Privacy Policy
Blueprint CPA & Advisory, PLLC - Last Updated: October 1, 2026 - blueprintfinancial.cpa
1. Introduction & Scope
Blueprint CPA & Advisory, PLLC, operating under the assumed name Blueprint Financial ("Blueprint CPA & Advisory," "Blueprint Financial," "we," "us," or "our") is a licensed CPA firm registered as a Professional Limited Liability Company under Illinois law. We adhere to applicable professional confidentiality requirements, including the AICPA Code of Professional Conduct, and to applicable federal and state privacy and data-security laws, including the Gramm-Leach-Bliley Act (GLBA) where applicable. This Privacy Policy applies to information collected through our website at blueprintfinancial.cpa and through direct professional engagement. It is not intended to replace any separate privacy notice or other client notice that Blueprint may provide when required by GLBA or other applicable law.
2. Professional Privacy Obligations
As a licensed CPA firm and tax preparer subject to GLBA, we are governed by: AICPA Code Rule 1.700.001 (Confidential Client Information Rule); IRC Section 7216 and Treasury Regulations 301.7216-1 through 301.7216-3 (restrictions and criminal penalties concerning prohibited use or disclosure of tax return information); IRC Section 6713 (civil penalties concerning prohibited use or disclosure of tax return information); IRS Circular 230; GLBA Safeguards Rule (16 C.F.R. Part 314), requiring a written information security program (WISP) to protect customer information within the Rule's scope; Illinois Public Accounting Act (225 ILCS 450); and IRS Publication 4557 (Safeguarding Taxpayer Data).
3. Information We Collect
Contact & inquiry data: Your name, email address, and the information you choose to include in your message. Additional business and contact information may be collected during consultation or onboarding.
Tax return information (IRC §7216): SSNs, EINs, income data, financial account details, and all information furnished in connection with tax preparation.
Engagement data: Financial statements, bank records, payroll information, and business records collected during bookkeeping, payroll, and advisory engagements.
Technical & usage data: We and our service providers may collect information such as IP address, browser and device type, pages viewed, referral source, approximate location, interaction data, and diagnostic information. This may be used for security, maintenance, troubleshooting, analytics, and improvement of the website and our services. It may include online or device identifiers, but we do not use it to directly identify individual website visitors.
Biometric Data: Blueprint does not currently collect, store, or use biometric identifiers or biometric information, as those terms are defined under the Illinois Biometric Information Privacy Act (740 ILCS 14), through this website or in the course of providing services.
Cookies & browser storage: We use Google Analytics (GA4) to understand visits and interactions with this website, including pages viewed, session activity, device and browser type, approximate location, and traffic source. This website's Google Analytics configuration disables Google Signals and advertising-personalization signals. Google receives usage, device, and online-identifier data and processes it under its applicable terms and privacy documentation. We also use browser storage to remember whether the cookie notice has been dismissed or has expired. That notice is informational; dismissing it does not disable Analytics or provide consent. Our Cookie Policy explains cookie lifetimes and available controls. External services, such as scheduling and the client portal, may set their own cookies when you visit them.
Tracking choices: This website does not change its analytics behavior in response to browser "Do Not Track" signals. Third-party services, including Google, may collect information about online activities over time and across different websites under their own terms and settings. See our Cookie Policy for browser controls and Google Analytics opt-out information.
reCAPTCHA: Our contact form embeds Google reCAPTCHA for security, fraud, and spam prevention. It processes technical and interaction data and uses a cookie for risk analysis. See reCAPTCHA data processing information.
4. How We Use Your Information
We use your information for purposes including the following: responding to inquiries; preparing and filing tax returns; providing bookkeeping, payroll, advisory, and related services; communicating regarding your engagement; complying with legal and professional obligations; and maintaining required records consistent with applicable retention schedules. We do not sell, rent, or trade your information. We do not use tax return information for marketing unrelated services without your prior written consent as required by IRC §7216 and Treasury Regulations §301.7216-3.
