judicial, administrative or investigative proceeding that produces a request for information from us. We may disclose your information to proper federal, state, or local officials in order, and to the extent necessary, to inform the official of activities that may constitute, or may have constituted, a violation of any criminal law or to assist the official in investigating or prosecuting a violation of criminal law. As permitted by law, we may disclose your information to the IRS and Information Sharing and Analysis Centers (ISACs) for the prevention of stolen identity refund fraud (SIRF) and as related to potential cyber security threats.
- Aggregate Data. We may disclose aggregate information compiled using information that does not identify you individually or personally. This may include, for example, the total number of visitors from a particular state or the average user age.
What types of web and wireless technologies (including Cookies) do we use?
- Cookies. We utilize a software technology called "cookies." Cookies allow us to customize our websites for you by placing small files on your computer or mobile device as you visit various components of our websites.
Cookies are small alphanumeric identifiers that a web server transfers to your computer via your Internet browser. When your Internet browser visits a web page, a cookie is set with a unique number. This number is recorded in a small text file that is transmitted to your computer and stored in the cookie directory of your hard drive. Then, when you visit each webpage on which the cookie technology is enabled, the website can recognize your browser as a unique user.
You may also adjust your browser settings to accept or deny all cookies, or to request your permission each time a site attempts to set a cookie. Although cookies are not required for some parts of our services, our services may not work properly if you disable cookies entirely.
- Local Storage Objects (LSOs) and HTML5. We provide certain features on our site or display advertising based upon your web browsing activity using LSOs (such as HTML5) to store content, information, and preferences. Your browser may offer LSO management tools.
- Clear GIFs or Web Beacons. We employ a software technology called clear gifs (also known as pixel tags or web beacons), that help us better manage content on our websites by allowing us to understand usage patterns, fix issues, and improve the products and services offered to you on our websites. We may use clear gifs in our emails to let us know which emails have been opened by recipients. This allows us to gauge the effectiveness of certain communications and the effectiveness of our marketing campaigns. These activities may be performed by us or a service provider acting on our behalf.
- Log Files. Like most websites, we use log files. Information collected in log files may include IP addresses, unique device IDs, browser type, Internet Service Provider (ISP), referring/exit pages, platform type, date/time stamp, and number of clicks. We utilize this information to analyze trends, administer the site or mobile application, track user's movement in the aggregate, and gather broad demographic information for aggregate use. When you use certain online tax services, IP addresses and unique device IDs may be tied to personally identifiable information to enable users to file or transmit tax returns to the IRS.
- Online Behavioral Advertising. We allow third-party companies to serve ads and collect certain pseudonymous information when you visit our websites. These companies may use this information (e.g., click stream information, browser type, time and date, subject of advertisements clicked or scrolled over) during your visits to our websites and other websites in order to provide advertisements about goods and services likely to be of greater interest to you. These companies typically use a cookie or third-party web beacon to collect this information. We may engage different providers to provide similar services from time to time. To opt-out of this type of advertising, complete both forms at http://webmedia.hrblock.com/optout.html and http://www.networkadvertising.org/managing/opt_out.asp. You may also opt-out of certain advertisements by clicking on the advertisement itself or through TRUSTe's preference manager: http://preferences.truste.com. Please note, even after opting out of personalized advertisements, you will continue to receive generic advertisements.
- Mobile Device Information. We may record data from your mobile device such as Apple IDFA, general characteristics of your device and other device IDs.
How do we respond to web browser “do not track” signals?
We treat the data of everyone who comes to our websites in accordance with this Privacy Notice, whatever their “do not track” setting. While we do not respond to web browser “do not track” signals, we give you choices about receiving promotional offers from us or third-parties. You can exercise your choices as described in this Privacy Notice.
How do we secure your information?
The security of your personal information is important to us. We maintain appropriate safeguards to protect your information. If you have any questions about the security of our services, you can contact us by clicking here.
We follow generally accepted standards to protect information submitted to us, both during transmission and once we receive it. Nevertheless, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security.
We maintain physical, electronic and procedural safeguards that comply with applicable law and federal standards and that are designed to restrict access to your information. These safeguards include programs and specifications for physical security and records retention and disposal; computer and communication security measures reflected in system design, password protection, and data management practices; and other measures to restrict access to the data we hold in physical and electronic forms.
If we collect sensitive information (such as your social security number), we will encrypt the transmission of that information using secure socket layer technology (SSL).
If we share your information with our service providers, we require all service providers to have written contracts that specify appropriate use of your personal information, require them to safeguard your personal information, and prohibit them from making unauthorized or unlawful use of your personal information.
How long do we keep your information?
We keep your information for as long as needed or as required by law.
We retain your information for as long as your account is active or as needed to provide you services. We may retain or use your information as necessary to comply with our policies, legal obligations, resolve disputes, and enforce our agreements.
