Scope and who we are
This Privacy Policy explains what personal information Xelvon Tax Advisors LLC collects, why, who ever sees it, how long we keep it, and what you can do about it. It covers this website, our secure client portal, our email and phone lines, and our client work.
Xelvon Tax Advisors LLC is a Utah limited liability company; Joseph Edwin Fox is the Managing Member. We serve clients in all 50 states and the District of Columbia entirely online, with no public office and no in-person meetings.
Two federal laws shape almost everything here. Under the Gramm-Leach-Bliley Act a tax preparation firm is a financial institution, so the Federal Trade Commission's Safeguards Rule and the Consumer Financial Protection Bureau's Regulation P apply to us. And Internal Revenue Code section 7216 makes it a federal crime for a preparer to use or disclose your tax return information beyond preparing and filing your return without your separate signed consent. Both are stricter than most state privacy laws.
Who we are, stated plainly. Xelvon Tax Advisors LLC is not a certified public accounting firm and is not a law firm. We are not certified public accountants, attorneys, or enrolled agents. We do not provide audit, review, compilation, attest, or assurance services, and we do not provide legal or investment advice. We do not have authority to represent clients before the Internal Revenue Service. Full detail is on our Disclaimers page.
Your information at a glance
| Category | Examples | Why | Who else sees it |
|---|---|---|---|
| Identifiers | Name, address, phone, email, date of birth | To identify you | Tax agencies; portal and e-file providers |
| Tax return information | Everything given to us for a return, and the return itself | To prepare and file it | Tax agencies only, absent your signed consent |
| Government identifiers | SSN, ITIN, EIN, IRS Identity Protection PIN, state ID number | Required on returns | Tax agencies; tax software provider |
| Financial account information | Bank routing and account numbers | Refund deposit or tax payment | Tax agencies; processor, for our fee only |
| Employment and income data | W-2, 1099, K-1, 1098, brokerage and business records | To calculate your tax | Tax agencies; software and portal providers |
| Spouse and dependents | Names, dates of birth, identifiers | Filing status and credits | Tax agencies |
| Portal uploads and communications | Your documents, emails, portal messages, notes of calls | Supporting records | Portal and email providers, under written contract |
| Website usage data | IP address, browser, pages viewed, form submissions | To run the site securely | Hosting provider |
The categories we collect, in detail
Tax return information is the broadest and most sensitive category — a term defined by federal law covering anything you give us, or that we derive, in preparing a return, including the fact that you are a client at all. Everything below becomes tax return information once it reaches a return.
- Identifiers — legal and prior names, address, phone, email, date of birth, occupation.
- Government identifiers — Social Security numbers, ITINs, EINs, IRS Identity Protection PINs, state ID numbers where e-filing requires them.
- Financial account information — bank routing and account numbers. Card details go straight to our processor and are not stored by us.
- Employment and income data — wage, self-employment, partnership, investment, retirement, rental, payroll and sales records.
- Dependents' and spouse's information — names, dates of birth, identifiers, months lived with you, childcare and education expenses, supplied by you.
- Documents uploaded to the portal — your files and their metadata.
- Website usage data — server logs of IP address, time, page requested, referrer and browser string.
- Communications — emails, portal messages, form submissions and notes of calls.
How we collect it
- Directly from you — website forms, email, phone, your organizer questionnaire, portal uploads.
- From people you authorize — a spouse filing jointly, a business partner, a payroll contact, another advisor, once you tell us in writing.
- From the IRS, when you sign an authorization. IRS Form 8821, Tax Information Authorization lets us request and read your transcripts for the years you list. It authorizes receipt of information only, not representation, and we have no authority to represent clients before the IRS.
- From our service providers — portal receipts, e-file acknowledgements, payment confirmations.
- Automatically from this website — server logs and the two strictly necessary cookies below. Nothing else.
Why we collect it, and what permits us to
- To do the work you hired us for — returns, bookkeeping, payroll, filings, planning.
