Privacy Policy
Last updated: September 2026
Introduction
Gregory Monaco, CPA LLC, doing business as Monaco CPA ("we," "our," or "us"), respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information submitted through https://www.monacocpa.cpa and the Monaco CPA services expressly covered by an accepted engagement. It applies only to this website; do not assume it governs a separately hosted domain or service.
Information We Collect
We may collect the following types of information:
Personal Information: Name, email address, mailing address, and other contact details you provide through the written contact form or client onboarding process.
Written-intake acknowledgment: The delivered intake record includes whether you accepted the required Terms and Privacy acknowledgment, the applicable policy-version marker, the submission timestamp, and a salted hash of the request IP address.
Financial Information: Tax documents, financial statements, income information, and other financial data that may be relevant to an accepted CPA service. Website forms and email are for brief written context only; do not submit tax documents, account numbers, Social Security numbers, government identifiers, passwords, authentication codes, or other sensitive records there. If work is accepted, document-exchange instructions are provided in writing.
Website Usage Data: We may process technical usage and request data, including IP address, browser type, pages visited, and timing information. IP addresses and combined device or usage details can be personal data; we do not label them anonymous merely because they are used for security or aggregate analytics. Your browser may also send first-party Content-Security-Policy violation reports (page address, referrer, blocked resource, and a short hashed script sample) to this site for security monitoring; these are rate-limited by a salted request identifier, logged as capped samples only, and not stored.
How We Use Your Information
We may use submitted information in connection with the website, a written inquiry, and - if work is accepted - the written engagement. The purpose, recipient, and handling of a record depend on the record type, applicable law, the accepted engagement, any required consent, and current provider terms.
Data Security
Website forms are for brief written intake only. Do not submit tax documents, account numbers, Social Security numbers, government identifiers, passwords, authentication codes, or other sensitive records through a website form or ordinary email. If work is accepted, use the document-exchange method identified in the written scope or later written instruction. This page does not promise a particular third-party portal configuration, encryption, confidentiality, or retention practice. No electronic transmission or storage method is guaranteed absolutely secure.
Third-Party Services
We use the following third-party services in connection with our practice. Each provider publishes its own terms and privacy materials; this page does not certify a provider's current processing, encryption, confidentiality, or retention practices.
- TaxDome - designated client portal and document-management platform when identified in an accepted engagement or written instruction.
- QuickBooks Online (Intuit) - bookkeeping and accounting software used during engagements.
- Resend - transactional email delivery that routes written contact-form (intake) submissions - the form on /contact, served by the /api/get-started endpoint - and other active written-intake submissions to the firm's email service.
- Microsoft 365 - the firm's email-hosting service and destination for lead notifications sent through Resend.
- Vercel - our hosting, serverless infrastructure, analytics, and key-value storage provider. Static assets may be delivered through a global CDN, and third-party providers may process data in locations governed by their own service terms. Vercel and network infrastructure may transiently process or log IP addresses. Our application uses short-lived salted-and-hashed request identifiers for specified abuse controls rather than placing raw IP addresses in those application rate-limit keys.
- Vercel Analytics and Speed Insights - first-party, cookieless page-view and Core Web Vitals telemetry from our hosting provider. Uses no third-party cookies (consent-gated; see Cookies below).
- Upstash (via the Vercel Marketplace) - the managed Redis store behind the key-value layer above. It holds limited operational records. Short-lived rate-limit counters use aggregate counts or salted pseudonymous request identifiers. Email-delivery reconciliation records are retained for up to 30 days and contain a random submission ID, lead type, salted payload digest, delivery status, created and updated timestamps, optional provider message and webhook event identifiers, the last accepted provider-event time, and a hashed event-ID replay reservation. No form content, message text, or raw contact details are stored in Redis.
Cookies & Tracking
Our website uses only Vercel Analytics and Speed Insights for first-party, cookieless page-view and Core Web Vitals telemetry, loaded only after you affirmatively grant analytics consent through our cookie banner. It sets no analytics or advertising cookies and shares no audience or remarketing data. We do not use Google Analytics, Google Tag Manager, Google Ads conversion measurement, or Microsoft Clarity, and we do not run third-party tracking for ad-targeting purposes. You may decline analytics without affecting site functionality. Use the persistent Privacy Choices control in the site footer to change or withdraw analytics consent at any time; clearing browser storage also removes the saved choice.
Browser Storage
Separate from cookies, this site uses your browser's built-in localStorage and sessionStorage to remember preferences and interface state. These are first-party keys read only by this site; none are advertising or cross-site trackers.
