Skip to main content

Major tax services are sending your data to Meta and Google

A new report claims that Meta’s tracking Pixel has been used to collect your financial information when using popular tax filing services to send in your return. This is disturbing news for taxpayers that likely assumed these online tax services were keeping such information locked up securely.

The types of data collected vary but are said to possibly include your filing status, adjusted gross income (rounded to the nearest thousand), and the amount of your refund (rounded to the nearest hundred). This information would be quite useful in targeting advertising to those with disposable income and help determine which people to target when tax refunds arrive. As if this wasn’t bad enough, your name, phone number, and the names of dependents such as your children are being obfusticated then sent to Meta by some tax filing services. According to the report by The Markup the obfustication is reversible.

SeniorLiving.Org/Flickr

The tax filing services named by this report included H&R Block, TaxAct, and TaxSlayer, some of the largest and most trusted companies to offer online filing services to U.S. taxpayers. Another major service, TurboTax, uses ad tracking but apparently doesn’t send sensitive private data. It’s not just Meta involved in this privacy issue. TaxAct is supposedly sending similar tax filing data to Google as well.

The particularly worrying detail about tax filing services using Meta and Google tracking and sending financial data is that the social media and search giants have been under scrutiny for several years regarding the use of sensitive information to target advertising. Privacy concerns were a major reason for Meta CEO Mark Zuckerberg, Google CEO Sundar Pichai, and other tech leaders, being called to testify in a Congressional hearing in 2018. Now we have another major privacy issue that hits even closer to home with U.S. tax data being collected.

There’s nothing to suggest that Meta or its advertisers are using your private financial records to direct advertising isn’t known. Meta’s tracking Pixel is supposed to help website owners identify when a Facebook ad is clicked, leading to a visit to their website, carrying anonymous data that justifies the expense of the advertising cost. As Meta notes on its developer website, form fields and optional data can be included but are not required. This is similar to how Google’s advertising platform works. To be clear, neither Meta nor Google require this information to be sent with tracking data. The decision to share your sensitive tax data is being made by these tax filing services.

According to a Meta spokesperson, “Advertisers should not send sensitive information about people through our Business Tools. Doing so is against our policies and we educate advertisers on properly setting up Business tools to prevent this from occurring. Our system is designed to filter out potentially sensitive data it is able to detect.”

Editors' Recommendations

Alan Truly
Computing Writer
Alan is a Computing Writer living in Nova Scotia, Canada. A tech-enthusiast since his youth, Alan stays current on what is…
If you use PayPal, your personal data may have been compromised
A person holds a mobile phone with the PayPal app open.

PayPal has recently suffered a massive data breach, and if you were one of the affected users, your details may have been leaked. Given the nature of a PayPal account, the exposed data includes some of the most sensitive information, which could put those users at risk of identity theft.

The company is taking steps to protect the accounts from further damage. Here's what we know about what happened and how to protect yourself.

Read more
Hackers just stole LastPass data, but your passwords are safe
A physical lock placed on a keyboard to represent a locked keyboard.

The developers behind password management software LastPass have just shared some concerning news: Bad actors were recently able to access “elements of our customers’ information” in a recent security breach.

It’s the second time in just a couple of months that LastPass has suffered a security incident, and it appears the two events are directly linked. That’s because LastPass’s developers say that the unauthorized party was able to access customer data “using information obtained in the August 2022 incident.”

Read more
iCloud might be sending your photos to strangers’ computers
Microsoft has released a new Windows 11 feature that makes the OS photos app compatible with Apple's iClould.

Microsoft's newly announced iCloud for Windows app, which is intended to connect your iCloud to your Photos app on your PC, has already developed a glitch that is sending photos to the wrong users.

Several users have reported instances on the MacRumors Forums where they have received someone else's images when attempting to load their iCloud data onto a Windows device, and similarly had their own images sent elsewhere. Some users also detailed receiving corrupted videos that played back only black screens with scan lines. Users began sharing their issues with the app on November 17 after Microsoft unveiled the feature the Wednesday prior.

Read more