Privacy Policy

Privacy Policy

Grimlow LLC Doing business as Grimmett & Company, Grimmett Co, and VegasTax

Effective date: September 24, 2026 Last updated: September 24, 2026


1. Introduction and scope

This Privacy Policy explains how Grimlow LLC (“Grimlow,” “we,” “us,” or “our”), doing business as Grimmett & Company, Grimmett Co, and VegasTax, collects, uses, discloses, and protects personal information in connection with:

  • Our website at https://grimmettco.com and related pages (the “Site”);
  • Online forms, email, and phone inquiries;
  • Our customer-care text messaging (SMS) program;
  • Document intake links we send to clients or prospects (for example, Microsoft SharePoint request-file links); and
  • Related digital communications about tax, accounting, and consulting services.

This Policy does not replace a signed engagement letter, power of attorney, or other written agreement that governs a client relationship. Confidentiality and use of information collected in the course of professional services are also governed by those documents, applicable professional standards, and law.

As a tax and accounting practice, we are subject to the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, which require us to maintain a written information security program to protect customer information. This Policy describes our public-facing privacy practices; our internal Written Information Security Plan (WISP) addresses operational safeguards in more detail.

By using the Site or submitting information to us, you acknowledge this Policy. If you do not agree, please do not use the Site or submit personal information.


2. Who we are / contact

Legal entity Grimlow LLC
Trade names (DBAs) Grimmett & Company; Grimmett Co; VegasTax
Privacy / general contact email info@vegastax.com
Office / voice phone (702) 795-2311
Customer-care SMS number (702) 840-1040
Mailing / office address 2651 Paseo Verde Pkwy, Suite 155, Henderson, NV 89074

For privacy requests, email info@vegastax.com with the subject line “Privacy Request.”


3. Categories of personal information we collect

3.1 Identifiers and contact information

Name, email address, phone number, postal address, business name, and similar contact details.

3.2 Commercial and relationship information

Inquiry details; subscription or service interest; appointment preferences; and records of communications with us (including SMS).

3.3 Tax, financial, and other sensitive information you choose to submit

Documents and data you send for tax, accounting, or consulting purposes (for example, tax returns, W-2s, 1099s, bank or brokerage statements, entity documents, government ID copies, or Social Security / EIN numbers). We collect this only when you or your authorized representative voluntarily provide it in connection with an inquiry or engagement.

3.4 SMS and mobile information

Mobile phone number; SMS opt-in / opt-out and consent records; message content and delivery metadata needed to operate the Care SMS program.

3.5 Internet and device information

IP address; browser type; device identifiers; pages visited; referring/exit pages; dates and times of access; and similar log data. We use hosting and platform cookies needed to operate the Site; we do not currently use third-party analytics or advertising pixels that track you across other sites for advertising.

3.6 Professional or employment-related information

Job title, employer, or business role if you provide them.

We do not knowingly collect personal information from children under 13 (see Section 14).


4. Sources of personal information

  • Directly from you — forms, email, phone, SMS, uploads to links we send you, and in-person or remote meetings.
  • Automatically — cookies, server logs, and similar technologies when you use the Site.
  • Service providers — hosting, email, messaging (including Twilio), tax/accounting software (for example Intuit ProConnect where used), and collaboration tools that process data on our behalf.
  • We do not typically purchase consumer lists for Site marketing; if that ever changes, we will update this Policy.

5. How we use personal information

We use personal information to:

  • Respond to inquiries and schedule appointments;
  • Provide and administer tax, accounting, and consulting services after an engagement is accepted;
  • Operate our customer-care SMS program;
  • Send service-related (non-marketing) communications;
  • Maintain security, prevent fraud and abuse, detect unauthorized access, and debug the Site and systems;
  • Comply with law, professional obligations (including IRS and FTC requirements applicable to tax professionals), and valid legal process;
  • Enforce our Terms and protect our rights; and
  • Operate, maintain, and secure the Site and our systems.

We do not sell your personal information. We do not sell mobile phone numbers or SMS consent records.


6. Cookies, analytics, and similar technologies

We use cookies and similar technologies that are necessary to operate the Site (for example, security, load balancing, session management, and remembering basic preferences).

We do not currently use third-party advertising pixels or analytics products that track you across other websites for advertising. We use hosting and platform cookies needed to run the Site. If we add analytics or advertising technologies later, we will update this Policy.

Third-party embedded content (if any) on the Site may set its own cookies subject to the third party’s policies.


7. Text messaging (SMS) / mobile information

Grimlow LLC operates a customer-care SMS program from (702) 840-1040. Messages relate to tax, accounting, or consulting engagements and may include appointment reminders and confirmations, document or information requests, status updates on work in progress, and replies when you text the firm for help with your engagement.

  • Message frequency varies with the engagement.
  • Message and data rates may apply.
  • Consent is not a condition of purchasing or receiving services.
  • We store consent with your client or prospect record.
  • We do not sell your phone number or SMS consent data.
  • We may share message delivery data with our messaging providers (including Twilio) and wireless carriers as needed to deliver texts.
  • Mobile opt-in data and consent records are not shared with third parties or affiliates for their own marketing.
  • Reply STOP to opt out of further SMS from this program. Reply HELP for help.
  • For SMS support: (702) 795-2311 or info@vegastax.com.

