SendTax Privacy Policy (U.S.)
Effective date: October 1, 2026
Who we are
SendTax is a product of Howell & Gibbs LLC ("SendTax," "we," "us," "our").
Mailing address: 418 Broadway, STE R, Albany, NY 12207, USA. Principal office for NY filings: Albany County, New York.
Scope & audience
This Policy applies to: (a) PTIN-holding tax preparers who use SendTax; and (b) U.S. tax filers (age 18+) who use SendTax to share documents with a preparer.
We operate only in the United States. We do not knowingly serve minors.
What we collect
Information you provide directly:
- Tax documents & data you or your preparer upload or connect (e.g., W-2/1099s, K-1s, receipts, IDs, messages).
- Account & contact info (name, email, phone).
- Payments handled by Stripe; SendTax does not store full card numbers. Stripe is a PCI-DSS Level 1 provider; using hosted Checkout/Elements keeps our PCI scope minimal (typically SAQ A).
Information from sign-in providers: if you choose to sign in with Google or Apple, they share your name and email address with us. We never see your Google or Apple password.
Information collected automatically:
- Log & usage data: IP address, browser type, pages visited, actions taken, timestamps, and referring URLs.
- Device data: device type, operating system, and unique device identifiers.
Cookies & tracking technologies
We use cookies and similar tracking technologies to operate the service, understand how it is used, and improve it. We use:
- Essential cookies — required for authentication and session management. These cannot be disabled.
- Analytics — we use PostHog for product analytics so we understand how users move through SendTax. Autocapture and session replay are disabled; we only record explicit milestone events. No tax document content is captured.
You can instruct your browser to refuse cookies, but some parts of the service may not function properly as a result.
How we use data
- Provide the service (receive, store, transmit to the designated preparer; support; troubleshooting).
- Security & compliance (fraud, incident response, legal obligations).
- Improvement: We measure how well SendTax works, for example how often it recognizes a document type correctly, and use those counts to improve it. We do not use the contents of your tax documents to build datasets or to train models unless you sign a separate consent for a specific document. You can withdraw that consent at any time. Tax return information is handled as IRC §7216 and its regulations require. We do not disclose it outside the U.S. without §7216-compliant consent (and note special limits for SSNs).
No ads / no selling: We do not sell personal information and we do not use tax data for marketing.
If state privacy laws apply, most "customer financial" data is GLBA-exempt, but we still honor applicable non-GLBA rights for residual data like site analytics.
Legal bases for processing
We process your personal information only when we have a valid legal basis to do so:
- Contract performance — processing necessary to provide the service you signed up for.
- Legal obligation — processing required to comply with applicable law (e.g., IRS e-file requirements, GLBA, NY SHIELD Act).
- Legitimate interests — operating, securing, and improving SendTax, where those interests are not overridden by your rights.
- Consent — where required by law (e.g., IRC §7216 consent for certain uses of tax return information), we obtain your explicit consent before processing.
Sharing
We share data only with:
- Your preparer / firm you select.
- Service providers in the United States that run parts of SendTax for us (hosting, storage, key management, sign-in, email, error monitoring, analytics, and document classification). Each gets only what its service needs and is bound by its terms to protect it. Where tax return information is involved, we disclose it to them only to provide SendTax, as IRC §7216 allows for auxiliary services. The current list is on our Sub-Processor List.
- Payments via Stripe.
- Legal (regulatory, court orders, safety).
Business transfers: If SendTax is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website before your data becomes subject to a different privacy policy.
Data location
We store and process data in the United States.
If a non-U.S. transfer is ever proposed, we will seek §7216-compliant consent first (and would not include SSNs in non-U.S. disclosures).
Retention & deletion
- Default: We retain customer information for up to 7 years after last activity on your account, consistent with AICPA professional guidance for tax-data retention and applicable tax-data retention obligations. Specific data categories may be retained for shorter or longer periods as described in our Data Retention & Deletion Policy.
- IRS e-file records: certain authorizations (e.g., Forms 8878/8879) must be retained 3 years (due date or IRS-received date, whichever is later), per IRS Publication 1345.
Security
We maintain a written information security program consistent with the FTC Safeguards Rule (access control; encryption; secure development; monitoring/logging; incident response; vendor oversight; annual reporting) and with NY SHIELD Act "reasonable safeguards". Some safeguards are still on our roadmap, and our Written Information Security Program marks them as such: a written risk assessment, and multi-factor authentication (MFA) for tax-professional accounts, which isn't available yet.
If a notification event involves 500+ consumers, we notify the FTC within 30 days of discovery as required, and provide any required state notices (NY presently requires consumer notice, with updated timelines).
For e-file ecosystem expectations in IRS Pub. 1345, our domain is registered to a U.S. entity and we commit to next-business-day incident reporting to the IRS. Two expectations are on our roadmap and not in place yet: an EV TLS certificate for public-facing tax sites, and weekly external ASV scans.
Your choices & rights
- No marketing emails by default; you can opt-in anytime, and opt-out at any time.
- You may request access, correction, or deletion of account information. Some data cannot be deleted while needed for legal obligations (e.g., 3-year retention items) or platform security.
- State privacy rights (e.g., CA/CO/CT/VA/UT etc.) generally do not apply to GLBA-covered customer financial data but can apply to non-GLBA data (site usage); we honor those rights as applicable.
To exercise any of these rights, email us at [email protected] with your request. We will respond within 30 days.
Do Not Track
Some browsers offer a "Do Not Track" (DNT) setting. We currently do not respond to DNT signals, as no uniform standard for doing so has been established. If a standard is adopted, we will update this policy accordingly.
Children
Not for individuals under 18. We do not knowingly collect children's data.
Changes
We will post updates and change the "Effective date." Material changes will be notified to account holders.
Contact
[email protected]
Howell & Gibbs LLC, 418 Broadway, STE R, Albany, NY 12207, USA