Beta testing — test data only. Do not enter real personal or tax information.
Version 2026.1 · Effective August 19, 2026

Records retention and deletion.

This is the published policy Ascendum Corporate Advisory LLC follows for keeping, locking down and destroying your tax records — including exactly what happens when you delete a return or leave the portal entirely.

Deleted means locked, immediately

The moment you delete a return it is sealed. For the 7-day restore window nobody — not you, not our staff through your portal view — can open its documents, extracted values, answers, drafts or prep packets. Only a restore reopens them.

A clock on every record

Nothing is kept "just in case". Every category below has a defined retention period and a legal basis, and is destroyed automatically when the clock runs out.

Law first, convenience second

A few records must survive a deletion request because federal tax law says so. We tell you which, why, and the date they are destroyed — we never hold anything quietly.

Retention schedule

RecordWe keep it forLegal basis

Copy of the filed return (or the client list and return record)

Federal law requires a paid preparer to retain a completed copy of each return, or a record of the taxpayer name, TIN, tax year and type of return, for three years after the return period closes. This obligation survives a deletion request.

3 years after the close of the return periodIRC § 6107(b); Treas. Reg. § 1.6107-1(b)

Form 8879 e-file signature authorization and the e-file record

As an Authorized IRS e-file Provider we must retain each signed Form 8879, the electronic acknowledgement and supporting documents we relied on when transmitting.

3 years from the due date or IRS received date, whichever is laterIRS Pub. 1345; Rev. Proc. 2007-40

Source documents you upload (W-2, 1099, K-1, receipts, statements)

Kept only while needed to support the filed return and answer an IRS or state notice. Deleted sooner on request unless a legal hold applies.

3 years after filing, then purged from active storageIRS Pub. 4557 data-minimization guidance

OCR / extracted values and questionnaire answers

Extracted figures are derived data. They are erased when the return is purged and are never retained after the underlying document is deleted.

Purged with the return, or immediately on deletionCompany data-minimization standard; GLBA Safeguards Rule

Social Security numbers and TINs

Stored AES-256-GCM encrypted in an isolated vault, never returned to the browser in full, and erased once no retained return still requires it.

Encrypted vault; erased when the client relationship endsIRS Pub. 4557; 16 CFR Part 314 (FTC Safeguards Rule)

IRC § 7216 consents and engagement / EULA signatures

Consent to use or disclose tax return information must be retained and produced on IRS request; it is proof that a disclosure was lawful.

3 years after the last return we prepared for youTreas. Reg. § 301.7216-3(c)

Payment and invoice records

Amount, date, reference and status only. Full card numbers are never stored — payments are processed by our PCI-DSS processor.

7 yearsIRC § 6001; state books-and-records rules

Security and access audit logs

Who accessed which record, when, from which IP. Logs are append-only and are retained even after the underlying record is deleted, with identifiers reduced to an internal id.

2 years, immutableFTC Safeguards Rule 16 CFR § 314.4(c)(8); IRS Pub. 4557

Encrypted backups

Deleted records disappear from active systems immediately and roll out of encrypted backups within the backup cycle. Backups are never used to resurrect deleted data.

Overwritten within 35 daysCompany continuity standard

Account profile and sign-in credentials

Name, email, phone, date of birth and address live only while the relationship is active. On a verified deletion request they are erased, leaving only the legally-required return record described above.

Until you close the account, then deletedState privacy acts (right to delete); FTC Safeguards Rule disposal standard

One-time sign-in codes (email / SMS OTP)

Login codes are single-use, hashed, and destroyed as soon as they are consumed or expire. They are never logged in plain text.

Minutes — expire and are purged after 10 minutes or first useCompany data-minimization standard; IRS Pub. 4557

QR upload tokens and upload links

In-store QR tokens are consumed on first use and cannot be replayed. The spent token record is kept briefly for fraud investigation, then purged automatically.

Single-use; spent tokens purged within 30 daysCompany data-minimization standard

Support requests, resend requests and idempotency records

Support references, upload-link resend history and deduplication keys are kept to answer 'what happened to my request' and to detect abuse, then purged.

1 year after the request is resolvedFTC Safeguards Rule monitoring standard

Webhook subscriptions and delivery logs

Status-notification webhooks you configure stay active until removed. Delivery attempts, failures and retries roll out of history after 90 days.

90 days for delivery history; subscriptions until you delete themCompany data-minimization standard

Marketing leads, refund-estimator entries and email consent

If you try the Refund Estimator or join the mailing list we keep your email and attribution only while the relationship is active. Every message carries a working unsubscribe; consent records are retained as proof and the address itself is suppressed, not marketed to, after opt-out.

