Privacy Policy
Last updated: June 6, 2026. We review this page periodically and will note material changes here.
This Privacy Policy explains what personal information CPAZenith collects, why we collect it, how we use and share it, how long we keep it, and what choices you have. It applies to the CPAZenith website, directory, paid digital products, and related services (the "Service").
1. Information we collect
You provide
- Account data: email, password hash, display name, and authentication identifiers (including Google sign-in IDs if used).
- Profile-claim data: firm details, license number, verification documents.
- Lead and consultation submissions: name, email, phone (optional), service interest, message.
- Reviews and content: star ratings, written reviews, and any other content you submit.
- Support communications: messages you send us by email or form.
Collected automatically
- Usage data: pages visited, referrer, timestamps, approximate location derived from IP, device and browser type.
- Cookies and similar technologies: session cookies for authentication, preference cookies, and limited first-party analytics.
- Server logs: IP address, request metadata, error traces.
From third parties
- Payment processor (Stripe): we receive transaction status and last-four card digits; we do not receive or store full card numbers.
- Public records: licensure status from state boards of accountancy and other regulators (see our Verification Policy).
2. How we use information
- To operate the Service, including authentication, search, lead delivery, and paid-product entitlement;
- To verify professional credentials and maintain the directory;
- To process payments, prevent fraud, and meet tax/accounting recordkeeping obligations;
- To send transactional emails (receipts, downloads, security alerts) and, with your consent, occasional updates;
- To improve the Service through aggregate analytics and product research;
- To comply with legal obligations and enforce our Terms.
Where the GDPR or similar laws apply, our legal bases are: contract (to provide the Service you requested), legitimate interests (to secure and improve the Service), consent (for marketing emails and optional cookies), and legal obligation (for tax and compliance recordkeeping).
3. How we share information
We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws. We disclose information only:
- To service providers acting under contract on our behalf: Stripe (payments), our backend provider Lovable Cloud (hosting, database, authentication), our transactional email provider, and analytics providers.
- To listed professionals when you submit a lead or consultation request directed to them.
- For legal reasons: to comply with valid legal process, enforce our Terms, or protect our or others' rights, property, or safety.
- In a business transaction: in connection with a merger, acquisition, financing, or sale of assets, with notice to affected users.
4. International transfers
The Service is operated from the United States. If you access it from outside the U.S., your information will be processed in the U.S. and other countries that may not have the same data-protection laws as your jurisdiction. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses).
5. How long we keep information
- Account data: until you delete your account, then up to 30 days in backups.
- Lead and consultation data: up to 24 months from submission, then deletion or anonymization.
- Payment and tax records: at least 7 years, as required by U.S. tax law.
- Server logs: typically 30–90 days.
- Public-records-derived listing data: retained while the source record is public; redaction available on request — see our Data Removal Request Policy.
6. Security
We use industry-standard safeguards including encryption in transit (TLS), at-rest encryption by our infrastructure provider, role-based access controls, row-level security at the database tier, and least-privilege service credentials. No system is perfectly secure; you are responsible for keeping your password confidential.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent. To exercise these rights, follow our Data Removal Request Policy or email hello@cpazenith.com. You will not be discriminated against for exercising your rights.
California residents (CCPA / CPRA)
You have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing." CPAZenith does not sell or share personal information for cross-context behavioral advertising. You may still submit a request to confirm this at the address above.
EEA / UK residents (GDPR / UK GDPR)
You have the rights described above and the right to lodge a complaint with your supervisory authority.
8. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
9. Cookies and tracking
We use strictly necessary cookies (for authentication and security) and limited first-party analytics cookies. You can block or delete cookies in your browser settings; doing so may impact functionality. We do not currently use third-party advertising cookies, and we honor the Global Privacy Control (GPC) signal where applicable.
10. Changes to this Policy
We will post material changes here and update the "Last updated" date. If changes materially affect your rights, we will notify you by email or in-product notice before they take effect.
11. Contact
Privacy questions and rights requests: hello@cpazenith.com.






