SendTax Privacy Policy (U.S.)

Effective date: October 1, 2026

Who we are

SendTax is a product of Howell & Gibbs LLC ("SendTax," "we," "us," "our").

Mailing address: 418 Broadway, STE R, Albany, NY 12207, USA. Principal office for NY filings: Albany County, New York.

Scope & audience

This Policy applies to: (a) PTIN-holding tax preparers who use SendTax; and (b) U.S. tax filers (age 18+) who use SendTax to share documents with a preparer.

We operate only in the United States. We do not knowingly serve minors.

What we collect

Information you provide directly:

Information from sign-in providers: if you choose to sign in with Google or Apple, they share your name and email address with us. We never see your Google or Apple password.

Information collected automatically:

Cookies & tracking technologies

We use cookies and similar tracking technologies to operate the service, understand how it is used, and improve it. We use:

You can instruct your browser to refuse cookies, but some parts of the service may not function properly as a result.

How we use data

No ads / no selling: We do not sell personal information and we do not use tax data for marketing.

If state privacy laws apply, most "customer financial" data is GLBA-exempt, but we still honor applicable non-GLBA rights for residual data like site analytics.

Legal bases for processing

We process your personal information only when we have a valid legal basis to do so:

Sharing

We share data only with:

Business transfers: If SendTax is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website before your data becomes subject to a different privacy policy.

Data location

We store and process data in the United States.

If a non-U.S. transfer is ever proposed, we will seek §7216-compliant consent first (and would not include SSNs in non-U.S. disclosures).

Retention & deletion

Security

We maintain a written information security program consistent with the FTC Safeguards Rule (access control; encryption; secure development; monitoring/logging; incident response; vendor oversight; annual reporting) and with NY SHIELD Act "reasonable safeguards". Some safeguards are still on our roadmap, and our Written Information Security Program marks them as such: a written risk assessment, and multi-factor authentication (MFA) for tax-professional accounts, which isn't available yet.

If a notification event involves 500+ consumers, we notify the FTC within 30 days of discovery as required, and provide any required state notices (NY presently requires consumer notice, with updated timelines).

For e-file ecosystem expectations in IRS Pub. 1345, our domain is registered to a U.S. entity and we commit to next-business-day incident reporting to the IRS. Two expectations are on our roadmap and not in place yet: an EV TLS certificate for public-facing tax sites, and weekly external ASV scans.

Your choices & rights

To exercise any of these rights, email us at [email protected] with your request. We will respond within 30 days.

Do Not Track

Some browsers offer a "Do Not Track" (DNT) setting. We currently do not respond to DNT signals, as no uniform standard for doing so has been established. If a standard is adopted, we will update this policy accordingly.

Children

Not for individuals under 18. We do not knowingly collect children's data.

Changes

We will post updates and change the "Effective date." Material changes will be notified to account holders.

Contact

[email protected]

Howell & Gibbs LLC, 418 Broadway, STE R, Albany, NY 12207, USA