Until you unsubscribe or request deletion, maximum 24 months of inactivityCAN-SPAM Act; state privacy acts (right to delete/opt out)

Offshore preparation access records

When offshore preparation is enabled, every access by an approved preparer is logged with your § 7216 consent reference. The logs are audit evidence and are destroyed with the security-log cycle.

2 years, immutable, then purgedTreas. Reg. § 301.7216-3 consent records; IRS Pub. 4557

Leaving the portal: what happens to your records

  1. 1. Download your records first

    Before anything is erased you can export a PDF summary of every return, your questionnaire answers, the values we read from your documents, and your filed copies. Once a permanent deletion runs, we cannot recreate them.

  2. 2. Soft delete and the recycle bin

    Deleting a return moves it to your recycle bin for 7 days. While it sits there, the return is locked: its documents, OCR values, answers, drafts and prep packets can no longer be opened, downloaded or edited by anyone but the restore step itself. Restore it and everything comes back; do nothing and it is purged automatically.

  3. 3. File a deletion request to close the relationship

    A "delete my data" request in the portal closes the whole relationship, not one return. We acknowledge it within 10 business days and complete it within 30 days, as required by state privacy laws such as the CCPA/CPRA (Cal. Civ. Code § 1798.105) and the Virginia, Colorado, Connecticut, Texas and Utah acts.

  4. 4. Identity verification (required, not optional)

    Because tax records are among the most sensitive data there is, we verify who you are before we release or erase anything — a signed request plus a one-time code to the phone or email on file, and government ID if the request came from a new contact point. Unverified deletion requests are refused, which is what stops an attacker from wiping or stealing your file.

  5. 5. What is erased

    Uploaded documents and their stored files, OCR/extracted values, questionnaire answers, drafts, comments, prep tasks, notifications, in-portal messages, saved estimates, and your SSN/TIN vault entry are permanently destroyed. Storage objects are removed, not just unlinked.

  6. 6. What we must legally keep

    Federal law overrides a deletion request for a narrow set of records: the retained copy or record of any return we prepared and its Form 8879 (3 years), your IRC § 7216 consents (3 years), payment records (7 years), and immutable security logs (2 years). These are held in encrypted archive, are not used for any other purpose, and are destroyed when their clock runs out.

  7. 7. Your written confirmation

    When the deletion completes you receive a dated confirmation listing exactly what was destroyed, what was retained, the legal basis for each retained item, and the date it will be destroyed. Your reference number stays valid for the whole exchange.

Start a deletion in your portal under Account & privacy → Privacy requests, or email tax@ascentaxus.com from the address on your file.

The US rules this policy implements

IRC § 7216 / Treas. Reg. § 301.7216

Criminal restriction on using or disclosing tax return information without your written, purpose-specific consent. We never sell, share or use your data for marketing.

IRC § 6713

Civil penalty for the same unauthorized disclosure or use.

IRC § 6107(b) / Treas. Reg. § 1.6107-1

3-year preparer retention of the return copy or return record.

Gramm-Leach-Bliley Act & FTC Safeguards Rule (16 CFR Part 314)

Written information security program, a designated qualified individual, risk assessment, encryption of customer information in transit and at rest, MFA, access controls, monitoring, vendor oversight, and secure disposal of customer information no later than two years after last use unless a legitimate business or legal need applies.

IRS Publication 4557 & Publication 5708

Written Data Security Plan for tax professionals: encryption, least-privilege access, audit logging, incident response and secure destruction.

IRS Publication 1345

e-file provider record retention, signature authorization handling and taxpayer identity verification.

FTC Disposal Rule (16 CFR Part 682)

Consumer report information must be destroyed so it cannot be practicably read or reconstructed.

FTC Safeguards Rule breach notification (16 CFR § 314.4(j))

Notification to the FTC within 30 days of discovering unauthorized acquisition of unencrypted information of 500 or more consumers, plus state breach-notice laws in all 50 states.

IRS / state incident reporting

Report a data theft to the IRS Stakeholder Liaison, the state tax agency and the Federation of Tax Administrators immediately, so fraudulent returns can be blocked in your name.

State privacy acts (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA and successors)

Rights to know, access, correct, delete and appeal, answered within 30 days (extendable once by 45 days with notice), with no discrimination for exercising them.

This policy is informational and is not legal advice. Questions about your specific records: tax@ascentaxus.com · (816) 294-5633.