The IRS requires us to retain filed tax returns for a period of at least three years.
It is our policy that if you start, but do not complete, a tax return in our online tax programs, we will generally keep the tax return information you provide until the end of that tax season, after which it will be deleted from our system.
Third-party products and services, including social media features
This Privacy Notice does not apply to products or services offered by third-parties on or through our services. You should carefully read the privacy notices and any terms and conditions applicable to such third-party products or services.
Our services may contain links to third-party websites or offers for services from third-parties. This Privacy Notice does not apply to these products or services. You should carefully read the privacy notices of the third-parties providing such products or services and any terms and conditions applicable to such products or services.
We have business relationships with third-parties that provide products or services on or through our services. These companies are clearly identified. When you request products or services from such companies, you give us permission to provide these third-parties with information about you necessary to fulfill or process your request.
For instance, your use of social media features may use scripting or may require us to share your IP address and which page you are visiting to enable the feature to function properly. Social media features and widgets are either hosted by a third-party or hosted directly on our site, and your interactions with these features are governed by the privacy notice of the company providing it. Examples of these features are the Facebook “Like” button, the “Share This” button, and interactive mini-programs that run on our services.
Updating or deleting your account
You may view and update your personal information through MyBlock?. You can delete your MyBlock? account through the "Manage Account" and "Account Settings" screens. If you have questions, you may contact us by clicking here or by calling 1-800-HRBLOCK. We will respond to requests within a reasonable timeframe.
If you are a user of our online tax return preparation products or MyBlock?, you may access your personal information through those services and, where available, update that information. The types of information that you can access and update may change over time. Remember, some of the information we collect does not identify you personally or is not stored in an online accessible format and thus, may not be accessible through MyBlockSM.
When you update information, we may maintain a copy of the unrevised information in our records. Additionally, if you request we delete your account or information, we may still retain and use your information as necessary to comply with our legal obligations.
You may choose to limit our use or our ability to share your information in certain circumstances. Our ability to offer you certain products and services and your experience may be affected by your choice. To opt out of electronic communications, click here. To opt out of all other communications call us at 1-800 HRBLOCK. You may, however, continue to receive e-mail communications related directly to the services and products you purchase, such as payment receipts and e-file status notifications.
Where permitted by law, we may use your information (subject to your consent, where required) to communicate with you about products and services available through H&R Block or third-parties. If at any time you wish to limit your receipt of such communications, you may click here. At your request and subject to the limitations below, we will make reasonable efforts to limit all such marketing communications to you. We will also provide you the ability to stop receiving marketing emails by following the unsubscribe instructions included in each marketing communication. We will respond to requests within a reasonable timeframe.
You may not opt-out of the sharing of information that does not identify you personally.
The above paragraphs only apply to personal information we obtain through your use of our services covered by this Privacy Notice. You may still receive offers from us, our affiliates or H&R Block independently owned, third-party franchisees where they obtain your contact information through other sources. In order to opt-out from communications from our affiliates or franchisees, you must contact each affiliate or franchisee in accordance with their policies.
Please see "What types of web and wireless technologies (including Cookies) do we use?" for information on how to opt-out of various web and wireless technologies we use.
Accessing Our Services from Outside the United States
Our services are hosted on servers located in the United States. We also use service providers located in the United States to bring you our services. If you access our services from outside the United States, you consent to the transfer of your information, including your personal information, to the United States, a jurisdiction that may not provide the same level of protection to your personal information as your home country.
If you have questions or concerns regarding this Privacy Notice, contact us by clicking here or by calling 1-800-HRBLOCK. If you do not receive acknowledgment of your inquiry or your inquiry has not been satisfactorily addressed within fifteen (15) business days, you may then contact TRUSTe here. TRUSTe will serve as your liaison with us to resolve your concerns.
Who is TRUSTe?
TRUSTe is an independent third-party who reviews this Privacy Notice and our privacy practices.
We have received TRUSTe's Privacy Seal signifying that this Privacy Notice and our practices have been reviewed for compliance with the TRUSTe program viewable on the validation page available by clicking the TRUSTe seal. The TRUSTe program covers information that is collected through your use of our services covered by this Privacy Notice, except for information collected through the use of healthcare.hrblock.com or any downloadable software product.
Privacy Notice Updates
This Privacy Notice may change. If we make a material change to this Privacy Notice, including a material change in the way we use any personal information collected, we will notify you by using one of the following methods at least thirty (30) days prior to the effective date of such change: (1) we will post a notice on our website describing the change; or (2) we will send you an email notifying you of the change.
This Privacy Notice is effective October 13, 2015.
© 2015 HRB Digital LLC. All rights reserved.
HRB Digital LLC
One H&R Block Way
Kansas City, MO 64105