Legal
Privacy policy
Last updated …
This policy describes how World of Torah, Inc. d/b/a Shtim (“Shtim,” “we,” “us”) handles information in connection with this website and the Shtim client portal.
1. Two different kinds of information
It matters which of the following applies to a given piece of information, because our role differs.
Information about you, as a visitor or contact
Information you give us about yourself or your firm — a name, email address, phone number, firm name, and anything you write in a message to us. We control this information and use it to respond to you and to administer the services.
Firm and matter records, as a service provider
Trust-account records that an enrolled law firm supplies or that we obtain in performing reconciliation services — matter names and numbers, balances, transactions, payee information, and related documents. We process this information on behalf of the firm, for the purpose of providing the services and as directed by the engagement agreement. The firm remains responsible for its own professional obligations regarding client confidentiality.
2. What this website collects
These public pages do not set cookies, do not run advertising or analytics trackers, and do not build profiles of visitors.
- Inquiry form. The Get Started form collects the firm and contact details you type into it, together with any note you add. Depending on how the form is configured, it either opens a message in your own email application or transmits the fields to us so that we can respond. We ask that you not include confidential client information, account numbers, or credentials in it.
- Hosting logs. Our hosting provider processes standard request information, including IP address, user agent, and the pages requested, in order to deliver the site and protect it from abuse.
- Web fonts. Typefaces are requested from Google Fonts. Making that request discloses your IP address and user agent to Google, which is subject to Google’s own privacy practices.
3. What the client portal collects
For enrolled firms, the portal holds account and firm details, portal user accounts and authentication data, matters and balances, imported and normalized transaction records, matter and payee assignments and the submissions behind them, reconciliation history, documents you upload, the executed engagement agreement, billing records, and audit-log entries recording actions taken in the system.
Shtim stores a bank name and the last four digits of an enrolled account. Shtim does not ask for, and should not be given, online banking credentials or authority to transact on an account.
4. How information is used
- To respond to inquiries and administer onboarding.
- To perform, maintain, support, and improve the reconciliation services.
- To authenticate users, enforce permissions, and maintain audit records.
- To calculate and process fees and to maintain billing records.
- To protect the security and integrity of the services and to investigate suspected misuse.
- To meet legal, regulatory, and recordkeeping obligations.
We do not sell personal information, and we do not use firm or matter records for advertising.
5. Service providers
We use third-party providers to operate the services, which may include hosting, databases, cloud storage, email, payment processing, software tooling, and, as described in the engagement agreement, automation and artificial-intelligence services. Providers receive only what they need to perform their function.
Payment details are collected and maintained by our payment processor. Shtim does not store full card or bank-account credentials when those credentials are held directly by the processor.
We use reasonable care in selecting and using third-party providers, but we do not warrant or guarantee the security, confidentiality, availability, privacy practices, or data-retention practices of any provider.
6. Disclosure
We disclose information only: to the enrolled firm whose records they are, and its authorized portal users; to service providers as described above; where the firm directs us to; where required by law, subpoena, court order, or other legal process; to establish or defend legal claims; and in connection with a corporate transaction, subject to equivalent protections.
7. Security
We maintain administrative, technical, and physical safeguards intended to protect information, including encryption in transit and at rest, access controls and role-based permissions, tenant separation, audit logging, and backups. Details are described on our Security page.
No system is guaranteed secure. Shtim does not provide cybersecurity or fraud-detection services and does not guarantee detection or prevention of any unauthorized access or data incident.
8. Retention
We retain firm and matter records for as long as the account is enrolled and afterward for the period set out in the engagement agreement or applicable retention configuration, and as needed to meet legal and recordkeeping obligations, resolve disputes, and enforce agreements. Inquiry correspondence is retained for as long as needed to respond and for our ordinary business records.
9. Your choices
You may ask us to correct or delete contact information we hold about you by writing to us. Where information belongs to an enrolled firm’s records, please direct requests to the firm; we act on those records at the firm’s direction and subject to our legal and recordkeeping obligations. Depending on where you live, you may have additional rights under applicable law, and we will honor those rights as required.
10. Children
The services are intended for law firms and their personnel. They are not directed to children, and we do not knowingly collect information from children.
11. Changes
We may update this policy. The date at the top reflects the current version. Material changes affecting enrolled firms will be communicated through the portal or by email.
12. Contact
Questions about this policy: email us, or call us. …