Last updated: October 8, 2026
Crosstie, Inc. licenses software to accounting and tax practices. This page says what information it holds, where it is held, what Google and Microsoft data the software accesses and why, and who else processes it.
- 1. This website
- 2. Google user data
- 3. Microsoft OneDrive
- 4. Where a firm’s data lives
- 5. Connection tokens
- 6. Service providers
- 7. Taxpayer information
- 8. Retention
- 9. Your choices
- 10. Children
- 11. Legal process
- 12. Security incidents
- 13. Changes
- 14. Contact
This policy describes how Crosstie, Inc. (“Crosstie”, “we”) handles personal information in two situations, which have different rules and should not be confused.
- This website, and people who contact us. When you visit crosstietax.com, join the early-access list, or email us, Crosstie decides what happens to that information. Crosstie is the controller of it.
- The software, used by an accounting or tax firm. When a firm uses Crosstie to run its practice and prepare returns, the client records, documents and tax return information belong to the firm. Crosstie holds and processes that information on the firm’s behalf and on its instructions, as a service provider. Crosstie is not the taxpayer’s accountant, has no engagement with the taxpayer, and does not decide what the firm does with its clients’ information.
If you are a taxpayer whose return your accountant prepares using this software, your relationship is with that firm. Ask the firm for its own privacy notice, and send requests about your information to the firm. Crosstie will refer such requests to the firm.
1. The information Crosstie collects through this website
If you join the early-access list, Crosstie records your email address; your name, if you give one; which products you ticked; your firm’s size band, if you select one; and, where present, the campaign tags in the link you arrived by (utm_source, utm_medium, utm_campaign) and the host name only of the site that referred you. Crosstie deliberately does not record the full referring URL, because a full URL can itself disclose what you were reading.
That information is used to reply to you, to send you an acknowledgement, and to email you about Crosstie’s products as they become available. Every such email carries an unsubscribe link, and unsubscribing stops them.
If you email us, we keep the message and your address so we can answer.
Analytics. These pages load Vercel Web Analytics from this site’s own domain. It reports aggregate traffic — pages viewed, referrers, country, device type. It does not set advertising cookies, does not track you across other websites, and does not build a profile of you.
Cookies. crosstietax.com sets no cookies of its own and uses no advertising or cross-site tracking technology. There is nothing here to opt out of.
What Crosstie does not do. Crosstie does not sell personal information, does not share it with advertising networks or data brokers, and does not use it to serve interest-based advertising.
2. Google user data: what the software accesses, why, and what happens to it
A firm using this software can connect its own Google account so that client documents and workpapers are filed in the firm’s own Google Drive. This section states exactly what that connection permits.
How the connection is made
An administrator at the firm starts the connection from Settings → Document storage inside the firm’s own deployment. Google’s own consent screen then appears, in the administrator’s own Google account. The firm grants access itself; Crosstie never asks for, and cannot accept, a Google password. Crosstie’s registered OAuth client identifies the application to Google.
The scopes requested, and what each is for
| Scope | What it permits | Why it is requested |
|---|---|---|
drive.file( https://www.googleapis.com/auth/drive.file) | Access only to files and folders the application itself creates, and to files a user explicitly opens with it | To create the firm’s client-files folder and the per-client folders beneath it; to store documents clients upload, signed engagement letters, receipts and exported workpapers; and to create and update Google Sheets workpapers |
openid | A signed assertion of which Google account completed the connection | To tie the connection to an account |
email | The email address of the account that connected | To show the firm, on its own settings screen, which Google account it is connected as, so it can see and verify its own connection |
drive.file is a per-file scope, not a whole-Drive scope. The application cannot see, list, search, read or modify anything else in the firm’s Google Drive. Files and folders it did not create are invisible to it. No other Google scope is requested — in particular, no scope giving access to Gmail, Calendar, Contacts, or a user’s Drive as a whole. Because drive.file is not a sensitive or restricted scope, Crosstie neither needs nor undergoes Google’s restricted-scope security assessment, and does not claim to have one.
