Tax prep websites have been sending sensitive financial data to Facebook

Meta's Pixel is once again harvesting private data without users' knowledge.

Sponsored Links

MIAMI, FL - DECEMBER 22:  A H&R Block office is seen on the day President Donald Trump signed the Republican tax cut bill in Washington, DC  on December 22, 2017 in Miami, Florida. Kathy Pickering, vice president of regulatory affairs and executive director of The Tax Institute at H&R Block released a statement about the new tax bill saying, " It's going to change the way you think about and plan your income taxes. You'll need to take a fresh look at your individual situation to know your outcome and new strategies to use to get the best tax outcome."  (Photo by Joe Raedle/Getty Images)
Joe Raedle/Getty Images

Meta's Pixel tracking tool is causing more headaches, this time for people filing their taxes online. The Markup has discovered that large tax prep services like H&R Block, TaxAct and TaxSlayer have been sending users' sensitive contact and financial information to Facebook through the Pixel. This sometimes included income data, filing statuses and even kids' college tuition grants.

Intuit's TurboTax also uses the Pixel to send data, although that's limited to usernames and the last sign-in dates for given devices. The tool isn't used beyond the login page, and a spokesperson told The Markup that the non-tax info goes to marketers to provide a "better customer experience." You don't see ads for TurboTax on Facebook if you already have an account, for instance. TaxAct is also delivering financial data to Google through that company's analytics tool. 

The companies involved are altering or reevaluating their uses of the Meta Pixel. TaxAct has stopped sending financial data through the tracker, although it's still transmitting similar content to Google as of this writing. TaxSlayer has pulled the Pixel to rethink its usage. H&R Block hasn't changed its approach, but a spokesperson told The Markup the tax firm will "review the information."

Turn on browser notifications to receive breaking news alerts from Engadget
You can disable notifications at any time in your settings menu.
Not now

In a statement to Engadget, a Meta spokesperson pointed barring advertisers from sharing sensitive info, and noted that the system is meant to filter out this content. Google's spokesperson, meanwhile, told The Markup the company had "strict policies" against targeting ads using sensitive content and that it anonymized analytics data to avoid linking it to users.

It's not clear if any of the tax filing sites were misusing the data. Whether or not they were, they could still face penalties for gathering details without permission. Internal Revenue Service regulations require that tax prep firms obtain signed consent for using info for any reason beyond the filing. None of the websites in the report mentioned Meta or Facebook by name, and in some cases had only generic disclosure agreements. The sites gave users the option to decline sharing tax data, but Facebook received it regardless of what users selected.

Meta is already in legal trouble over the Pixel. Two proposed class action lawsuits filed earlier this year accused the social media giant and hospitals of violating privacy laws by scooping up patient data without consent. The plaintiffs also claimed Meta failed to enforce its own policies. In that sense, the tax site revelation just adds to the company's problems.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission. All prices are correct at the time of publishing.
View All Comments
Tax prep websites have been sending sensitive financial data to Facebook