Privacy Policy

1. Introduction

This Privacy Policy describes how ZP Consultants LLC (“Firm,” “we,” “us”) collects, uses, and protects information in connection with the zpinson.com website and our professional services (“Services”). The Firm provides CPA-led finance, controls, operating-advisory, and implementation services. This policy applies to all visitors to zpinson.com and all clients of the Firm.

2. CPA Professional Obligations

As a CPA-led firm, ZP Consultants is bound by professional standards of confidentiality that exceed general business privacy requirements. Specifically:

These professional obligations apply in addition to, and independently of, this Privacy Policy.

3. Information We Collect

3.1 Information You Provide

We collect information you voluntarily submit, including:

The Work-With-Us application is reviewed manually for fit, readiness, and capacity. Do not submit passwords, account credentials, financial statements, personal data, confidential client records, API keys, or other sensitive materials through that public form.

3.2 Client Engagement Data

When you engage ZP Consultants for professional services, we collect and process financial data necessary to deliver those services, including:

Client engagement data is governed by your signed engagement letter, which may contain additional confidentiality and data handling provisions that supplement this policy.

3.3 Automatically Collected Information

We use Plausible Analytics, a privacy-focused, cookieless analytics service. Plausible does not use cookies, does not collect personal data, and does not track visitors across websites. The data collected includes:

Because Plausible is cookieless and does not collect personal data, no cookie consent banner is required.

3.4 Information We Do Not Collect

We do not use tracking cookies, advertising pixels, or any form of cross-site tracking on zpinson.com.

4. How We Use Your Information

We use the information we collect to:

5. Technology Disclosure

Professional engagements may use automation or AI-enabled tools where appropriate to the agreed scope. The engagement letter and applicable workflow controls define the information, access, approvals, review, and responsibilities for that work. The public application is not a channel for sensitive materials or credentials.

Your information remains subject to the confidentiality obligations described in Section 2 of this policy. Technology does not replace the Firm’s professional responsibility under the applicable engagement terms.

6. Third-Party Processors

We use the following third-party services:

We do not sell, rent, or share your personal information or financial data with third parties for marketing purposes.

7. Data Storage and Security

Website hosting and application infrastructure are located in the European Union, specifically Hetzner data centers in Germany and Finland. Data is encrypted in transit via TLS and at rest where applicable.

Financial data is handled with additional security controls appropriate to its sensitivity, including access controls, audit logging, and encrypted storage. We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.

8. Data Retention

We retain personal information collected through general-contact forms, Work-With-Us applications, and communications for a maximum of 12 months from the date of collection, unless a longer retention period is required by law, security needs, a dispute, or an active business relationship exists. Application data is used for manual fit review and is not used to make an automated acceptance or rejection decision.

Client engagement data (financial records, tax documents, work papers) is retained in accordance with professional standards and applicable law, which may require retention periods of 3 to 7 years depending on the nature of the engagement. Specific retention terms may be set forth in your engagement letter.

Aggregate analytics data (which contains no personal information) may be retained indefinitely.

9. Your Rights

9.1 GDPR Rights (EEA Residents)

If you are located in the European Economic Area, you have the right to:

9.2 CCPA Rights (California Residents)

If you are a California resident, you have the right to:

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

9.3 Exercising Your Rights

To exercise any of the above rights, contact us at contact@zpinson.com. We will respond to verified requests within 30 days. Note that certain professional retention obligations may limit our ability to delete client engagement data prior to the expiration of required retention periods.

10. Children’s Privacy

The Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date. Clients will be notified of material changes via email. Continued use of the website or Services after changes constitutes acceptance of the revised policy.

12. Contact

ZP Consultants LLC
Zalmy Pinson, CPA
11 S Ridge Rd
Pomona, NY 10970
contact@zpinson.com