On smaller screens, scroll horizontally to review every column.
| Key | Purpose | Category | Duration |
|---|---|---|---|
| monaco-cpa-cookie-consent | Remembers your cookie-consent choice | Essential (consent) | localStorage - until you clear browser data |
| theme | Remembers your light/dark theme preference | Preference (theme) | localStorage - until you clear browser data |
| combined-banner-dismissed | Hides the rotating top banner after you dismiss it | Preference (dismissal) | sessionStorage - current tab session |
| sticky-cta-dismissed | Hides the mobile sticky call-to-action after you dismiss it | Preference (dismissal) | sessionStorage - current tab session |
| monaco-checklist-{slug}-v1 (one key per available checklist) | Saves completion state for each tax-document checklist | Functional (checklist progress) | localStorage - until you clear browser data |
These values are stored locally and are not automatically transmitted to Monaco CPA. Some combinations may still be identifying in context.
Data Retention
Retention periods for client records, written inquiries, Microsoft 365 mailboxes, Resend delivery records, provider backups, and downstream systems depend on the accepted engagement, the record type, applicable tax/professional/legal duties, and provider configuration. IRC § 6107(b) and Treas. Reg. § 1.6107-1 require preparers to keep a copy or list of returns for at least three years; other records can have different requirements. Historical calculator, estimate, and chatbot lead emails submitted before their respective retirements are subject to the same fact-specific analysis. This public policy does not publish a fixed retention or deletion schedule, and a deletion request is evaluated against the records available, applicable duties, and provider limitations at that time.
Tax Return Information (IRC § 7216 & § 6713)
Federal law imposes strict limits on how a paid tax return preparer may use or disclose information obtained in connection with the preparation of a tax return. Under 26 U.S.C. § 7216 and Treas. Reg. § 301.7216, permitted uses and disclosures depend on the applicable rule, the accepted engagement, and any required separate consent. A use or disclosure that is not otherwise authorized requires the consent prescribed by the current rules, including the applicable form and content requirements.
“Tax return information” includes any information furnished to us, by you or on your behalf, in connection with the preparation of a return - including the return itself, supporting schedules, work papers, basis records, and any personally identifiable information collected during the engagement. This web policy does not itself authorize a use or disclosure, establish a processor configuration, or substitute for a required engagement-specific consent.
Companion civil penalties under 26 U.S.C. § 6713 and criminal penalties under § 7216 apply to unauthorized use or disclosure. A required consent must satisfy the applicable recipient, purpose, and other required terms. For Form 1040-series consent covered by Revenue Procedure 2013-14, a consent that does not specify a duration is valid for one year from signature. Consent is not required for a use or disclosure that the regulations or other applicable law independently authorize or require.
New Jersey Data Privacy Act (NJDPA)
Whether a particular privacy statute applies depends on current facts and legal analysis. This page does not determine applicability of the New Jersey Data Privacy Act (N.J.S.A. 56:8-166.4 et seq.) or provide a complete statutory notice. A New Jersey resident may submit the following requests for review:
- Confirm whether we process your personal data and access that data
- Correct inaccuracies in your personal data
- Delete personal data we have collected from you
- Obtain a portable copy of your personal data in a usable format
- Opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects
Tax-return information can be subject to separate federal protections and retention duties. A request does not override a legal, professional, security, or engagement-related retention duty.
To exercise NJDPA rights without completing tax-intake questions, email taxhelp@MonacoCPA.CPA. Monaco CPA provides this written channel without using this notice to determine or disclaim whether a privacy statute applies. If applicable law requires a response period, explanation of a denial, or appeal process, those procedures will be followed. Otherwise, the request is reviewed voluntarily against the available records and applicable retention duties, without promising a particular result.
Your Rights
You may request access to, correction of, or deletion of your personal information by contacting us; no tax-service selection is required. This is a written request channel, not a promise of a fixed acknowledgment, completion date, scope of deletion, or legal outcome. Some information may need to be retained for legal, regulatory, professional, security, or engagement-related purposes.
Other State Privacy Rights: Residents of California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws may have additional rights regarding their personal data. This page does not determine CCPA/CPRA applicability or that of any other state statute. Contact us to exercise any applicable rights under your state's privacy law.
Children's Privacy
This website is not a minor-client intake channel. Do not submit a minor's personal data, tax documents, account identifiers, or return information through a web form. Monaco CPA does not accept minor-specific engagements through this site; minor-related material is general education only.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
Written Inquiries
Questions about this Privacy Policy or data practices may be emailed directly to taxhelp@MonacoCPA.CPA.