BoardReady

Guides · BR-10

Board Package Document Privacy in NYC: Handling Tax Returns & Bank Statements

Board package document privacy is about how NYC deal teams move a buyer's tax returns, bank and brokerage statements, IDs, and SSNs from client to managing agent without leaving copies in email threads, shared drives, or tools that retain them.

This page is for buyer's agents, real-estate attorneys, and package coordinators / TCs who already move client tax returns, bank and brokerage statements, IDs, and SSNs through assembly — and who worry about client PII and firm risk when those files sit in email threads, shared drives, consumer chat tools, or an unvetted upload box. It is not a buyer identity-theft FAQ, and it is not a checklist of what documents to gather. Those jobs live elsewhere.

The promise is a practical map: which exhibits concentrate risk, where handoffs usually leak copies, what a safer intake-to-submit path looks like, and what BoardReady publicly commits to on privacy. Ask every tool the same questions. Then pick a channel your firm will actually stand behind.

BoardReady is NYC co-op and condo board package assembly software — requirements in, documents classified, missing items left in view, one ordered PDF out. Privacy claims below match the homepage Documents block only. Features can change; re-read that block the day you rely on it.

This is not legal, financial, or tax advice, and it is not compliance or cybersecurity advice. Firm policies and counsel control how your desk handles client files. Nothing here is a certification, a retention SLA, or a guarantee that a package will be approved.

Why board packages are a high-sensitivity workflow

A complete board package is a concentrated PII packet. Typical high-risk exhibits — named here as patterns, not as a submit-against list — include federal (and sometimes state) tax returns with schedules; bank, brokerage, and retirement statements; pay stubs; government IDs; financial-statement forms that may carry SSNs or account identifiers; and gift letters with supporting statements. Practitioner checklists and assembly write-upsdescribe the same categories. The building's current packet is still the source of truth (extract this building's real checklist).

Completeness and privacy pull in opposite directions if you treat them as a trade-off. The same file that must be complete for the managing agent — every required page, including blank statement pages — is also the file you do not want sitting in a personal Downloads folder or a forwarded thread. What managing agents check is a completeness gate. Privacy is how those pages travel before that gate. A bounced package for a missing schedule is an assembly error (bounce-backs vs financial weakness). A return that also lives in three inboxes is a different problem.

Assembly vs submission

Completeness QC and privacy are related and not the same job. You still need every page the building asked for. Privacy is how and where those pages travel — intake, working set, QC review, and the channel the managing agent actually requires at the end. Assembly software and a building portal often stack: assemble and QC in one place, then submit through the required portal, inbox, or messenger. That coexistence is the preparers vs portals vs assembly software map. Do not skip the building's required channel because the working file already looks orderly.

Where PII risk actually creeps in (pro habits)

These are common desk habits, not accusations. Most of them start as speed.

  1. Personal email threads with the full return attached — "can you print this?" — and then a reply-all that keeps the attachment alive.
  2. Shared drives and personal cloud folders with loose permissions, a lingering ex-employee account, or a folder named after the buyer that never gets closed.
  3. Consumer AI / chat tools used to "summarize" or "reorganize" a tax PDF. Retention and training policies vary. Many consumer tools are not built for client financials. Treat an unpublished policy as a no.
  4. Over-broad CC lists and forwarding chains to third parties who do not need the full return — a lender contact, a roommate, last month's TC.
  5. Skipping the building's required channel at the end and emailing management "because it was faster" after a careful assemble. The last mile is still a handoff.

SellWise and the "approved channel" consensus

This is industry hygiene, not a product comparison. SellWise's co-op board checklist tells assemblers: handle financial records securely; confirm the authorized recipient and submission method before sending tax returns, account statements, identification, or other sensitive information. The same page's QC list includes a line that sensitive files are being sent through the approved channel. That is the standard to brief a desk on. This page does not invent SellWise encryption or retention features — that checklist does not claim them.

Redaction is not DIY policy

The same SellWise noteis the right caution: redact only when the building or transaction counsel confirms that redaction is permitted. There is no citywide "always black out account numbers" rule you can apply from a blog. Blind DIY redaction can make a package incomplete or non-compliant with the packet the managing agent issued. Ask. Then follow the written instruction.

A practical sensitive-doc path for deal teams

Keep one intentional path from intake to archive. Minimize extra copies. Name the person who is allowed to open the full return.

StageGoalPrivacy habit
IntakeCollect from client / third partiesFirm-approved intake only; minimize copies
Assembly / classifyMatch docs to building requirementsPrefer tools with a clear retention stance; keep the working set small
QCCompleteness before the managing agent sees the fileLimit who opens full returns; still include every required page
SubmitDeliver to the managing agentOnly the building’s required portal / email / messenger instructions
ArchiveFirm retention rulesFollow firm policy; do not leave forever in personal Downloads

Assembly software and portals often stack. Assemble and QC first, then submit through the channel the managing agent requires — see the tools map. The ordered PDF is the assembly deliverable (building order, dividers, bookmarks). It is not a license to invent a second submission inbox.

