SHARPECPA

Sharpe CPA  /  Privacy

Privacy Policy

What we collect through this website and the client portal, why, who we share it with, how long we keep it, and the rights you have under California law.

Effective date: August 22, 2026  ·  Last updated: August 22, 2026

1. Who we are

This website and the client portal at sharpecpa.com/portal are operated by James D. Sharpe, Certified Public Accountant ("Sharpe CPA," "we," "us," or "our"), licensed by the California Board of Accountancy, CPA License #38745.

We provide tax preparation and planning, accounting and financial statement work, governmental finance advisory work, and accounting software offered on subscription and as downloads. We do not currently perform attest engagements.

2. What this policy covers

Information reaches us in three ways, and it is worth separating them, because different law applies to each.

  • Website information. What you send through the site or by email, and the ordinary technical records our web server keeps when you visit.
  • Account and subscription information. What you give us to open a portal account, subscribe to an application, and use it.
  • Engagement information. The returns, books, schedules, payroll records, audit evidence and related documents you send us in the course of an engagement, whether through the portal or otherwise.

This policy covers all three. Engagement information is subject to additional restrictions under federal tax law and the rules of the accounting profession, described in section 11, which limit what we may do with it beyond anything this policy permits.

This policy does not cover information you give to a third party directly, or the practices of any website we link to.

3. Information we collect

The table below lists the categories of personal information we have collected in the preceding twelve months, using the category names defined in the California Consumer Privacy Act, with where each comes from, why we collect it, and how long we keep it.

CategoryWhat this means for usWhere it comes from Why we collect itHow long we keep it
Identifiers Name, business name, postal and email address, telephone and mobile number, portal username, IP address You, directly; your web browser To identify you, correspond with you, operate your account and send the alerts you have asked for For the life of the relationship and then with the engagement records below
Customer records (Cal. Civ. Code § 1798.80) Billing address, the fact and amount of a payment, subscription status You; our payment processor To bill you, collect payment and keep our own books Seven years, as our accounting records
Commercial information Which applications you subscribe to, what you have downloaded, the services engaged You; our own records To provide what you have subscribed to and support it Seven years
Internet activity Pages requested, date and time, browser and operating system, referring page; and, inside the portal, a log of every sign-in, upload, download, share and failed attempt Your browser; our servers To keep the site working and to detect and investigate misuse of an account Web server logs, typically 12 months. Portal activity log, for the life of the account — it is a security record
Professional or employment information Occupation, employer, licence or firm details for CPAs who open an account You, directly To know who we are dealing with and what an application should show them For the life of the account
Sensitive personal information Social Security and other taxpayer identification numbers, financial account numbers, and the contents of documents you upload — appearing in tax and accounting records you send us You, in the course of an engagement Solely to perform the engagement and to meet our own legal obligations Through the federal and California assessment periods that apply to the return — generally at least seven years — and longer where a record supports a position on a later return
Inferences None. We do not build profiles or score anyone

We do not collect biometric information, precise geolocation, or the contents of your mail, email or text messages other than what you send to us.

Why engagement records are kept as long as they are

A tax return can be examined for as long as the statute of limitations on assessment runs. That is ordinarily three years federally, six where there has been a substantial omission of gross income, four for California, and unlimited where no return was filed or the return was fraudulent. Separately, California law requires audit documentation to be kept for a minimum of seven years. Our general rule is seven years, and files older than that are destroyed.

Two things are held longer, and one is destroyed sooner:

  • Audit documentation is held past seven years for as long as any regulatory or legal proceeding involving this practice is pending.
  • A record that supports a position on a return not yet filed — a basis figure, a depreciation schedule, a carryforward — is kept until that position closes, however old it is. Destroying it would leave a live position undocumented.
  • Paper files are shredded at three years. The electronic record is the record of this practice; paper is a working copy and goes first.

We review this schedule at least once a year and securely destroy records that have passed it. Retention here is a decision we revisit, not a habit: anything we cannot give a reason to keep is destroyed.

