Privacy Policy
Last updated: 10 September 2026
USA eServices LLC, doing business as eFiling, is a private document-filing service and not a government agency. This policy sets out what we collect, why we collect it, who receives it, how long we keep it, and what you can ask us to do with it.
Who we are, and what this policy covers
USA eServices LLC, doing business as eFiling ("eFiling", "we", "us", "our"), is the company you contract with, the company that takes the payment, and the company this policy binds.
eFiling is a private document-filing service. We are not a government agency. We are not affiliated with, endorsed by, or sponsored by the Internal Revenue Service, FinCEN, any Secretary of State, or any other federal, state, or local government agency. We are not a law firm and we cannot give legal advice. Every state accepts formation documents from the public. If you file yourself you pay only the state's fee and nothing to us.
Our marketing site is efiling.us.com. Our customer portal is app.efiling.us.com. In this policy, "you" means the person using those sites or buying a service from us. Section 10 covers people who are named in a business-entity report and who are not our customers.
This policy covers the marketing site, the LLC application, the checkout, the customer portal, the business-name search, the business-entity reports, the contact form, Help and support, and the email we send. It does not cover the websites of the state agencies we file with, or any other site we link to. Those sites have their own policies.
Our Terms of Service are at efiling.us.com/terms and our Refund Policy is at efiling.us.com/refunds.
The short version
- We collect what a filing needs: the company name, the addresses, the people who will run the company, and how to reach you.
- We ask for a Social Security number in one case only: an LLC application where the state of formation is Colorado, the District of Columbia or Mississippi. We do not collect one for any other service we sell, including the federal tax identification number (EIN) service. It is encrypted, it is never shown back to you, and it is never used for marketing or advertising. Section 5 sets out the detail, including the uses we make of a number we already hold.
- Card numbers never reach our servers. The card is entered into the payment gateway's own form and swapped for a token before anything is sent to us.
- Every checkout stores the card at the gateway. There is no checkbox for this, in either direction — no box to tick and none to clear. Section 6 explains what the stored token is and what it is not.
- The application carries a box, selected by default, consenting to service-related text messages about your order. You can clear it before you submit, or ask us to clear it. We send no text messages today. Section 12.
- We do not sell personal information for money or for other valuable consideration. We do sell business-entity reports, which are compiled from public records and can name officers, directors and registered agents. Section 10 states our position on that and what a person named in a report can ask for.
- Our advertising and analytics tags do receive information about your visit, and the formation receipt page passes your email address to Google's conversion tag. Under California law and several other state laws that is probably "sharing" or "targeted advertising", and we treat it as such. Section 9 explains how to opt out, and what our opt-out does not yet do.
- You can ask us what we hold, ask us to correct it, and ask us to delete it. Section 16 explains how.
What we collect, and where it comes from
Every category below comes from you, or from a company acting for us to carry out something you asked for. We do not buy personal information about you, and we do not assemble profiles of you from outside sources. This section is about information about you as a customer or a visitor; section 10 covers the people named in a business-entity report.
Browsing the marketing site. Reading the public pages — the home page, pricing, the state pages, the landing pages, the reviews — writes nothing about you to our database. There is no account to create and no lead form to fill in. A language choice is stored in a cookie in your own browser. Analytics and advertising cookies are described in section 11. Every page also fetches its typefaces from Google's font service, which is described in section 8.
The business-name search, and the name check inside the application. When you search for a business name, we send the words you typed and the state you selected to our search partner, which answers with matching records. We do not keep the search itself; the answer is cached on our own server for one hour so that repeating a search does not repeat the request. Nothing identifying you goes with the query.
The same partner answers the live availability check inside the application, which runs as you type a company name.
Business-entity reports. If you join the waiting list for a report, we store your email address, the entity name and identifier, the state, the plan you chose, and the search that produced the match.
If you buy a report, we store the same fields plus the quantity, the amount, the order status, and — from the payment — the card brand, the last four digits, and the gateway's own transaction identifiers. Reports are produced and sent by a person here; the order details reach that person by email.
The LLC application.
- Business identity — the proposed company name, the state of formation, the package chosen, and the landing page the application started from.
- Business activity — the category and subcategory you select, your answers to the follow-up questions, and your description of the main service.
- Addresses — the business address, and the mailing address if it is different.
- Contact person — first, middle and last name, suffix, title, email address, telephone number.
- The people running the company — whether it is member-managed or manager-managed, and for each member or manager a name, or an organization name.
- Four questions — whether this is your first LLC, whether you will have employees, whether you have started doing business, and whether you will accept credit cards.
- Consents — the date and time you accepted the agreement, and whether the service-message box is selected.
- Government identifier — a Social Security number, in Colorado, the District of Columbia and Mississippi only. See section 5.
While the application is being typed. Your answers are saved in your own browser's local storage as you type, so that a reload or a closed tab does not lose them. That copy stays on your device and is cleared when you submit.
Once the email field contains something that looks like an email address, the partially completed form is also saved on our servers as a draft, so that you can come back to it from a link we send you, and once it also contains a name, an account is created for that address so that the application can be reached from the portal too. Before an email address is typed, no record exists on our side. The Social Security number and the agreement checkbox are excluded from both copies.
