Legal

Privacy Policy

Effective September 13, 2026 · Last updated September 13, 2026

01The short version

  • We never sell personal information, and we don't use it for targeted advertising.
  • The site uses no analytics trackers, advertising pixels or third-party cookies — only the cookies needed to keep you signed in.
  • Documents and answers that firms collect belong to those firms. We process them only to run the service for the firm.
  • Every upload is scanned for malware and encrypted at rest with a key unique to each workspace. Everything is hosted in the United States.
  • We don't use anyone's documents or answers to train AI models.
  • Demo workspaces are deleted automatically after 7 days.
  • Firms can export their records at any time. To ask about, correct or delete your information, email privacy@clientdocumentcollection.com.

02Who we are and what this covers

Client Document Collection is operated by YRC Business Systems (“we,” “us,” “our”). This policy explains how we handle personal information when you visit clientdocumentcollection.com, create or use an account, open a demo, or respond to a document request through a secure client link (together, the “Service”).

In this policy:

  • Customers are the businesses — accounting, tax, legal, lending, insurance and other professional firms — that use the Service to collect information from their own clients.
  • Users are the people a Customer adds to its workspace.
  • Clients are the people and businesses a Customer sends requests to. Clients don't create accounts.
  • Customer Content is everything a Customer or its Clients put into the Service: client records, requested documents, answers, confirmations, signatures and notes.

03Our two roles

For our own website, accounts and demos, we decide how personal information is used, and this policy applies directly.

For Customer Content, the Customer decides what to collect and why. We act as the Customer's service provider (sometimes called a “processor”): we store and process Customer Content only to provide the Service to that Customer, under our agreement with them and as the law allows. If you're a Client who received a request from a firm, that firm's own privacy notice governs how it uses your information. Please send questions or requests about that information to the firm first — we'll help the firm respond.

04Information we collect

Information you give us

  • Account information: your name, work email address, firm name and role.
  • Demo requests: your name, work email address and, if you choose, your firm's name.
  • Communications: what you send when you email us for support or with a question.

Customer Content

Depending on what a Customer requests, Customer Content can include Client names and contact details; tax returns, financial statements, pay stubs and bank statements; identity documents; legal and insurance records; written answers; acknowledgements; and typed-name signatures, which we record with the date, time and IP address. Because firms decide what to ask for, Customer Content may include sensitive information such as Social Security numbers, financial account numbers or government ID numbers.

Information collected automatically

  • Technical and security data: IP address, browser and device type (user agent), and the time of sign-ins and other activity.
  • Audit trail: a tamper-evident record of significant actions — sign-ins, client link opens, uploads, downloads, reviews, exports and settings changes — including who did them, when, and from which IP address.
  • Email records: the messages the Service sends on a Customer's behalf, and whether our email provider accepted them for delivery.
  • Essential cookies that keep you signed in, described in section 7.

We don't buy personal information, collect precise geolocation, or use analytics or advertising trackers.

05How we use information

  • To provide the Service: sending one-time sign-in codes, delivering requests and reminders on a Customer's behalf, storing and organizing Customer Content, and producing exports.
  • To keep the Service and its users safe: malware scanning, rate limiting, detecting abuse and unauthorized access, and keeping the audit trail.
  • To support you when you contact us.
  • To send account holders and demo requesters service messages and occasional product updates. You can opt out of product updates at any time; service messages such as sign-in codes aren't optional.
  • To comply with law, enforce our agreements, and protect our rights and the rights of others.
  • To improve the Service, using aggregate or de-identified information that doesn't identify you.

We don't sell personal information. We don't use Customer Content for advertising or to train artificial intelligence models, and our staff don't view Customer Content except when a Customer asks for help, when needed to secure the Service, or when required by law.

06How we share information

We share personal information only in these situations:

  • With the Customer: anything a Client submits through a secure link goes to the firm that sent the request.
  • With service providers who help us run the Service under contract and only for that purpose — see the table below.
  • For legal reasons: to comply with a valid law, subpoena or court order; to protect anyone's safety; or to prevent fraud or abuse. Where the law allows, we'll tell the affected Customer before disclosing Customer Content.
  • In a business transfer, such as a merger or acquisition, subject to this policy's protections.
  • With your consent or at your direction.
Service providerWhat they doWhere
ContaboServer hosting for the application, database and encrypted documentsSt. Louis, Missouri, USA
ResendDelivery of sign-in codes, document requests and remindersUnited States

Malware scanning runs on our own servers; files aren't sent to an outside scanning service.

07Cookies and tracking

We only use cookies that the Service needs to work. We don't use analytics, advertising or third-party cookies.

CookiePurposeHow long it lasts
cdc_sessionKeeps you signed inUp to 72 hours, as set by your workspace
cdc_pendingRemembers which email a sign-in code was sent to, so it never has to appear in a web address15 minutes
cdc_chooseLets you pick a workspace after signing in, if your email belongs to more than one5 minutes

Because we don't track you across websites or sell or share information for targeted advertising, there's nothing for a “Do Not Track” or Global Privacy Control signal to switch off. We treat those signals as a valid opt-out request anyway.