4. How we use it

  • To perform the engagement you have retained us for.
  • To operate your portal account and any application you subscribe to.
  • To bill you and collect payment.
  • To correspond with you about your work, your account and your subscriptions.
  • To send the text or email alerts you have switched on.
  • To secure the site and the portal, and to investigate misuse.
  • To meet our own obligations under tax law, the rules of the California Board of Accountancy, and our professional standards.

We do not use engagement information to market anything to you, and we do not use it for any purpose other than the engagement itself except as section 11 describes.

5. Who we share it with

We share personal information only with the following, and only so far as each needs it:

  • Service providers who process it on our instructions and may not use it for their own purposes — our web host, our payment processor, and the messaging provider that delivers text alerts.
  • Taxing authorities and other government bodies, where you have authorised a filing or the law requires it.
  • Our own attorneys, insurers, peer reviewers and professional advisors, in confidence.
  • In response to a subpoena, summons, court order or a validly issued request from a regulator, including the California Board of Accountancy. Where we are permitted to tell you first, we will.
  • A successor, if the practice is sold or merged. Client records would move only as the professional rules and section 11 allow.

Every client we do tax work for is also covered by a non-disclosure agreement between us.

Testimonials

The only other place a client's information appears publicly is a testimonial, and only where that client has agreed to it in writing. A testimonial identifies someone as a client of this practice, which is itself a disclosure, so we treat it as one: we ask for a written consent that names the use, we show the client the exact wording before it is published, and we remove a testimonial at any time on request, without being asked why. Nobody is paid or given a discount for one, and nothing in a testimonial is written by us on a client's behalf.

6. We do not sell or share your information

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in California law. We have not done so in the preceding twelve months. There is nothing here to opt out of, which is why you will not find a "Do Not Sell or Share My Personal Information" link on this site.

7. Sensitive personal information

Tax and accounting work cannot be done without sensitive information. We collect it only to perform the engagement, to bill for it, and to meet our own legal obligations — all of which are purposes for which California law does not permit a limitation request. We do not use or disclose it to infer anything about you.

8. Cookies and tracking

The public pages of this site set no advertising or analytics cookies. The portal sets one strictly necessary session cookie, which identifies your signed-in session and nothing else; it is marked HttpOnly and SameSite, is sent only over an encrypted connection, and is discarded when you sign out or the session times out.

We honour a Global Privacy Control signal. Since we do not sell or share personal information, the signal has nothing to act on, but it is respected all the same.

9. Your California privacy rights

If you are a California resident you have the right to:

  • Know what personal information we have collected about you, where it came from, why, who we disclosed it to, and to receive a copy.
  • Delete personal information we have collected from you.
  • Correct personal information you believe is inaccurate.
  • Limit the use of sensitive personal information — though, as section 7 explains, our uses are ones the law exempts.
  • Opt out of sale or sharing — we do neither.
  • Not be discriminated against for exercising any of these. We will not charge you differently, or give you a lesser service, because you did.

One limit worth stating plainly. A request to delete cannot reach records we are required to keep. Tax return information, workpapers and audit documentation are subject to retention requirements under federal and California law and under our professional standards, and we will keep those for the periods stated in section 3 even after a deletion request. We will tell you exactly what we kept and why.

10. How to make a request

Call (530) 592-5046 or email tax@sharpecpa.com with "Privacy request" in the subject line. Both reach the same person.

We will verify who you are before we act, in proportion to what is being asked — more carefully for a copy of tax records than for a correction to a mailing address. If you have a portal account, signing in is part of that verification. We will confirm receipt within ten business days and respond within forty-five calendar days, extending once by another forty-five where the request is complex, in which case we will tell you before the first period runs out.

An authorised agent may act for you with written permission signed by you, and we may still ask you to confirm it directly.

11. Client tax information and professional confidentiality

Three separate obligations sit on top of ordinary privacy law here, and we would rather set them out than leave them implied.

Internal Revenue Code § 7216

We do not use or disclose your tax return information for any purpose other than preparing and filing your returns, except with your written consent or where a specific regulation permits it. That is the rule under IRC § 7216 and Treasury Regulation § 301.7216, and it carries criminal penalties. Where a consent is required, we will ask you for one that names the recipient and the specific purpose, in the form the regulation requires, and you are free to decline — declining does not affect the work we do for you.

