Privacy Policy
How we collect, use, and protect your information
Last updated: February 9, 2026
Overview
CK Reynolds Tax Service (“we,” “us,” or “our”) is committed to protecting the privacy and security of your personal and tax information. This policy describes what information we collect, how we use it, how we protect it, and your rights regarding your data.
As an IRS Enrolled Agent, we are bound by IRS Publication 4557 (Safeguarding Taxpayer Data) and maintain strict data security standards.
Information We Collect
Account Information
- Name, email address, phone number
- Mailing address
- Account credentials (password stored as a one-way hash)
Tax Documents & Financial Information
- Tax forms you upload (W-2s, 1099s, receipts, and other documents)
- Information you provide during consultations (income, expenses, deductions)
- Prior-year tax returns
Payment Information
- Service tier selected and payment amount
- Card brand and last 4 digits (for your reference only)
Technical Information
- IP address and browser type (for security and login history)
- Login timestamps
- Session identifiers (stored as encrypted HttpOnly cookies)
How We Use Your Information
Tax preparation
To prepare and file your tax returns accurately
Account management
To maintain your secure client portal
Communication
Appointment reminders, document requests, and filing updates
Payment processing
To process service payments through Square
Security
To detect unauthorized access and protect your account
Legal compliance
To comply with IRS requirements and applicable laws
How We Protect Your Information
Encryption
- In transit: All data transmitted over HTTPS (TLS 1.3)
- At rest: Documents encrypted with AES-256 server-side encryption
- Passwords: Stored using bcrypt with a cost factor of 12 (one-way hash, never stored in plain text)
Access Controls
- Row-level security ensures you can only access your own data
- Admin access is role-restricted and logged in audit trails
- Session cookies are HttpOnly and secure (cannot be accessed by JavaScript)
- Password reset tokens expire after 15 minutes and are single-use
Infrastructure
- Database hosted on Supabase (AWS infrastructure, SOC 2 Type II compliant)
- Document storage on Backblaze B2 (encrypted at rest)
- All access logged for security audit purposes
Third-Party Services
We use the following third-party services to operate our platform. Each processes only the minimum data necessary:
| Service | Purpose | Data Shared |
|---|---|---|
| Square | Payment processing | Card details (directly to Square, never to us) |
| Supabase | Database hosting | Account and profile data |
| Backblaze B2 | Document storage | Uploaded documents (encrypted) |
| IONOS SMTP | Email delivery | Email address, message content |
| Twilio | SMS notifications | Phone number, message content |
We do not sell, rent, or share your personal information with any third parties for marketing purposes.
Data Retention
Tax documents
7 yearsPer IRS requirements (Pub 4557)
Account data
While activeRetained as long as your account is active
Payment records
7 yearsFor tax and legal compliance
Audit logs
3 yearsFor security purposes
Your Rights
You have the right to:
- Access — View all personal data we hold about you through your client portal
- Correct — Update your profile information at any time
- Delete — Request deletion of your account and associated data (subject to IRS retention requirements)
- Export — Request a copy of your data
- Opt out — Manage email and SMS notification preferences in your profile settings
Contact Us
If you have questions about this privacy policy or how we handle your data:
- Email: ckreynoldstaxservice@gmail.com
- Or use our contact form
IRS Pub 4557 Compliance
CK Reynolds Tax Service follows IRS Publication 4557 guidelines for safeguarding taxpayer data, including encryption at rest and in transit, access controls, secure document storage, and audit logging of all data access.