What Crosstie does with Google user data
The access a firm grants is used solely to operate features the firm sees and uses in the application:
- Creating folders. At connection time, one root folder is created for the firm’s client files, and a folder per client beneath it.
- Writing files. Documents the firm’s clients upload through the portal, signed engagement letters, payment and estimated-tax receipts, and exported workpapers are written into those folders.
- Reading files. Files it created are read back — to show a document to firm staff, to extract figures from a document into the workpaper, and to verify what was written.
- Creating Google Sheets. A Google Sheets workpaper is created for a client, and the client’s name, tax year, entity type and the workpaper’s figures are written into it.
Google user data is not used for any other purpose. It is not used to train, test or improve any machine-learning or artificial-intelligence model. It is not used for advertising, for analytics about you, for benchmarking, for research, or for any product-development purpose. It is not sold, rented, or shared with data brokers or information resellers, and it is not used to assess credit-worthiness.
Where Google user data is stored, and who can see it
The files themselves stay in the firm’s own Google Drive, in the firm’s own Google account. Crosstie does not copy a firm’s Drive into a separate document repository of its own. What is stored in Crosstie’s systems is the connection itself and the references needed to find those files again: the Google account email address, the identifier of the root folder, the identifiers and names of files created, and the refresh token — encrypted, as section 5 describes.
No human at Crosstie reads a firm’s Google user data as a matter of course. Access happens only where it is necessary to provide support the firm has asked for, or to diagnose a defect, and the application records who opened what.
Google Limited Use disclosure
Crosstie’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, and in the terms of that policy:
- Crosstie limits its use of data obtained through these scopes to providing and improving user-facing features that are prominent in the application’s own interface.
- Crosstie does not transfer that data except to provide or improve those user-facing features with the user’s consent, for security purposes, to comply with applicable law, or in connection with a merger, acquisition or sale of assets after obtaining the user’s explicit prior consent.
- Crosstie does not allow humans to read that data unless the user has given affirmative agreement to view specific files, it is necessary for security purposes, it is necessary to comply with applicable law, or the data is aggregated and used for internal operations consistent with applicable law.
- Crosstie does not transfer or sell that data to advertising platforms, data brokers or information resellers; does not use it for serving advertising, including retargeting or personalized advertising; and does not use it to determine credit-worthiness or for lending.
Disconnecting
An administrator can disconnect the storage connection at any time from Settings → Document storage. The stored token is cleared and revocation is requested from Google. The firm’s files remain in the firm’s own Drive, where they already were; the application simply loses access to them. A firm can also revoke access directly from its own Google account security settings.
3. Microsoft OneDrive
A firm may connect Microsoft OneDrive instead of Google Drive. It works the same way — the firm signs in to its own Microsoft account and grants access on Microsoft’s own screen — and is used for the same purpose: storing client folders, documents, letters, receipts and workpaper exports in the firm’s own storage.
| Permission | What it permits | Why it is requested |
|---|---|---|
Files.ReadWrite | Read and write files in the signed-in account’s own OneDrive | To create and use the firm’s client-files folders. OneDrive has no per-file equivalent of Google’s drive.file, so this permission is broader than the Google one: it reaches the connected account’s OneDrive, not only the folders the application created. A firm choosing OneDrive should know that. |
User.Read | The signed-in account’s basic profile | To show the firm which account it is connected as |
offline_access | A refresh token | So files can be written when nobody is signed in to Microsoft — for example when a client uploads a document overnight |
The application acts as the account that connected, in that account’s own OneDrive. No application-level permission across a Microsoft tenant is requested.
4. Where a firm’s data actually lives
Client records, documents and tax return information handled through this software sit in three places, and it is worth being plain about which is which.
- The application database (Supabase). Client records, engagements, workpapers and trial balances, computed figures, the firm’s own books where it uses the accounting module, staff accounts, notes, and the access log. Each firm’s deployment has its own database; firms are not commingled in one shared set of tables.
