Privacy Notice
Written to be read, not to be skipped. It says what is collected, why, who else sees it, and how long it is kept.
LegalWhat is collected, why, and for how longLast updated: July 22, 2026
Last updated: July 22, 2026 · Effective: July 22, 2026
1. Who we are and who controls your data
This website, farobookkeeping.com, is operated by Larimar Group LLC, a Rhode Island limited liability company doing business as Faro Bookkeeping.
The Rhode Island Data Transparency and Privacy Protection Act (R.I. Gen. Laws § 6-48.1-3(a)) requires any commercial website conducting business in Rhode Island to designate a controller of personal data. The designated controller for this website is:
- Controller: Larimar Group LLC, d/b/a Faro Bookkeeping
- Designated contact: Christopher Lara, Owner
- Electronic mail address for privacy requests: info@farobookkeeping.com
"We," "us," and "Faro" below all mean Larimar Group LLC.
2. What we collect
If you only browse this website
Standard, non-identifying usage data. With analytics measurement enabled, Google Analytics sets cookies and records how the site is used — the pages you view, your approximate location and device type (from your IP address and browser), and how you arrived. This measures site traffic. It is never linked to your bookkeeping records, and we do not use it to build a personal profile of you. Section 6 lists the specific tools and how to opt out.
Our hosting provider, Cloudflare, also processes standard technical request data (IP address, browser type, requested page, timestamp) to deliver the site and defend it against attack.
If you submit the contact form or email us
Only what you choose to give us:
- Your name and email address (required)
- Your phone number and business name (optional)
- The service you're interested in and your approximate monthly transaction volume (optional)
- Whatever you write in the message field
- The language you contacted us in, and the date and time of the submission
Our contact form is protected by Cloudflare Turnstile, which distinguishes people from automated bots. Turnstile is used specifically because it performs this check without the behavioral profiling and cross-site tracking that conventional CAPTCHA services rely on.
If you book a call
Our booking page is hosted by Microsoft Bookings, part of the Microsoft 365 subscription we already use. Booking a call collects:
- Your name, email address and phone number (all required — the appointment is a phone call, so we need a way to reach you)
- Your business name (required), which is what we use to prepare for the call
- Anything you write in the notes field (optional)
- The date and time you chose
We do not ask for a street address, and the booking page never asks for payment details. Microsoft processes the booking on our behalf as a service provider. If you do not go on to become a client, it is deleted on the same schedule as any other enquiry — see section 7.
If you become a client
To do bookkeeping we necessarily handle your business financial records: bank and credit card statements, transaction detail, invoices, receipts, payroll summaries, and prior tax returns or accounting files where relevant. This may include an Employer Identification Number, and in the case of a sole proprietor it may include a Social Security number. All of it is treated as confidential client information under the terms of your engagement letter.
3. How we use it
- To answer your inquiry and arrange a consultation
- To prepare a quote and an engagement letter
- To perform the bookkeeping services you have engaged us to perform
- To communicate with you about your account and your books
- To meet our own legal, tax, and recordkeeping obligations
- To protect this website and our systems against fraud and abuse
That is the complete list. We do not use your information for any purpose you did not come to us for.
4. What we never do
- We do not sell your personal data. Not to data brokers, not to lead-generation services, not to anyone, for money or for any other valuable consideration.
- We do not process your data for targeted advertising and we run no advertising on this site.
- We do not share your information with third parties for their own marketing purposes.
- We do not use your business financial data to train artificial intelligence models, our own or anyone else's.
- We do not add you to a mailing list because you contacted us. If we ever offer a newsletter, it will require you to opt in deliberately.
5. Who else may see it
We use a small number of service providers to operate the practice. Each one processes data only on our instructions and only as needed to provide their service. Rhode Island law (R.I. Gen. Laws § 11-49.3-2(c)) requires that any third party receiving personal information be bound by written contract to protect it, and ours are.
