Privacy Policy
Effective date / version: 2026-09-26 · privacy v1.1
(1) Plain-Language Summary
- Who we are and who we work for. SteadFile LLC operates a web platform that helps businesses ("Payers") collect IRS Form W-9 and W-8 series tax forms from the people and entities they pay ("Payees"). For most of what we do with your information, we act on the Payer's instructions as their service provider/processor. The Payer decides why your information is collected.
- What we collect. Identity details (name, address), your taxpayer ID (SSN, EIN, or foreign TIN), tax status and tax-treaty claims, your e-signature, and verification/technical records (email one-time-passcode events, IP address, browser user agent, timestamps).
- Where it goes. Your completed form and its data are made available to the Payer who invited you. We use vetted infrastructure vendors (database/hosting/email) to run the service. We do not sell or "share" your personal information for advertising.
- Your key rights. Depending on where you live, you can ask to access, correct, delete, or receive a copy of your information, and limit use of sensitive data. Because we usually act for the Payer, we will route many requests to the Payer. Tax-record and legal-defense obligations may require us to keep some records even after a deletion request.
- Contact. privacy@steadfile.com.
(2) Scope and Roles — Our Dual-Role Architecture
SteadFile plays two distinct roles:
(a) Processor / Service Provider (most processing).
When a Payer invites you and you complete the questionnaire, e-sign, and generate your IRS form, SteadFile processes your information on the Payer's behalf and under the Payer's documented instructions. The Payer is the "controller" (GDPR/UK GDPR) and "business" (US state law). For this payer-directed data, SteadFile does not decide the purposes of processing, and privacy requests about that data are routed to the Payer as the responsible party. We support the Payer in responding.
(b) Independent Controller (limited purposes).
SteadFile acts as an independent controller only for: (i) security and fraud prevention; (ii) legal compliance, including retention of tax records and evidentiary consent/verification/signing records; and (iii) creating de-identified/aggregated analytics to improve the service. For these limited purposes you may contact us directly.
(3) Data Inventory
| Category | Source | Purpose | Lawful basis (GDPR/UK GDPR) | Retention | Recipients |
|---|---|---|---|---|---|
| Identity data (name, address, entity classification) | You (Payee) | Populate the correct IRS form; make it available to the Payer | Legal obligation (tax); contract/legitimate interests of Payer (as controller) | With Payer for the relationship; withholding-certificate baseline of at least 4 years | Payer; infrastructure subprocessors |
| Taxpayer IDs (SSN, EIN, foreign TIN) — sensitive | You (Payee) | Complete W-9/W-8; backup-withholding/FATCA determinations | Legal obligation; substantial-public-interest/tax basis | At least 4 years; masked in the interface, with each reveal recorded in an audit log | Payer; infrastructure subprocessors |
| Tax status & treaty claims | You (Payee) | Suggest/populate correct form; treaty benefit claims | Legal obligation; contract | At least 4 years | Payer; infrastructure subprocessors |
| E-signature + signing metadata (artifact hashes, timestamps) | You (Payee) | Execute and evidence the certification | Legal obligation; legitimate interests (evidence/defense) | Legal-defense periods | Payer; infrastructure subprocessors |
| Verification data (email OTP events) | You + system | Verify identity of signer; anti-fraud | Legitimate interests (security); legal obligation | Legal-defense periods | Infrastructure subprocessors |
| Technical/session data (IP address, user agent) | System | Deliver the app; security; evidence | Legitimate interests (security/operation) | Legal-defense periods for evidentiary logs | Infrastructure subprocessors |
| Payer account data (name, work email, company name, login credentials) | You (Payer) | Create and secure your account; deliver the service | Contract; legitimate interests (security) | Life of the account plus legal-defense periods | Infrastructure subprocessors; Stripe (billing contact details) |
| Uploaded documents (e.g., a previously completed IRS form) | You (Payee or Payer) | Complete the Payer's form-collection request | Legal obligation (tax); contract | At least 4 years | Payer; infrastructure subprocessors |
(4) How Information Is Shared
- The Payer. The core function of the platform is to deliver your completed form and its data to the Payer who invited you.