- The firm’s own Google Drive or OneDrive. The primary home for client documents. Documents clients upload through the portal, signed engagement letters, audit trails, receipts and exported workpapers are written there, and some of them exist only there. A storage bucket in the application database serves as a fallback and holds the firm’s uploaded logo and branding images.
- Cloudflare R2. Backups only. A weekly job writes a database dump and an archive of the client-documents folders to R2 storage, so that a loss can be recovered from. Backup copies are deleted after 90 days.
United States only. All of this is held on infrastructure located in the United States: Crosstie’s hosting, database, storage and backups run in Amazon Web Services’ US East (Northern Virginia) region. Crosstie does not store or process this information outside the United States, and will give a firm advance written notice before that changes.
5. How connection tokens are stored and refreshed
When a firm connects Google Drive or OneDrive, the application receives a long-lived refresh token. That token is the firm’s standing grant of access, so it is handled accordingly.
- It is encrypted before it is stored, with AES-256-GCM, under a key held in the deployment’s server-side environment and not in the database. A stored token is unreadable to anyone holding only a copy of the database.
- It is never returned by any part of the application. No screen, API response or export discloses it.
- It is used only server-side, to obtain short-lived access tokens from Google or Microsoft as calls are made. Where the provider issues a replacement refresh token, the replacement is re-encrypted and stored and the old one discarded.
- The flow that establishes a connection is authorized by a single-use value that expires in ten minutes and names the administrator who began it.
- When a connection is disconnected, the stored token is cleared and revocation is requested from the provider. Disconnected connections are retained as a record that a connection once existed, without a usable token.
Crosstie does not store full payment card or bank account numbers. Card details are handled by Stripe.
6. Service providers
Crosstie uses the providers below, each for the purpose named and no other. This list is updated when a provider is added or removed.
| Provider | Used for | Handles client or taxpayer information? |
|---|---|---|
| Supabase | Application database, authentication, and the fallback document bucket | Yes |
| Vercel | Application and website hosting; Web Analytics on this website | Yes, as the host the application runs on |
| Cloudflare (R2) | Weekly backup storage | Yes, in backups |
| Google (Drive, Sheets) | The firm’s own document storage and workpaper Sheets, where the firm connects Google | Yes, in the firm’s own Google account |
| Microsoft (OneDrive, Graph) | The firm’s own document storage, where the firm connects OneDrive | Yes, in the firm’s own Microsoft account |
| Stripe | Subscription payments to Crosstie, and, where a firm uses the software to collect client payments, payment processing for the firm | Payment and contact details; not tax return information |
| Resend | Sending email — this site’s acknowledgements, and the application’s notifications to firm staff and clients | Names, email addresses, and the contents of those messages |
| Quo | Text messaging, where a firm licenses the texting module | Phone numbers and message contents |
| Mercury | Bank transaction feed, where a firm uses the accounting module for its own books | The firm’s own banking data |
| Cal.com | Appointment scheduling, where a firm uses the scheduling feature | Names, email addresses, appointment details |
| GitHub | Where the code is held, and where the weekly backup job runs | Only in transit during the backup job |
7. Taxpayer information, §7216, and the FTC Safeguards Rule
The information a firm handles through this software is tax return information, and both Crosstie and the firm have obligations about it worth stating exactly.
The firm is the tax return preparer. The firm, and the individual who signs a return, are the preparer. Crosstie does not prepare returns, does not sign them, is not identified as a preparer on any return, and exercises no professional judgement for the firm. Crosstie receives tax return information as a person assisting the firm in providing tax return preparation services, and uses and discloses it only as the rules permit such a person to do.
Consents are the firm’s to obtain. Where the law requires a client’s written consent before tax return information may be used or disclosed — including under 26 U.S.C. §7216 and 26 C.F.R. §301.7216-3 — obtaining that consent, and deciding whether it covers a given use, is the firm’s responsibility as the preparer. Crosstie does not decide what consent a firm needs.