What to ask any tool before you upload a return

Ask these of any SaaS, portal, or AI assistant — not only of BoardReady. Quote the vendor's public page. Do not upgrade marketing adjectives into controls your firm has not verified.

The next section maps BoardReady's published answers. Only homepage claims. A dedicated documents write-up lives at how BoardReady handles tax returns and bank statements; this article still quotes the homepage Documents block so the privacy lines stay in one place.

BoardReady's published privacy stance (quote the site)

Product frame from the homepage: software for buyer's agents, attorneys, and package coordinators / TCs to turn building transfer requirements and client docs into one complete, ordered board package PDF. What it is not: not a managing agent, not a board, not a guarantee of approval. Not the building's submission portal.

Documents block, paraphrased tightly and quoted where the wording matters:

  1. Encrypted so storage cannot read them. "Files are encrypted with a key we hold. The storage provider cannot open them." BoardReady holds the key. That is not a claim that BoardReady staff cannot access files, and it is not zero-knowledge.
  2. Only you can open a package. "Another account asking for that id gets nothing back — not a hint that it exists."
  3. Models do not keep a copy. "We assemble on hosts that do not retain prompts. Labs that keep or train on documents are refused."

That is the published differentiator for desks that will not drop a return into a tool that trains on uploads. It is not HIPAA, SOC 2, ISO, PCI, "bank-grade," or "military-grade." Those words are not on the homepage. The homepage states $99 unlocks the assembled PDF download. Privacy is not a price argument; that number is here only because it is live on the site today.

How this fits the assembly workflow

Same three steps as the homepage: drop the building package, add client docs, get a board-ready PDF. The professional workflow for assembling a co-op board package is the full sequence. If a financial statement is in play, tie balances to supporting statements in the working set — do not paste numbers into a random chatbot (why statements must tie to the financial statement). Then submit only through the managing agent's required channel. Co-op vs condo gates change the packet, not the privacy habit (co-op vs condo packages for deal teams). Completeness clocks still want a clean first submit (Local Law 58 for assemblers).

If the desk already assembles the file

If your firm will not drop tax returns into tools that retain or train on uploads, read BoardReady's Documents policy on NYC co-op & condo board package software — then try it on the next package. Upload the building requirements, add client docs, keep missing items visible until the ordered PDF is ready. Assemble and QC first; submit only through the managing agent's required channel. BoardReady is built for the assembly step.

NYC co-op & condo board package software →·Walk through the demo

FAQ

Is it safe to upload tax returns to board package assembly software?

Safety depends on the vendor's published controls and your firm's policy. Ask who can open the file, whether storage is encrypted and who holds the keys, and whether models retain or train on uploads. BoardReady's homepage states encrypted storage (a key BoardReady holds; the storage provider cannot open the files), account isolation, and no model retention — labs that keep or train on documents are refused.

Should I email the client’s full tax return to teammates or the managing agent?

Prefer firm-approved channels. For teammates, keep the working set small and avoid personal threads with the full return attached. For the managing agent, follow their required submission method — portal, specific inbox, or messenger. SellWise and other practitioner notes emphasize confirming the authorized recipient and approved channel before sending sensitive financials.

Do AI tools keep or train on documents I upload?

Policies vary by product. Treat "summarize my tax PDF in a consumer chatbot" as high risk unless the vendor explicitly refuses retention and training. BoardReady states that models do not keep a copy and refuses labs that keep or train on documents (homepage).

Can another BoardReady account see my client’s package?

Per the homepage: another account asking for that id gets nothing back — not a hint that it exists. Only the owning account can open a package.

Is BoardReady a substitute for the building’s secure portal?

No. BoardReady is assembly software. If the building requires Domecile or another portal, assemble and QC first, then submit through the required channel. See preparers vs portals vs assembly software.

Should I redact SSNs and account numbers?

Only when the building's instructions or transaction counsel say redaction is permitted. Blind DIY redaction can make a package incomplete or non-compliant with the packet. SellWise makes the same caution. This page does not invent a universal redaction rule.

Does using BoardReady guarantee we meet a privacy law or certification?

No. Homepage privacy claims are product behaviors, not legal certifications. This page does not claim HIPAA, SOC 2, ISO, PCI, or any other badge. Firm counsel and compliance own legal standards.

The path, once

If your desk already assembles packages and wants encrypted storage with no model retention as stated on the site, try NYC co-op & condo board package software on the next file. Related: the assembly workflow, the managing-agent gate, assembly bounce-backs vs financial weakness, stacking assembly and portals.

This is not legal, financial, or tax advice. Firm policy and counsel control the deal. Product features can change — re-check the homepage Documents block before you brief a compliance lead.

← All guides·NYC co-op & condo board package software