08Security

  • Encryption in transit (HTTPS) everywhere.
  • Uploaded documents are encrypted at rest with AES-256, using a key unique to each workspace.
  • Every upload is checked to confirm it's really the type of file it claims to be, then scanned for malware. Files that fail are blocked, and files that can't be scanned yet stay locked until they pass.
  • Sign-in uses one-time email codes that expire after 10 minutes, with limits on attempts.
  • Client links are private, expire, can be revoked at any time, and are hidden from search engines.
  • Each workspace is isolated from every other, and role-based permissions control what each user can do — auditor roles are strictly read-only.
  • A tamper-evident audit trail makes changes to historical records detectable.

No system is perfectly secure, so we can't guarantee absolute security. If a security incident affects your personal information, we'll notify affected Customers — and individuals, where we're responsible for doing so — as required by applicable law.

09How long we keep information

InformationHow long we keep it
Account informationWhile the account is active, then deleted or de-identified within 90 days after the account is closed, unless the law requires us to keep it longer
Customer ContentAs long as the Customer keeps it in the Service. Deleted within 90 days after the Customer closes its account or asks us to delete it
Audit trailFor the life of the workspace, because it's the Customer's evidence record
Demo workspacesDeleted automatically 7 days after they're created
Demo request details (name, email, firm)Up to 24 months, or until you ask us to delete them
One-time sign-in codesDeleted within 24 hours; only a one-way cryptographic hash of each code is ever stored
Session recordsDeleted within 30 days after they expire
Support emailsAs long as needed to resolve your request and keep a record of it

Any backup copies are overwritten on a rolling basis within 30 days of the original being deleted.

10Your choices and rights

  • Users can ask their workspace owner, or us, to update their name or email address. Workspace owners and managers control who has access, and can export records and the full audit trail at any time.
  • Anyone can ask us to access, correct or delete personal information we hold about them by emailing privacy@clientdocumentcollection.com.
  • Clients of a firm should contact that firm directly. If you contact us instead, we'll pass your request to the firm and help it respond.
  • Product updates: if we send you any, you can opt out at any time by replying or emailing us.

To protect your information, we'll confirm your identity before acting on a request — usually by sending a one-time code to your email address. You can use an authorized agent; we may ask for proof of the agent's authority and confirm your identity directly. We won't discriminate against you for exercising any of your privacy rights.

11State privacy disclosures

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with comprehensive privacy laws may have rights to: know or access the personal information we hold; correct it; delete it; receive a portable copy; opt out of the sale or sharing of personal information, targeted advertising and certain profiling; and limit the use of sensitive personal information. We don't sell or share personal information, run targeted advertising or profiling, or use sensitive personal information for anything beyond providing the Service.

To make a request, email privacy@clientdocumentcollection.com. We'll respond within 45 days and let you know if we need up to 45 more, as the law allows. If we deny your request and your state provides a right to appeal, reply with “Appeal” in the subject line, and we'll respond within 60 days.

California (CCPA/CPRA). In the past 12 months we've collected the categories below. We collected them from you, from the Customer that invited you, or automatically as described in section 4. We used them for the purposes in section 5 and disclosed them only to the service providers in section 6. We haven't sold or shared any of them, and we don't knowingly sell or share information about anyone under 16. California's “Shine the Light” law doesn't apply, because we don't share personal information with third parties for their direct marketing.

CategoryExamplesSold or shared
IdentifiersName, email address, IP addressNo
Customer records (Cal. Civ. Code § 1798.80)Contact details and financial information in Customer ContentNo
Professional informationFirm name and roleNo
Internet or network activitySign-in times, audit trail events, browser typeNo
Sensitive personal informationSocial Security, financial account or government ID numbers in documents a Customer requests — processed only to provide the ServiceNo

12Regulated and sensitive information

Many of our Customers work under professional confidentiality and data-protection rules. Customers are responsible for their own legal obligations — including any notices or consents required before collecting information through the Service — and for requesting only the information they need.

No protected health information. The Service isn't designed for protected health information under HIPAA, and we don't sign business associate agreements. Customers must not use it to collect protected health information.

13Children

The Service is for businesses and isn't directed at children. We don't knowingly collect personal information directly from children under 13. Customer Content may contain information about minors — dependents listed on a tax return, for example — which we process only on the Customer's behalf. If you think a child has given us personal information directly, email privacy@clientdocumentcollection.com and we'll delete it.

14United States only

The Service is offered to Customers in the United States and is hosted in the United States. If you use it from outside the country, your information will be transferred to, stored in and processed in the United States.

15Changes to this policy

We'll post any changes on this page and update the date at the top. If a change is material, we'll also notify workspace owners by email before it takes effect.

16Contact us

Questions about this policy or a privacy request? Email privacy@clientdocumentcollection.com. For a privacy rights request, it helps to put “Privacy request” in the subject line.

YRC Business Systems · Client Document Collection · clientdocumentcollection.com