Privacy
Last updated August 2026. Written to match the platform as designed. Must be reviewed by counsel before launch.
The short version
We are a tax and accounting firm, which makes us a financial institution under federal law and puts your information under rules that are stricter than most websites face. We do not sell personal data. We do not send client information to advertising platforms. We do not use your tax return to decide what else to sell you unless you have signed a separate consent that says we may — and that consent is never a condition of your tax work.
Which laws apply
There is no single United States equivalent of the GDPR. Congress has not passed a comprehensive federal privacy law; the ADPPA and the American Privacy Rights Act both stalled. What applies to us instead is a combination:
| Regime | What it governs here |
|---|---|
| Gramm-Leach-Bliley Act and the FTC Safeguards Rule 16 CFR Part 314 |
Tax preparation firms are financial institutions under GLBA. We must run a written information security programme with a named qualified individual, risk assessments, encryption, multi-factor authentication, vendor oversight, training, testing and a written incident response plan — and notify the FTC within 30 days of discovering a breach affecting 500 or more consumers. |
| Internal Revenue Code section 7216 Treas. Reg. 301.7216 |
Criminal restriction on how a tax return preparer may use or disclose your return information. Anything beyond preparing your return — including using it to decide which other services to offer you — requires your prior written consent in a prescribed form. |
| IRS Publications 4557 and 5708 | Written Information Security Plan requirements for tax professionals, tied to PTIN obligations. |
| State comprehensive privacy laws | Around twenty are in force as of 2026, with further states enacted and taking effect later, each with its own thresholds and rights. Georgia has not enacted one, but we serve clients nationally, so we apply the rights below to everyone. |
| Fair Credit Reporting Act | Applies where a consumer report on an owner or guarantor is involved. Commercial credit files on a business are generally outside the FCRA. |
| CAN-SPAM and the TCPA | Email and phone or text marketing, including consent and opt-out. |
| State breach notification statutes | Notice to affected individuals and, in many states, the attorney general. |
Your tax return information
Section 7216 makes it a crime for a preparer to use or disclose your return information other than to prepare your return, unless an exception applies or you consent in writing. Two things follow, and we hold to both:
- Consent is separate and specific. If we want to use your return information to recommend business credit work, capital readiness, or any other non-tax service, we ask for a distinct written consent that names the purpose and the duration. It is not folded into the engagement letter.
- It is never a condition of service. Declining changes nothing about the tax work you receive or its price. You can withdraw consent at any time, and withdrawal stops future use.
Without that consent, our marketing to you can only rest on information the regulations permit us to use without it — such as sending general educational material to our client list. Our systems enforce this in software, not by policy alone: return information sits behind a consent gate, and the marketing and recommendation engines cannot read it unless a valid, live consent record exists for that client and that purpose.
What we collect
Contact details you submit; documents you upload for an engagement; tax and financial records necessary to perform it; business credit data retrieved with your consent; billing records and payment outcomes; and technical data such as pages viewed. We do not request Social Security numbers, EINs or bank details through marketing forms.
Payments
Card and bank details are handled by a PCI-DSS compliant payment processor. Card numbers never reach our systems. We retain the token, the last four digits, the brand, the amount and the outcome so we can service your account and meet record-keeping obligations.
Business credit data
The D&B account is yours. We hold no bureau subscription that reads it, we never ask for your D&B username or password, and nobody here signs in to D&B as you. What we hold is what you send us from your own file, and we hold and use it only after explicit written consent that records who authorised it, when, and for what purpose. You may withdraw that consent at any time, which stops any further use. Credit data you give us is not redistributed.
Automated processing and AI
We use automated analysis to compare records, detect inconsistencies, draft correction requests and prepare recommendations. Identifiers are minimised or masked before that processing where they are not required. Complete tax returns are not passed to third-party language models, and client data is not used to train them. A business credit report is the one document a client may choose to have read this way, from text they paste themselves and after the redaction described under “What we will never do”; it is optional and the figures can be typed instead. Decisions with legal or significant effects — eligibility, pricing, filings, submissions — are made by qualified people. Where a state law gives you the right to opt out of profiling in furtherance of decisions with legal or similarly significant effects, we honour it.
Marketing
Marketing consent is collected separately from the consents needed to deliver a service, and declining never affects the service you receive. Every marketing email carries an unsubscribe link that we action promptly. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we honour the Global Privacy Control and other recognised universal opt-out signals.
Your rights
Depending on your state you may have the right to confirm whether we process your personal data and access it, correct inaccuracies, request deletion, obtain a portable copy, opt out of sale, targeted advertising and certain profiling, and appeal a refusal. We extend this process to every client and enquirer regardless of state. Some data cannot be deleted while professional and legal retention obligations apply to it; we will tell you when that is the case and why.
To make a request, contact us at the address on the Contact page. We verify identity before acting, respond within the period applicable law requires, and tell you how to appeal if we decline.
Retention and security
Records are kept for the period professional and legal obligations require, then deleted. Data is encrypted in transit and at rest, access is least-privilege and behind multi-factor authentication, and material access to a client file is logged. If a breach affects your information we notify you as required by the applicable state statute, and we notify the FTC within 30 days where the Safeguards Rule requires it.