Collecting tax documents from clients without email
To collect W-2s, 1099s and other tax documents without email attachments, send each client a ShieldFive document request: one link with the list of forms you need, which the client opens on a phone or computer and uploads to without creating an account. Each file is encrypted in the client's browser before upload, so ShieldFive stores only ciphertext and never holds your keys.
Specs
Updated .
| Client needs an account? | No. No account, no sign-in, no app. The client needs the link and the PIN. |
|---|---|
| PIN | Required, at least 4 characters, chosen by you and sent separately from the link. |
| Max file size | 5 GB per file. |
| Max per request | About 2 GB in total by default. |
| Files per request | 25 by default, adjustable from 1 to 100. |
| File types | Any type: PDFs, phone photos, spreadsheets. |
| Checklist | Up to 100 requested items per request. A Form 1040 template, transcribed from the IRS "Gather your documents" list, is built in. |
| Link expiry | Up to 7 days on the free plan. 7, 30 or 90 days, or no expiry, on Firm seats and during the 14-day trial; 30 days by default. |
| Reminders to you | An email when files arrive, and a reminder to follow up if nothing has arrived after about 3 and 7 days. Every plan. |
| Reminders to the client | On Firm seats and during the trial, if you add the client's email: at most 2, after about 3 and 7 days, while required items are missing. |
| Plans | 14-day trial with everything unlocked, no card. Then free with 1 open request at a time, or a Firm seat at €29 per month (€290 per year). Clients never pay. |
| Encryption | Client-side, in the client's browser, to your firm's public keys. File names and the checklist are encrypted too. ShieldFive never holds the keys. |
Steps
- Unlock your vault, open Requests and choose Request documents.
Start from the Individual tax return (Form 1040) template, or list the forms yourself, one per line. Delete what does not apply to this client. End a line with "(optional)" to mark it optional.
Set a PIN, the number of files, and an expiry that covers your deadline. Optionally add the client's email so ShieldFive can remind them.
Select Create secure link. Put the link in your engagement email instead of "send me your documents", and give the PIN by text or on the phone.
The client opens the link, types the PIN and uploads a photo or PDF into each slot. They can send what they have and come back to the same link for the rest.
When you are emailed that something arrived, open Requests and use Download & decrypt. Revoke the link once you have everything; received files stay in your vault.
Limits
ShieldFive does not email the link for you. Part of the decryption key is in the
#fragment of the link and never reaches our servers, so you send the link yourself, and it has to arrive complete.The client-reminder email cannot contain the upload link, for the same reason; it points the client back to the link you sent.
There are no recurring requests. Next season you create a new request, though you can reuse the checklist with Send this checklist to another client.
It collects documents. It does not e-file, e-sign or bill.
Clients choose files, not folders. The page has to stay open while files encrypt and upload.
Nothing identifies the uploader automatically. If you need to be certain who sent a document, confirm it with the client through a channel you already trust.
The upload page is code ShieldFive serves, so the client trusts that code at the moment of upload, as with every browser-based encryption product.
Full details of every limit are in Requesting documents from a client. For why email is a poor channel for tax forms, see Stop emailing W-2s and 1099s, and for the checklist itself, the Form 1040 document checklist.