- Subprocessors. We use Supabase (database, storage, authentication; hosted on AWS in the US East (Ohio) us-east-2 region), Vercel (application hosting), Stripe (subscription billing for Payers — card details are entered directly with Stripe and are never stored by SteadFile), and a transactional email provider (e.g., Resend) to send invitation and verification emails. Each is bound by a data-processing agreement and processes personal data only to provide services to us.
- Legal requirements. We may disclose information to comply with law, respond to lawful requests, or establish/exercise/defend legal claims.
- We do not sell or "share" personal information. Under the CCPA (as amended by the CPRA), "sale" means disclosing personal information for monetary or other valuable consideration, and "sharing" means disclosing it for cross-context behavioral advertising. SteadFile does neither. Disclosures to our subprocessors are service-provider disclosures, and delivery to the Payer is the requested service — neither is a sale or share.
(5) Security Summary
We maintain technical and organizational measures consistent with our Payer data-processing agreements, including: encryption in transit and at rest; TIN masking in the interface with audited reveal events; role-based access controls; and append-only audit logging. No system is perfectly secure, and we do not guarantee absolute security; we describe our safeguards without promising a specific outcome.
(6) Retention and Deletion
- Tax records. Because W-9/W-8 records are withholding-certificate records, they are retained for at least four years, consistent with IRS recordkeeping requirements for withholding certificates.
- Evidentiary records. Consent events, OTP verification, signing metadata, and artifact hashes are retained for legal-defense periods.
- Deletion interaction. We honor deletion rights subject to legal-obligation and recordkeeping exemptions. If you ask us to delete payer-directed data, we route the request to the Payer as controller. We may retain records where retention is required by law or necessary to establish/exercise/defend legal claims or prevent fraud.
(7) Your Rights
EU / UK / Swiss (GDPR, UK GDPR, Swiss FADP).
You may request access, rectification, erasure, restriction, portability, and objection; where processing is based on consent, you may withdraw it; and you may lodge a complaint with your supervisory authority (in the UK, the ICO; in Switzerland, the FDPIC; in the EU, your national authority). Because SteadFile is usually a processor, requests about payer-directed data are routed to the Payer (the controller). For our limited independent-controller processing, contact us directly. Our EU/UK representative details appear in Section (10) once appointed.
US State Rights.
Residents of states with comprehensive privacy laws may have rights to: confirm/access, correct, delete, obtain a portable copy, opt out of sale/share/targeted advertising/certain profiling, and limit the use of sensitive personal information. SteadFile does not sell/share or conduct targeted advertising or profiling. We do not discriminate against you for exercising rights.
- Verification and routing. We verify requests using commercially reasonable methods. Where we act as service provider/processor, we route requests to the Payer and assist them.
- Timelines. GDPR/UK GDPR: within one month (extendable). US state laws: generally within 45 days, extendable by an additional 45 days; opt-out/limit requests are handled promptly.
- Appeals. If we (or the Payer) deny a state-law request, you may appeal; if an appeal is denied, you may contact your state Attorney General.
(8) International Transfers
SteadFile processes personal data in the United States. For transfers of EU/EEA, UK, and Swiss personal data to the US, we rely on the European Commission's Standard Contractual Clauses (Modules 2 and 3, 2021 version), the UK International Data Transfer Addendum to the EU SCCs, and the Swiss addendum. We do not currently rely on the EU-US Data Privacy Framework.
(9) Cookies and Essential Technology
The site uses only strictly necessary cookies/session storage required to log you in, keep your session, and secure the application. Under the EU/UK ePrivacy rules, strictly necessary technologies do not require consent. We do not use advertising or analytics trackers. If analytics or other non-essential technologies are added later, we will update this policy and, where required, present a consent mechanism before those technologies load.
(10) Children; Changes; Contact; Version
- Children. The service is not directed to children and is intended for adults completing tax forms. We do not knowingly collect personal information from children under 13 (COPPA) or otherwise process children's data.
- Changes. This policy is versioned. We will re-present material changes and update the version marker and effective date.
- Contact. privacy@steadfile.com; SteadFile LLC, c/o Northwest Registered Agent LLC, 5534 Saint Joe Road, Fort Wayne, IN 46835.
- Version: privacy v1.1. Effective date: 2026-09-26.
- EU / UK representative. To be appointed — name and address will appear here once an Article 27 representative is in place.