Skip to content

Privacy Policy

Effective October 1, 2026 · See also the Security page

1. Who this covers

This policy covers our customers (firms, their team members, and API developers); the owner of each firm, who completes an identity check before the firm files; contractors and other payees who complete a Form W-9, or answer a request to receive their tax forms electronically, through a link a firm sends them; and visitors to this site.

For payer and payee data a firm enters or collects through the service, the firm is the payer or the payer's filing agent, and we process that data on the firm's behalf to provide the service.

2. What we collect

Account data: firm name, user names and emails, roles, authentication data (password hashes, MFA enrollment), and billing records.

The owner identity check: before a firm files, its owner verifies their identity with Stripe Identity, which reads an image of a government-issued photo ID and a selfie taken on the owner's own device. We receive the result, the legal name on the document and the date of birth (stored encrypted). We never receive or hold the document images or the selfie; Stripe holds those.

Payer and form data entered by your firm or your software: each payer's identity details (including its taxpayer identification number), the amounts and withholding on each form, uploaded documents such as W-9 scans, and filing results. This is the working data of information-return filing. We collect it solely to provide the service.

Payee and recipient data: when a contractor completes a Form W-9 through a firm's link, their name, taxpayer identification number, address, tax classification and electronic signature. When a recipient consents to, or withdraws consent to, receiving their forms electronically, the choice, the email address, the version of the disclosures they were shown, and when.

Waitlist: if you join the waitlist on this site, your email address, the page you joined from, and when you confirmed or unsubscribed. We use it only to send the notes you asked for.

Usage and technical data: API request logs, product events, and device and browser information used for security, debugging, and usage counts. Taxpayer identification numbers are kept out of our application logs by design, and as a second safeguard, text shaped like an SSN, ITIN, EIN or email address is scrubbed from the records we retain.

3. How we use it

To provide the service: validation, transmission to the IRS at your direction, status tracking, webhooks, and support. We never transmit to a state tax agency. Where you turn on Combined Federal/State filing for a payer, the IRS forwards that payer's records to the participating states; state upload files we prepare are yours to file.

To operate the business: billing through our payment processor, verifying the identity of each firm's owner, fraud and abuse prevention, and service communications.

We do not sell personal information, and we do not use taxpayer return information for advertising.

4. Tax return information and IRC section 7216

Section 7216 of the Internal Revenue Code restricts how a tax return preparer may use and disclose tax return information. On this platform your firm is the preparer. We process tax return information only on your firm's behalf, to provide the service your firm has engaged us for, and under the consents your firm obtains from its clients. We do not use or disclose tax return information for any other purpose.

When return information reaches one of the providers listed in section 5, it is only so that provider can perform its part of the service for your firm, under a contract that limits it to that purpose.

5. Who we share it with

The IRS, when you submit a filing; that is the product. The IRS may forward a state's copy of an information return when you turn on Combined Federal/State filing for a payer. State files you download are sent to the state by you.

The providers who help us run the service, each under contract and each limited to its part of the service: Microsoft Azure, in its Central US region, which hosts the service, its database, its encryption keys and its document storage; Stripe, for billing, which never receives return data; Stripe Identity, for the owner identity check described in section 2; and Resend, for the emails we send, whose messages by design carry no return data in their bodies.

From January 2027, a print and mail vendor will receive the recipient copies a firm asks us to print and mail. We will name that vendor on this page before it is first used.

Legal process, when required. We will notify affected customers where the law allows.

6. Cookies and site visits

We set only the cookies the service needs to work: sign-in session cookies and a token that protects your account against cross-site request forgery. We set no advertising or analytics cookies and load no third-party trackers. We count page visits without cookies or third parties.

7. How it's protected

Every taxpayer identifier we store is encrypted at rest with AES-256-GCM, as are MFA secrets and webhook secrets; transport is TLS; API keys are stored only as hashes; tenants are strictly isolated; and access is role-gated with MFA available on every account. Our security program is aligned to IRS Publication 4557 and the FTC Safeguards Rule and is set out in a written information security program, which a firm can ask us for. The service and the data it holds are hosted in the United States, on Microsoft Azure's Central US region. Details are on the Security page.

If we confirm a breach of data we hold for your firm, we notify your firm within 72 hours of confirming it and work with you to notify your affected clients as the law requires. As an e-file provider we also notify the IRS within 24 hours of confirming a breach of taxpayer data, and we report to the FTC as the Safeguards Rule requires.

8. Retention and deletion

Documents your firm uploads are kept for the period your firm sets, from 3 to 25 years (7 unless your firm changes it), and deleted after that. We retain account and filing data while your account is active and as required for legal, tax, and audit obligations.

Firms can erase payer and recipient records in-product; recipients may direct erasure requests through the firm or to us, and we honor them subject to those legal retention requirements.

9. Your choices and rights

You can access your data in-product, correct account information, download the recipient copy of any form as a PDF, and cancel at any time. Ask us for a bulk export of your payers, recipients and filing history and we will provide it. Depending on where you live, you may have additional rights (access, deletion, correction, portability). Contact us and we will honor them consistent with the legal retention rules above.

10. Contact and changes

Privacy questions and requests: privacy@simplifygigtax.com. Security reports: security@simplifygigtax.com. We will post changes to this policy here, including any change to the providers in section 5, and notify you of material changes in the product or by email.