5. Third-Party Service Providers
We use third-party service providers for functions such as bookkeeping and accounting, client-portal and document management, tax preparation, scheduling, payment processing, communications, cloud storage, and other business operations. Disclosure of confidential client information to a provider is subject to applicable law, professional confidentiality requirements, and the engagement terms. Under AICPA Interpretation 1.700.040, the required confidentiality safeguards may be satisfied by a provider confidentiality agreement and reasonable assurance that the provider has appropriate procedures to prevent unauthorized disclosure, or by specific client consent. Additional legal or engagement requirements still apply. Use or disclosure of tax return information requires an applicable exception under IRC §7216 and its regulations or valid taxpayer consent when required. Provider terms, permitted uses, subprocessors, and technical controls may vary by vendor and service.
Disclosure may also occur in response to legal process or a governmental request only to the extent authorized by applicable law, including the restrictions on tax return information under IRC §7216 and its regulations; in connection with an authorized quality or peer review to the extent permitted by Treasury Regulation §301.7216-2(p) and applicable professional confidentiality rules; or in connection with a practice sale or transfer as permitted by applicable law and professional standards and under appropriate confidentiality safeguards.
6. Data Retention
We retain records based on the type of information, the services performed, applicable legal and professional requirements, contractual obligations, and legitimate business needs.
As a general practice, we may retain tax, accounting, bookkeeping, payroll, advisory, engagement, billing, and related professional records for seven years after the applicable engagement or service period ends, where that period is appropriate for the record involved. A shorter or longer retention period may apply to a particular record category.
We may retain records for a longer period when required or permitted by law, regulation, professional standards, contract, insurance requirements, governmental request, subpoena, audit, examination, investigation, dispute, claim, litigation, legal hold, or another legitimate business or professional need.
Retention periods vary by record type, system, service provider, legal requirement, and business need. Contact-form submissions and pre-engagement inquiries that do not lead to an engagement are generally retained only as long as reasonably necessary for inquiry management, recordkeeping, security, dispute resolution, or other legitimate business purposes. Technical, analytics, and log data are retained according to the applicable system configuration, provider settings, security needs, and legal requirements.
Information maintained by third-party service providers may also be subject to the provider's system limitations, backup cycles, contractual terms, and legal obligations.
When we determine that records are eligible for disposal and no preservation requirement applies, the records are securely deleted, destroyed, or anonymized using methods appropriate to the record format and sensitivity, consistent with IRS Publication 4557 (cross-cut shredding for paper; secure deletion for electronic records).
Clients remain responsible for retaining their own copies of tax returns, financial reports, filings, source records, payroll records, and other documents needed for legal, tax, financial, or business purposes. Continued portal availability is not a substitute for the client's own record-retention obligations.
7. Data Security & GLBA Safeguards
We use administrative, technical, and physical safeguards designed to protect client information in a manner appropriate to the size and operations of the Firm, the services provided, and the sensitivity of the information involved. These safeguards include access controls, strong authentication practices, designated client-portal use, access-controlled cloud systems, and procedures for evaluating security concerns. Specific safeguards may vary by system, service provider, information type, and identified risk.
Do not transmit Social Security numbers, Employer Identification Numbers, financial account numbers, tax returns, payroll records, or other sensitive financial documents through the general contact form or ordinary email. Sensitive documents should be exchanged through Blueprint's designated client portal.
8. Breach Notification
When a security incident triggers a legal notification obligation, Blueprint will provide notices to affected individuals, regulators, governmental authorities, consumer reporting agencies, or other recipients as and when required by applicable federal or state breach-notification law, including the Illinois Personal Information Protection Act (815 ILCS 530) where applicable. The timing, method, recipients, and content of any notice will be determined by the law applicable to the incident and the information involved.
8a. State Privacy Requests
Depending on applicable law and whether that law applies to Blueprint, residents of certain U.S. states may have rights regarding their personal information. These rights may include requesting access to, correction of, deletion of, or a portable copy of certain personal information, as well as opting out of certain sales, sharing, or targeted advertising and appealing the denial of a request.
Privacy rights are subject to the scope, applicability thresholds, definitions, exceptions, exemptions, verification requirements, and retention obligations of the applicable law. A particular right may not apply to Blueprint, to the person submitting the request, or to all information we maintain.
We may retain information when retention is required or permitted for tax, accounting, payroll, professional, contractual, security, fraud-prevention, dispute-resolution, insurance, legal, regulatory, or other legitimate purposes. Information handled in connection with professional services may also be governed by the Gramm-Leach-Bliley Act, IRC §7216, applicable professional standards, engagement obligations, and other federal or state requirements.