- To comply with law. Tax law dictates what appears on a return, requires us to verify your identity before an electronic signature, and sets minimum retention periods.
- To run the firm honestly — quoting, invoicing, payment, disputes, security.
- With your separate signed consent — for anything involving tax return information beyond preparing and filing your return.
The section 7216 rule, stated plainly
We will not use or disclose your tax return information for any purpose other than preparing and filing your return unless you first sign a separate written consent. Not for marketing, a lender, a mortgage broker, an insurance agent, a referral partner, a newsletter list, an analytics or advertising vendor, or an artificial-intelligence service. The rule is 26 CFR 301.7216-3, and breaking it carries criminal and civil penalties for us.
Four things follow:
- A consent is always its own document. It can never be bundled into this Privacy Policy, our Terms of Service, a cookie banner or an "I agree" checkbox. Presented that way, it is not valid.
- Consent to use and consent to disclose must be two separate documents.
- No service may be conditioned on such a consent. Say no and nothing changes about your work or its price. We also may not pre-tick a box, pre-fill a signature, or ask again after you decline.
- A consent lasts for the period you specify; if you specify none, one year from signature.
Read the exact consent forms we use, in full, before anyone asks you to sign anything, on our Consent Forms page. Transmitting the return to the IRS and your state is part of filing it, and needs no consent.
What we share, and with whom
We disclose nonpublic personal information only as Regulation P permits without an opt-out: to carry out the services you asked for, to process transactions you requested, with your written consent, and as law requires or permits. We reserve no right to disclose beyond that, so there is nothing to opt out of under 12 CFR 1016.6. Former clients are treated identically: when an engagement ends, we do not start sharing your information.
We do not sell personal information. We never have, and we will not. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not trade, rent or license client lists, and we take no referral fee for sending your information anywhere.
The service providers we use
Each vendor is chosen for its security posture, bound by a written contract requiring confidentiality and appropriate safeguards, and permitted to use your information only to serve us. The categories:
- Secure client portal and document exchange — the encrypted system you upload to.
- Tax preparation software and IRS e-file transmission.
- Encrypted email — for correspondence; sensitive documents go through the portal instead.
- Payment processing — for our invoices.
- Bookkeeping and financial record-keeping software.
- Scheduling — collecting only your name, email address and topic.
- Website hosting — which processes server logs.
- Website analytics — see below; none is in use at present.
We do not name individual vendors, because vendors change and a stale list is worse than none. To learn who handles your file today, email privacy@xelvontax.com.
Cookies and website analytics
This website uses only strictly necessary cookies: a session cookie holding your place while you complete a form, marked HttpOnly and SameSite, sent only over HTTPS and expiring when you close your browser; and a CSRF token cookie proving a submission came from this website rather than an attacker's page.
There are no advertising cookies here, and no third-party trackers, pixels, session-replay scripts or social widgets load by default. No third-party analytics script runs at present. If we add one, we will update this section first, choose a tool that does not build advertising profiles, and never run it on the portal, the intake questionnaire or any upload page — sending tax return information to a marketing vendor is a federal offense, not merely bad manners.
You can block or delete cookies in your browser settings. Blocking the two above stops our forms working; phone and email still reach us.
How we protect your information
Access is limited to those who need a file to do the work. We encrypt client information in transit and at rest, require multi-factor authentication on systems touching client data, log access, and maintain a Written Information Security Plan as required by the FTC Safeguards Rule (16 CFR 314.4) and described in IRS Publication 4557, Safeguarding Taxpayer Data. We update that plan as our systems change.
Regulation P does not require us to publish the technical detail of our safeguards, and we do not, because publishing it would weaken it. What we can describe openly is on our Security page. No system is perfectly secure; we will not pretend otherwise.
