Back to Dashboard

Privacy Policy

Effective: July 23, 2026 | Last updated: July 23, 2026 | Version 1.0

This Privacy Policy explains how Prism HMS, operated by Cosby AI Solutions LLC ("Prism HMS", "we", "us"), collects, uses, protects, retains, and shares information when you use our accounting, reconciliation, and cash-management services, including when you connect a bank account through Plaid. This policy governs financial and account data. Hotel-guest data is covered by our separate guest privacy notice at /legal/privacy.

1. Information We Collect

We collect the following categories of information:

  • Bank and financial data via Plaid. When you connect a financial account, we use Plaid Inc. ("Plaid") to access, on your authorization, your account and routing identifiers, account names and balances, account types, and transaction history (dates, amounts, merchant names, and categories).
  • Account and profile information. Name, email address, phone number, business name, and role.
  • Usage and log data. Actions taken in the platform, timestamps, and audit records used for security and compliance.

2. How We Use Your Information

We use financial data solely to provide the services you request, specifically:

  • Bank and ledger reconciliation.
  • Accounts payable and accounts receivable processing.
  • Cash management, balance monitoring, and financial reporting.
  • Security, fraud prevention, audit logging, and legal compliance.

We do not use your financial data for advertising, and we do not sell it.

3. Plaid

We use Plaid to connect to your financial institution. By connecting an account, you also authorize Plaid to collect your financial data in accordance with the Plaid End User Privacy Policy. Plaid provides us with an access token and the financial data listed above. We never receive or store your online-banking login credentials; those are handled by Plaid.

4. Storage and Protection

  • Encryption at rest. Data is stored in a managed PostgreSQL database, encrypted at rest with AES-256.
  • Encryption in transit. All connections use TLS 1.2 or higher.
  • Plaid access tokens. Access tokens are additionally encrypted at the application layer and are readable only by our secure server processes. They are never exposed to browser or client roles.
  • Access controls. Row Level Security enforces that each organization can access only its own data. Multi-factor authentication (MFA) protects administrative access and is required before connecting a bank account.

5. Data Retention

  • Transaction data: retained for 7 years to meet IRS and tax-compliance requirements.
  • Plaid access tokens: deleted within 24 hours of a bank connection being disconnected.
  • Full account data: deleted within 30 days of an account-closure or deletion request, except records we are legally required to retain (such as the 7-year transaction records).
  • Backups: retained for 90 days, after which they age out.

Full details are documented in our internal Data Retention Policy. You can request deletion of your data at any time from your account settings or by contacting us (see Section 8).

6. Third-Party Sharing

We share financial data only with Plaid, which is required to provide the bank-connection service. We do not sell your personal information, and we do not share it with advertisers or data brokers. We may disclose information when required by law, subpoena, or valid legal process, or to protect the rights, property, or safety of our users or the public.

7. Your Privacy Rights (CCPA and CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following rights:

  • Right to know what personal information we collect, use, and disclose.
  • Right to delete personal information we have collected, subject to legal retention exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell or share your personal information as those terms are defined under the CCPA, so there is nothing to opt out of.
  • Right to non-discrimination for exercising your privacy rights.

To exercise any of these rights, email jason@cosbyaisolutions.com. We will verify your request and respond within the timeframes required by law.

8. Deleting Your Data

You can request deletion from Settings inside the platform, or by emailing jason@cosbyaisolutions.com. When you request deletion, we disconnect your bank connections (removing the associated Plaid access tokens), send you a confirmation, and remove your personal data within 30 days, retaining only records we are legally required to keep.

9. Contact

Cosby AI Solutions LLC
Email: jason@cosbyaisolutions.com
Website: cosbyaisolutions.com

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-platform notice. The version and effective date at the top of this page indicate the current version.

Related: Terms of Service · Guest Privacy Notice

Powered by Cosby AI Solutions — cosbyaisolutions.com