Program details and additional terms appear in our Terms and Conditions (Part B — SMS / Messaging Program Terms) and on our SMS opt-in page: https://grimmettco.com/sms-opt-in/.

Consent language note: Where we obtain SMS consent (including checkboxes), the consent identifies Grimlow LLC as the sender. Trade names may appear elsewhere for brand clarity but are not substituted for Grimlow LLC in the consent statement.


8. How we disclose personal information

We may disclose personal information to:

Recipient type Purpose
Service providers / processors Website hosting; email and productivity suites; Microsoft 365 / SharePoint (document intake and collaboration); Twilio and wireless carriers (SMS delivery); tax preparation / practice software (e.g., Intuit ProConnect where used); spam/security filters; IT and support vendors — under contracts requiring appropriate use and protection
Professional advisors Attorneys, insurers, or consultants as needed to operate the firm
Legal / compliance When required by law, court order, government request (including IRS or state tax agencies), or to protect rights, safety, and security
Business transfers In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

We do not publish a public website short link for client document upload. When document intake is needed, we provide a secure link directly (for example by SMS or email).


9. Security of personal information

We maintain administrative, technical, and physical safeguards designed to protect personal information, consistent with our obligations under the FTC Safeguards Rule and IRS guidance for tax professionals (including themes in IRS Publications 4557 and 5708). Safeguards may include, as appropriate to our size and systems:

  • Access controls and need-to-know limitations for client data;
  • Multi-factor authentication for systems that access customer information, where required or reasonably available;
  • Encryption of sensitive information in transit and, where feasible, at rest;
  • Anti-malware / endpoint protections and timely software updates;
  • Secure document intake and collaboration tools (for example SharePoint links we send directly);
  • Employee awareness expectations regarding phishing and unauthorized disclosure; and
  • Vendor oversight for service providers that handle customer information.

No method of transmission or storage is completely secure. If we believe a security incident affecting your information has occurred in a way that triggers notice duties under applicable law (including FTC Safeguards Rule notification events, state breach laws, or IRS/state tax agency guidance for tax professionals), we will notify you and regulators as required.

This Section describes our public security posture. Detailed procedures, risk assessments, hardware inventories, and incident-response playbooks live in our internal Written Information Security Plan (WISP) and are not published on the Site.


10. Retention

We retain personal information only as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law or our professional obligations.

Data type Retention approach
Website / marketing inquiries 36 months after last contact, then delete or anonymize unless converted to a client file
SMS consent and message logs While the relationship is active, and for at least 4 years after opt-out or last message, for compliance and dispute defense
Client tax and accounting files Per our engagement letter and firm record-retention policy, and as required by IRS / applicable law. Client files are retained according to our engagement letter and firm schedule; ask us for our current retention schedule
Site server logs Up to 24 months, unless needed longer for security or legal purposes

Under the FTC Safeguards Rule, customer information that is no longer needed is generally disposed of securely (with limited exceptions for legal or business need). Our internal WISP addresses secure disposal methods.


11. Your privacy rights (general)

Subject to applicable law and exceptions (including records we must keep for tax, legal, or security reasons), you may request to:

  • Access or receive a copy of certain personal information we hold about you;
  • Correct inaccurate information; and
  • Delete certain personal information.

To submit a request, email info@vegastax.com with “Privacy Request” in the subject line and enough detail for us to verify your identity and locate your information.


12. California privacy rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA (“CCPA”), may provide additional rights.

12.1 Categories collected and disclosed

In the prior 12 months, we may have collected the categories listed in Section 3, and disclosed them to service providers for the business purposes in Sections 5 and 8. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

12.2 Sensitive personal information

We may process sensitive information you submit for professional services (for example SSN, financial account data, or government ID). We use it only to provide the requested services, comply with law, and secure our systems — not to infer characteristics for advertising.

12.3 Your CCPA rights

California residents may have the right to know, delete, correct, and limit certain uses of sensitive personal information, and to be free from discrimination for exercising CCPA rights. Because we do not sell or share PI for cross-context behavioral advertising, a “Do Not Sell or Share” link is not required at this time; if that changes, we will update the Site and this Policy.

12.4 How to submit a CCPA request

Email info@vegastax.com or call (702) 795-2311. Authorized agents must provide proof of authority. We will verify and respond within the timeframes required by law.


13. Children’s privacy

The Site is directed to adults and businesses. We do not knowingly collect personal information from children under 13. If you believe a child provided information, contact us and we will delete it as required.


14. Third-party sites

The Site may link to third-party websites or services. Their privacy practices are their own. Review their policies before providing information.


15. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be highlighted on the Site or communicated by email or SMS where appropriate. Continued use of the Site after an update means you acknowledge the revised Policy.


16. Contact us

Grimlow LLC d/b/a Grimmett & Company, Grimmett Co, and VegasTax 2651 Paseo Verde Pkwy, Suite 155, Henderson, NV 89074 Email: info@vegastax.com Voice: (702) 795-2311 SMS Care: (702) 840-1040


This Policy is provided for website and SMS compliance purposes. It is not legal advice to third parties. Our internal WISP is maintained separately and is available to clients upon request where appropriate and with consent of our Data Security Coordinator.