How long we keep information
| What | How long | Then |
|---|---|---|
| Returns, workpapers and related correspondence | Seven years from the filing date | Secure destruction: files erased, paper cross-cut shredded |
| Signed Form 8879 e-file authorizations | At least three years, as IRS rules require; held in the seven-year file | Destroyed with that file |
| Documents in the client portal | Your active engagement, plus a wind-down period | Removed from the portal; the record follows the seven-year rule |
| Bookkeeping and payroll records | Seven years, or longer where a payroll or state rule requires | Secure destruction |
| Marketing and inquiry contact data | Until you opt out or ask us to delete it | Deleted, but for a suppression record so we do not email you again by mistake |
| Website server logs | Short-term, for security and troubleshooting | Overwritten on the host's rotation |
Keep your own copy of your return — please do not treat our retention schedule as your record-keeping plan.
Children and dependents
This website and our services are intended for adults. We do not knowingly collect personal information directly from anyone under 18, and we do not market to children.
We do process information about children routinely, because tax returns require it — a dependent's name, date of birth and Social Security number, childcare provider details, education expenses, and a dependent's own income where reportable. It reaches us from the parent, guardian or filing adult, not from the child, and carries the same protections as everything else in the file. If you believe a child gave us information directly, email privacy@xelvontax.com and we will delete it unless tax law requires us to keep it.
Your privacy rights
Whatever state you live in, and whether or not a state privacy law applies to us, we offer every client and visitor:
- Access — ask what we hold about you and get a copy.
- Correction — have inaccurate information fixed.
- Deletion — subject to the retention duties above. We cannot delete a filed return or records the law requires us to keep, and we will tell you plainly what we keep.
- Portability — receive what you gave us in a usable format.
- Opt out of marketing — use the unsubscribe link in any commercial email. This never affects service messages about your engagement.
- No retaliation — we will not deny service, change your price or lower your work's quality because you exercised a privacy right.
State-specific rights
Most state privacy laws apply only above revenue or volume thresholds a firm our size does not meet, and several also carve out data governed by the Gramm-Leach-Bliley Act. We will not hide behind either point.
California
Under the California Consumer Privacy Act as amended, California residents have rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation. Three points of honesty about how that law meets ours:
- Data we process to prepare your return or keep your books is generally exempt from the CCPA because the Gramm-Leach-Bliley Act governs it. That is a data-level exemption, not a shield for the whole firm.
- Data outside it — inquiry forms, newsletter sign-ups, server logs, job applications — is not exempt, and CCPA rights apply in the ordinary way.
- The exemption does not extend to Civil Code section 1798.150, the private right of action for a breach caused by a failure to maintain reasonable security. Nothing here limits that right.
We do not sell or share personal information, so there is no "Do Not Sell or Share My Personal Information" link — the answer is already no. You may use an authorized agent; we ask for written permission signed by you and verify your identity directly. California requires no appeal process, but we offer one: say why you disagree and a different person reviews it.
Utah
The Utah Consumer Privacy Act gives Utah residents rights to confirm processing and access their data, delete data they provided, obtain a portable copy, and opt out of targeted advertising and the sale of personal data. Since July 1, 2026 it also provides a right to request correction of inaccuracies. The Act exempts financial institutions governed by, and data handled under, the Gramm-Leach-Bliley Act. We honor these requests regardless.
Colorado, Connecticut, Virginia and Texas
Residents of these states may confirm and access their data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling. Each law also requires an appeal route.
| State | Response deadline | Appeal answered within | If we deny the appeal, we give you a route to |
|---|---|---|---|
| Colorado | 45 days, one 45-day extension | 45 days | The Colorado Attorney General |
| Connecticut | 45 days, one 45-day extension | 60 days | The Connecticut Attorney General |
| Virginia | 45 days, one 45-day extension | 60 days | The Virginia Attorney General |
| Texas | 45 days, one 45-day extension | 60 days | The Texas Attorney General's online complaint mechanism |
Every other state
State privacy laws keep arriving and changing, so rather than keep a list that goes stale we apply the rights in Your privacy rights to every state. If your state grants more, say so with your request and we will apply it.
