Draft — not yet in effect
Privacy Policy — draft
Drafting note
Not legal advice. Not reviewed by counsel. Draft v0.1 · 2026-09-24 · not yet published. Drafting notes in blockquotes; strip before publishing.
{{…}}= fill.Honesty rules for this page (from the brief and
privacy-checklist.md): no zero-data-retention claim, no certification claim, no "in progress" language for work not started.
Sidesheet Privacy Policy
Effective: {{EFFECTIVE_DATE}} · Last updated: {{EFFECTIVE_DATE}}
UNTAP LLC ("we") provides Sidesheet, a service that business brokers and accounting firms use to turn business tax returns into structured financial spreads. This policy explains what information we handle, why, and the choices you have.
1. Two kinds of information, two roles
| What it is | Our role | |
|---|---|---|
| Customer Data | Files our customers upload — mainly their clients' tax returns — and the spreads and exports we generate from them | Service provider. We process it only on our customer's instructions, under our Terms of Service. Our customer decides what to upload and controls it. |
| Account and website data | Information about the people who use our service or visit our website | We decide how it is used, as described in §3. |
If your information is in a tax return that one of our customers uploaded — for example, you own a business being valued — please contact that firm first; they control that data. We will help them respond, and you can also contact us (§9).
2. Customer Data (tax returns and spreads)
What we do with it: extract financial line items from uploaded returns, organize them into spreads, and let our customer review and export them. That is all.
What we never do with it:
- No AI training. We do not use Customer Data to train or fine-tune AI models. Our AI provider, Google Cloud, is contractually prohibited from doing so without our permission, which we do not give.
- No selling or sharing. We do not sell, rent, license, or share Customer Data. We are not a data broker.
- No combining. We do not combine one customer's data with another's or with outside data.
- No advertising or tracking. We do not use Customer Data for advertising, and we do not put third-party analytics or tracking tools on the pages where returns are uploaded or spreads are shown.
Quality improvement is opt-in. Only if a customer turns it on, named UNTAP LLC staff may review copies of that customer's uploads — after names, addresses and taxpayer identification numbers are removed automatically — to test and improve extraction accuracy. It never covers returns the customer firm prepared, can be turned off at any time (review copies are then deleted within 30 days), and is never used to train AI models or shared.
Where it goes: Customer Data is processed and stored in the United States by the subprocessors listed at https://sidesheet.co/legal/subprocessors: Google Cloud (hosting and AI extraction) and Supabase (database, sign-in, and file storage). Each is bound by a written agreement limiting its use of the data to providing its service to us.
Staff access: UNTAP LLC personnel do not look at Customer Data except when a customer grants support access for a specific issue, when needed to investigate a security incident or keep the service running, or when required by law. Access is logged.
How long we keep it: each customer chooses how long uploaded files and their spreads are kept (from 30 days up to 7 years), can delete any file or client sooner, and we delete automatically at the end of the chosen period. When a customer closes their account, they have 30 days to export; we then delete their Customer Data from production systems, and backups expire within a further 30 days.
Tax return confidentiality. Federal law (26 U.S.C. §7216) restricts how tax return preparers use and disclose their clients' tax return information. Where a customer firm prepared a return it uploads, our Terms require it to have its client's written consent first, and our upload process asks it to confirm this.
3. Account and website data
| We collect | From | Used to | Kept |
|---|---|---|---|
| Name, work email, firm name, role | You, at sign-up; name and email from Google or Microsoft if you sign in with them | Run your account, sign-in, service emails | Life of the account + 30 days |
| Sign-in and security events (time, IP address, device) | Automatically | Security, fraud prevention, troubleshooting | 90 days |
| Billing details | You, via Stripe | Billing | 7 years, for tax and accounting records |
| Support messages | You | Help you | 2 years; attached files deleted when the issue is closed |
| Website visits | — | We do not use website analytics | — |
When an admin removes you from their firm's account, or you leave it, your login is deleted. We keep records of the Terms you accepted and of actions such as uploads and attestations, linked to an internal ID rather than your name or email, as evidence for the customer and for us (acceptance records: life of the customer account plus 7 years; security logs: up to 1 year).
Payments. Our payment processor is Stripe, Inc., which is also a subprocessor. Stripe receives your admin's email address and the payment details you enter at checkout or in the billing portal. We store only Stripe's customer and subscription identifiers and billing dates, never your card details.
We do not sell or share this information for advertising. We use it only for the purposes above, to comply with law, and to protect the service and its users.
4. Cookies
We use cookies that are strictly necessary to sign you in and keep your session secure. {{If website analytics are added to the marketing site, list them here with an opt-out.}}
5. Security
- Encryption in transit (TLS) and at rest.
- Data processed and stored in the United States.
- Separation between customers enforced in the database.
- Multi-factor authentication required for every user by default; a firm's administrator may make it optional, and anyone who has set one up must always use it.
Certification status: We have not completed a SOC 2 audit, ISO 27001 certification, or an independent penetration test. When that changes we will say so here and on https://sidesheet.co/legal/security.
If we confirm a security incident that resulted in unauthorized access to or disclosure of Customer Data, we notify the affected customer within 48 hours of confirming it.
6. Your choices and rights
- Account data: you can access, correct, export, or delete your account information by contacting privacy@sidesheet.co. We respond within 30 days.
- Data in a customer's uploads: contact the firm that uploaded it (§1). We act on that firm's instructions and will help it respond.
- Depending on where you live, you may have additional rights under state privacy laws. We will not discriminate against you for exercising them.
Drafting note
Drafting note: we have not determined whether UNTAP LLC meets the applicability thresholds of any state comprehensive privacy law (e.g. CCPA's revenue/volume thresholds); as a small pre-revenue company it likely does not yet. This section is written to be accurate either way — it does not claim compliance with any specific statute. Revisit at revenue.
7. Children
The service is for businesses and is not directed to anyone under 18.
8. Changes
We will post changes here and update the date above. For material changes we will email each customer's admins at least 30 days in advance. We will never expand how we use Customer Data without our customers' express agreement.
9. Contact
UNTAP LLC · {{MAILING_ADDRESS}} · privacy@sidesheet.co · security issues: security@sidesheet.co