The Confidential Client Information Rule

As a CPA we are bound by the AICPA Code of Professional Conduct § 1.700.001 and the corresponding California rules, which prohibit disclosing confidential client information without your specific consent, subject to narrow exceptions for a validly issued subpoena or summons, a peer review, and an inquiry by a professional or regulatory body. Those obligations survive the end of an engagement, and they survive this policy: where this policy and the professional rules differ, the stricter of the two governs.

The Gramm-Leach-Bliley Act and the FTC Safeguards Rule

Some of what we hold is also subject to the federal Gramm-Leach-Bliley Act. We maintain a written information security program consistent with the FTC Safeguards Rule (16 C.F.R. Part 314) and IRS Publication 4557, covering the whole practice regardless of how any particular record is classified. Where the Act applies to a record, California law treats it differently from ordinary website data — but that does not reduce what we have committed to here. We will honour a verifiable request about any information we hold, subject only to the retention limits in section 9, and it does not affect your rights in the event of a breach under Cal. Civ. Code § 1798.150.

12. How we protect information

This is a small practice, and its security comes from keeping the number of places your information can be rather than from a large apparatus.

Where it lives

  • Client records are held on equipment this practice owns and controls.
  • Storage media holding client records are kept under lock in a private residence, not in a shared or public office.
  • Media are retained and destroyed under the schedule in section 3, which is reviewed at least once a year.

How it moves

  • We do not email tax returns. A completed return reaches a client through a secure drop box, never as a mail attachment.
  • Filing data exchanged with the California Department of Tax and Fee Administration moves through the CDTFA's own secure drop box.
  • Documents you send us should come through the client portal for the same reason: it keeps them off mail servers nobody here controls.

The client portal

The portal was written here rather than bought, so we can be specific about it:

  • It is served only over an encrypted (HTTPS) connection.
  • Passwords are stored as one-way hashes and are never readable by us. Nobody here can look up your password; we can only issue you a new one.
  • Accounts lock temporarily after repeated failed sign-in attempts, and sessions end automatically after a period of inactivity.
  • Uploaded documents are stored under randomised names, in a directory placed outside the reach of ordinary web requests, and every download is re-checked against the requester's account before a single byte is sent.
  • Every form is protected against cross-site request forgery.
  • Every sign-in, upload, download, share and failed attempt is logged with a timestamp.

Where text alerts are switched on, please note that text messages travel unencrypted through the messaging provider and the mobile carriers. We set the level of detail in those messages deliberately for that reason, and they never carry document contents.

No method of transmission or storage is perfectly secure, and we do not claim otherwise.

13. Payments and subscriptions

Subscriptions are billed through a third-party payment processor. Card numbers are entered on the processor's own hosted page and never reach our server — we never see them, store them, or have any ability to retrieve them. What comes back to us is the fact of a payment, its amount and date, and the last four digits and card brand for your reference. The processor handles that information as an independent business under its own privacy policy.

14. Children

Our services are directed to businesses, to accounting professionals, and to adults. We do not knowingly collect personal information from anyone under sixteen years of age, and we do not sell or share the personal information of minors, because we do not sell or share anyone's. If you believe a child has provided us information, contact us and we will delete it.

A dependent's information appearing in a parent's tax return is engagement information belonging to that engagement, and is handled under section 11.

15. Links to other websites

This site links to other websites, including taxing authority pages, the California Board of Accountancy, and our own separate service at taxtraks.net. We do not control those sites and are not responsible for their privacy practices. Their policies govern once you leave ours.

16. Changes to this policy

We review this policy at least once every twelve months and update it whenever our practices change. When we do, the revised version is posted at this address and the "Last updated" date at the top changes. If the changes are material — meaning they meaningfully affect how we collect, use or disclose personal information — we will say so prominently on this page for at least thirty days and notify anyone with an active portal account. We will not use information we have already collected for a materially different purpose without telling you first and obtaining your consent.

17. How to contact us

For any question about this policy, or to exercise a privacy right:

James D. Sharpe, CPA
California CPA License #38745
Telephone: (530) 592-5046
Email: tax@sharpecpa.com

This policy is provided in an accessible, printable format. If you need it in an alternative format, call the number above and we will provide one.