How to make a request, and what happens next
Email privacy@xelvontax.com with "Privacy Request" in the subject line, call (435) 341-4014 during business hours, or use our Contact form. Tell us what you want and which state you live in.
How we verify you. A tax file is the most complete record of a person that exists, so we verify carefully before releasing or changing anything: for a client, through your portal account or by matching details in your file and confirming on a phone number we hold; for a non-client, against the limited information we have. We will not use your request as an excuse to collect more than verification requires, and we will not release tax return information to anyone but the taxpayer without the taxpayer's signed authorization.
Timing. We acknowledge requests promptly and respond within 45 days, extendable once by a further 45 days for a complex request if we tell you within the first 45 days that we are doing so and why. A reasonable request is free.
Appeals. If we refuse, we will say why in writing and explain how to appeal. Send it to the same address marked "Privacy Appeal", and someone uninvolved in the original decision reviews it. We answer appeals within 45 days for Colorado residents and 60 days for everyone else, and a denied appeal always comes with contact details for your state Attorney General.
Nevada residents
Nevada law lets a consumer direct an operator of a website or online service not to sell covered information about them. Xelvon Tax Advisors LLC does not sell covered information and has no plans to. To have that confirmed in writing, or to submit a verified request anyway, our designated request address is privacy@xelvontax.com. We respond within 60 days, and will tell you if an extension of up to 30 further days is reasonably necessary.
Do Not Track and opt-out preference signals
Browsers can send a "Do Not Track" signal, and some send a Global Privacy Control signal. No industry standard governs how a site should answer either. Ours is simple: this website does not track your activity across other sites in the first place, and we do not sell or share personal information, so there is nothing for such a signal to switch off. We treat any opt-out preference signal as a valid request not to sell or share — already our practice for everyone.
If there is a data breach
We maintain a written incident response plan. If client information is exposed we will investigate immediately, contain the incident, and tell those affected without unreasonable delay so you can protect yourself — by requesting an IRS Identity Protection PIN and freezing your credit. Our commitments:
- If a notification event involves the information of at least 500 consumers, we will notify the Federal Trade Commission electronically as soon as possible and no later than 30 days after discovery, as 16 CFR 314.4(j) requires.
- We will give the notices your own state's breach law requires, on that state's timetable — those laws follow the resident, not the firm.
- We will report a theft of client tax data to the IRS Stakeholder Liaison and affected state tax agencies, so fraudulent returns can be flagged before processing.
- We will tell you what happened and what we are doing about it, in plain language and without minimizing it.
Spot something that looks like a security problem — a suspicious email using our name, a flaw on this website? Please tell security@xelvontax.com.
Where your information is stored
Xelvon Tax Advisors LLC is a United States firm serving United States taxpayers, and our services are directed only to the United States. Client information is stored on systems located in the United States. We do not disclose tax return information to any preparer or service outside the United States; federal law would require your separate written consent first, and we do not seek one. If you are a U.S. taxpayer abroad, what you send us is stored in the United States under United States law.
Changes to this policy
We review this policy at least annually and whenever our practices or the law change materially. When we change it we update the effective date at the top of this page and post the new version here. If a change materially affects information we already hold, we will tell you directly — by email or through the portal — before it takes effect, and obtain any consent it requires. We will never apply a new sharing practice retroactively without asking you first.
How to contact us
Privacy questions, records requests, complaints and appeals all go to the same place:
- Email: privacy@xelvontax.com
- Phone: (435) 341-4014, Monday through Friday, 9:00 a.m. to 6:00 p.m. Mountain Time, with extended hours from late January through April 15
- Security reports: security@xelvontax.com
- Anything else: hello@xelvontax.com or the Contact page
We keep no public office, so please send privacy correspondence to the email address above rather than by post. A real person reads it, and we aim to reply within two business days even when the full answer takes longer. Need this policy in an accessible format? Email accessibility@xelvontax.com — see our Accessibility Statement.