Where a firm uses preparers outside the United States. A firm that answers yes to “Preparers outside the United States” in its settings gets a §7216 disclosure section in its engagement letter and a consent election presented to each client at signing. Files are then routed to a domestic or international file room according to the consent recorded, so that personnel or contractors located outside the United States can be given access to a file only where the client’s consent permits it. Which of its people are given that access, and whether a consent supports it, are the firm’s decisions.
Safeguards. The FTC Standards for Safeguarding Customer Information (16 C.F.R. Part 314) require a firm to oversee its service providers. The controls Crosstie can point to are: encryption of stored connection tokens as described in section 5; transport encryption for data in transit; two-factor authentication required for staff accounts, enforced in the database as well as in the application; row-level access rules in the database, with each firm’s deployment holding its own database; an access log recording who opened which client record; a per-file storage scope for Google Drive; weekly backups with their integrity verified on upload; automated security checks that block a release; and a weekly security audit. Crosstie does not hold a SOC 2 report or any other third-party security certification, and does not claim one.
8. Retention
This website. Early-access list entries are kept while the list is active. Ask us to remove yours and we will.
A firm’s data, while the firm is a customer. It is kept for as long as the firm uses the service, because the firm needs it.
Financial records are held for seven years. The database enforces a seven-year retention period on financial records — journal entries and lines, accounts, trial-balance data, fixed assets, loans, client ledgers and bank transactions. A deletion of one of these rows is refused unless the row and its detail are first copied into an append-only archive, and that archive cannot itself be altered or deleted. Rows older than seven years are exempt from the rule and can be removed. This exists so that a firm’s accounting records cannot be silently lost, and it means a deletion request against a financial record produces an archived copy rather than an erasure.
Backups. Backup copies in Cloudflare R2 are deleted 90 days after they are written. A record removed from the live system can therefore persist in a backup for up to 90 days.
After a firm leaves. Export and deletion on termination are governed by the firm’s subscription agreement with Crosstie, which sets the transition period, the export right, and when data is deleted.
9. Your choices and requests
If you are on the early-access list, you can unsubscribe from the link in any email, or ask us to delete your entry.
If you are a firm using the software, you can export your client data and your work product from the application at any time, in a machine-readable format.
If you are a taxpayer, the firm that prepared your return is the one with your engagement and the one that decides what happens to your information. Please send access, correction and deletion requests to that firm. Crosstie will act on the firm’s instruction and will pass such requests to the firm.
Some jurisdictions give individuals rights to access, correct, delete or port personal information, or to object to its processing. Where such a right applies to information Crosstie holds as a controller — this website and our own correspondence — contact us and we will respond. Where it concerns a firm’s client data, the firm is the one to ask, for the reason above.
10. Children
Crosstie is sold to accounting and tax firms and is not directed to children. Crosstie does not knowingly collect personal information from children through this website. A tax return may of course contain information about a taxpayer’s dependants; that information reaches Crosstie only from the firm, as part of the firm’s work for its client, and the firm’s engagement governs it.
11. Legal process
If Crosstie receives a subpoena, court order or other legal demand for a firm’s client data, Crosstie will, unless the law forbids it, notify the firm before responding, give the firm the opportunity to object or seek protection, and disclose no more than the demand requires. Where it may lawfully do so, Crosstie will direct the requester to the firm.
12. Security incidents
If Crosstie becomes aware of unauthorized access to, or acquisition, use, disclosure or loss of, a firm’s client data, Crosstie will notify the firm without undue delay and give it the information and cooperation it needs to meet its own reporting obligations, including to the IRS, state authorities and the FTC. The firm decides whether and how to notify its own clients, except where the law requires Crosstie to notify them directly.
13. Changes to this policy
Crosstie will update this page when its practices change, and will change the date at the top. Where a change materially affects how a firm’s client data is handled, Crosstie will tell the firm. Where a change would affect how Google user data is used, Crosstie will update this policy and seek consent before using that data in the new way, as Google’s policy requires.
14. Contact
Questions about this policy, or a request about your information: hello@crosstietax.com.
Crosstie, Inc.
8 The Green, Suite B
Dover, DE 19901
United States
Crosstie, Inc. is a Delaware corporation.