We do not sell personal information for monetary or other valuable consideration. For our website analytics practices and available controls, see Section 3 and our Cookie Policy. Other permitted disclosures to service providers and third parties are described in Section 5.
To submit a privacy request, email contact@blueprintfinancial.cpa with the subject line "Privacy Request." Include your full name, email address, state of residence, relationship to Blueprint, and a description of the request. Do not include Social Security numbers, Employer Identification Numbers, financial account numbers, passwords, tax returns, or other sensitive documents in the initial email.
We may take reasonable steps to verify the requester's identity, state of residence, authority to act for another person, and relationship to the information requested. We will respond within the timeframe required by applicable law and may extend the response period when permitted. If we deny a request in whole or in part, we will provide an explanation and appeal instructions when required by applicable law.
8b. Children’s Privacy (COPPA)
Our services are directed at business owners, organizations, and adult individuals. We do not knowingly collect personal information from children under 13 years of age as defined under the Children’s Online Privacy Protection Act (COPPA). If you believe a child has provided personal information to us, please contact us immediately at contact@blueprintfinancial.cpa and we will promptly delete the information.
8c. Electronic Signatures & Engagement Formation
Engagement documents, consents, and related agreements may be executed electronically in accordance with applicable electronic-signature law, including the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act, 15 U.S.C. §7001 et seq.) and the Uniform Electronic Transactions Act as adopted by applicable states, including the Illinois Uniform Electronic Transactions Act (815 ILCS 333). Electronic records and signatures may have the same legal effect as paper records and handwritten signatures when the requirements of applicable law and the parties' agreement are satisfied.
8d. Use of Technology, AI & Automated Processing
Blueprint may use artificial-intelligence-assisted and other automated technologies in connection with professional services, including tools used to analyze information, prepare work product, assist with research, forecasting, tax preparation, documentation, and administrative workflows. Any processing of client information through these tools is subject to the requirements in Section 5, including any applicable IRC §7216 exception or required valid consent for tax return information. Before a tool processes client information, its relevant data-use terms, confidentiality and security safeguards, and suitability for the intended use must be evaluated. Blueprint’s planned use does not include using confidential client information to train public generative AI models. These technologies support, but do not replace, professional judgment and review. This privacy notice does not itself authorize otherwise prohibited processing or replace any consent separately required by law or the engagement.
8e. Testimonials, Endorsements & Client References
Blueprint CPA & Advisory, PLLC complies with the Federal Trade Commission's Guides Concerning the Use of Endorsements and Testimonials in Advertising (16 C.F.R. Part 255) and applicable state consumer protection laws in any use of client testimonials, reviews, or endorsements. If client testimonials, case studies, or endorsements appear on this Site in the future: (i) all such statements will reflect the honest opinions, findings, beliefs, or experiences of the endorser; (ii) any material connection between the firm and the endorser (such as compensation, free services, or other consideration) will be clearly and conspicuously disclosed; (iii) results described in any testimonial are specific to that client's facts and circumstances, do not constitute typical results, and do not guarantee similar outcomes for other clients; and (iv) the firm will not fabricate, alter, or selectively edit testimonials in a manner that misrepresents the endorser's actual experience. As of the Last Updated date shown above, this Site does not display client testimonials.
9. Your Rights & Contact
To submit a request concerning your personal information, email contact@blueprintfinancial.cpa with the subject line "Privacy Request." Depending on applicable law and whether that law applies to Blueprint, you may have the rights described in Section 8a of this Privacy Policy. We may verify your identity, residence, relationship to the information, and authority to submit the request before taking action. Requests will be processed within the timeframe required by applicable law, subject to permitted extensions, exemptions, and record-retention obligations.
10. Changes to This Policy
We will post revisions to this Privacy Policy on this website and update the Last Updated date above. Material changes will be identified in a dated notice within this policy explaining the change and when it takes effect. If applicable law requires additional notice or consent before a change applies to your information, we will provide that notice or obtain that consent.
October 1, 2026 update: Effective on the Last Updated date above, we clarified provider and AI safeguards, when separate consent is required, limits on legal-request disclosures, website tracking and available controls, and how policy changes will be communicated.