- Cloudflare, Inc. — website hosting, network security, and bot protection (Turnstile)
- Resend — delivery of contact form submissions to our inbox
- Microsoft Corporation — business email and encrypted document storage (Microsoft 365)
- Intuit Inc. — QuickBooks Online, where client accounting records are maintained. Note that your QuickBooks subscription is held in your own name, under Intuit's own terms and privacy policy.
Beyond those, we disclose information only: with your explicit direction (for example, to your CPA or lender); where required by law, subpoena, or court order; or where necessary to establish or defend a legal claim. If we are ever legally compelled to disclose your information, we will tell you unless we are prohibited from doing so.
6. Cookies and tracking
With analytics measurement enabled, this website uses Google Analytics. This provider sets cookies and similar identifiers to measure how visitors use the site. It may collect your IP address, device and browser details, the pages you view, and actions such as submitting the contact form.
How to opt out. You can install the Google Analytics Opt-out Add-on, and block or delete cookies in your browser settings.
We honor Global Privacy Control and browser Do Not Track signals, and we do not sell your personal data. Two narrow security cookies are always present regardless: Cloudflare may set a short-lived bot-management cookie (__cf_bm), and Cloudflare Turnstile may store a temporary token on the contact page while it verifies your submission. Neither is used to track you across other websites.
7. How long we keep it
Rhode Island law prohibits retaining personal information longer than reasonably needed (R.I. Gen. Laws § 11-49.3-2(b)). Our schedule:
- Inquiries that do not become clients: deleted within 24 months of the last contact.
- Client records: retained for seven years after the engagement ends, then securely destroyed. Seven years matches the outer bound of IRS record retention guidance and the period during which you are most likely to need these records.
- Engagement letters and billing records: retained for seven years for our own legal and tax obligations.
- Website security logs: retained by Cloudflare on their standard schedule, which is measured in days.
If you ask us to delete your information sooner and we have no legal obligation to keep it, we will.
8. How it is protected
We maintain a risk-based written information security program as required by R.I. Gen. Laws § 11-49.3-2(a), appropriate to the size of the practice and the sensitivity of the data. Controls include multi-factor authentication on every system that touches client data, encryption in transit and at rest, least-privilege access, secure document exchange, and annual review.
Our full security posture, including our position on the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, is set out on the data security page.
If personal information about you were ever compromised, we would notify you in accordance with R.I. Gen. Laws § 11-49.3-4 — in the most expedient time possible and no later than 45 calendar days after confirming the breach.
No system is immune to compromise, and any business that tells you otherwise is not being straight with you. What we commit to is real controls, honest disclosure, and prompt notice.
9. Your rights and how to use them
Depending on where you live, you may have statutory rights over your personal data. Rather than parse which law covers which visitor, we extend the following to everyone who contacts us, regardless of residency:
- Access — ask what personal information we hold about you
- Correction — have inaccurate information fixed
- Deletion — ask us to delete it, subject to records we are legally required to keep
- Portability — receive a copy in a usable format
- Opt out — of sale, targeted advertising, and profiling. Already the default here, since we do none of them.
To exercise any of these, email info@farobookkeeping.com. We will respond within 45 days. We may need to verify your identity first, and for client financial records that verification will be meaningful — protecting your data means not handing it to someone who merely claims to be you.
There is no charge for a reasonable request. If you are unhappy with our response, you may contact the Rhode Island Attorney General's Consumer Protection Unit.
10. Children
This website is intended for business owners and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, email info@farobookkeeping.com and we will delete it.
11. Changes to this notice
If we change this notice we will update the date at the top. For any change that materially affects how we handle your information, we will notify current clients by email rather than relying on you to re-read this page.
12. How to reach us
Larimar Group LLC, d/b/a Faro Bookkeeping
Attn: Christopher Lara, Controller
Pawtucket, Rhode Island
info@farobookkeeping.com
This notice describes our practices in plain language. It is not a substitute for legal advice, and it does not modify the terms of any signed engagement letter, which controls in the event of a conflict.