Drafts are what the follow-up emails described in section 12 are sent from.
The checkout. The billing address for the card, if it differs from the business address. What happens to the card itself is section 6.
The customer portal. An account is created when an order is placed, when you create a free account, or when an application carries your name and email address. The account holds your email address, your name, your initials, and how it came to exist. There is no password column, because we do not use passwords.
Alongside it we hold the businesses on your account (name, state, the federal tax identification number (EIN) once it is issued, formation and placement dates, the stage the formation has reached), the answers you give when asked what you want the LLC to do — which only change the order the offers appear in — the metadata of documents held for you (title, kind, page count, date received, and where it came from), compliance deadlines, and the notifications shown in the bell.
Ongoing services: annual compliance and monthly bookkeeping. We sell two services that continue after the formation: annual compliance, and monthly bookkeeping. What we hold for them today is the order itself — the service bought, the price, the billing dates, and the payment records in section 6. No financial records, no bank or accounting-platform connection, and no tax document is collected through this website or held in our database. Where the work needs records from you, a person here asks you for them and the exchange happens outside this service. If that changes, we will describe the new category here before we start collecting it.
Signing in. Sign-in codes are stored only as a bcrypt digest, never as the six digits, with the expiry time, the number of attempts, and the address the request came from.
A signed-in session record holds a token, the time it was last used, the IP address and the browser's user agent string. The address and user agent are refreshed at most once an hour.
A passkey record holds the credential identifier, the public key, the signature counter, whether the credential is backed up, the transports it reports, the nickname you give it, and when it was last used. Each account also has a 64-byte random handle, minted when the first passkey is registered. It is never your email address and never your account number, because an authenticator stores it in the clear on hardware we do not control.
The contact form. Your name, email address, telephone number, subject, the order number if you give one, and your message. Name, email address, telephone number, subject and message are required; the order number is optional.
Help and support. The subject, the topic, the status, a reference, the text of each message, and the business, filing or payment you attach to the request. A message cannot be edited after it is sent, by you or by us. Help and support asks for no contact details, because the signed-in account already identifies you.
Our logs. Our servers write ordinary application logs. Social Security numbers, sign-in codes, card fields, credentials, tokens, passwords, email addresses and the text of support messages are filtered out before a line is written.
The same categories, in the words the California law uses
- Identifiers — name, postal address, email address, telephone number, online identifiers, IP address, account identifiers.
- Customer records information (Cal. Civ. Code § 1798.80(e)) — name, address, telephone number, and limited financial information: the card brand, the last four digits, and the billing address.
- Commercial information — the products you ordered and considered, and the history of those orders, including any ongoing service and its billing dates.
- Internet or other electronic network activity information — pages viewed, referring page, and the interactions described in section 11.
- Sensitive personal information — a Social Security number, in the one case described in section 5. This is the only category of sensitive personal information we collect.
We do not collect precise geolocation, biometric information, racial or ethnic origin, religious beliefs, health information, or the contents of your mail or messages with anyone but us.
Payment information, and your card
Card numbers never reach our servers. The card number, the expiry date and the security code are typed into fields served by our payment gateway inside its own frames. The gateway returns a single-use token to your browser, and the token is what is sent to us. The number itself is never in our page, never in the request we receive, and never in our database.
What we do hold after a payment:
- The card brand and the last four digits, as the gateway reports them.
- The billing address you typed at the checkout, which is also sent to the gateway so that the bank can check it against the card.
- The gateway's transaction identifier and our own order reference.
- The amount, the itemized lines as they were at the moment of the charge, the status, and any decline code and message.
- A vault token: an identifier the gateway holds against your account so that a later charge can be made without the card being entered again.
Every checkout stores the card at the gateway. There is no checkbox for this, in either direction — no box to tick and none to clear. This is what allows the registered agent's first year to be charged when your order is placed with our filing partner, and what allows an extra bought from the portal to be one click. The vault token is an identifier only — it does not give us the card number, and it is useless outside our own gateway account.
In the rare case the gateway cannot store the card, the order is charged as a plain sale and no card is kept. When that happens, a later purchase asks for the card again.
Report purchases are charged as a single sale and the card is not stored.
How we use the information
- To carry out the filing you ordered — the company name, the addresses, the people running the company, your contact details, and the activity answers are used to prepare and place the filing.
- To check name availability — the name you type is sent to our search partner for that purpose only.
- To take payment — the token, the amount, the billing address and your email address are sent to the gateway to authorize the charge you made, and, later, the charges you authorized at the checkout.
- To run your account — the email address to sign you in, the session record to keep you signed in, the passkey to let you sign in without a code.
- To show you your filings — the business, document, deadline and notification records the portal displays.
- To answer you — the contact form and Help and support.
- To tell you what has happened to your order — the formation progress messages described in section 12.
- To offer you the other services we sell — after your first purchase, in the portal and by email. The answers you give about what you want the LLC to do change only the order those offers appear in.
- To measure the site and our advertising — see sections 9 and 11.
- To keep the service secure — rate limits, the address a sign-in code was requested from, and the signature checks on incoming webhooks.
- To meet our legal obligations and to establish, exercise or defend legal claims.
We do not use a Social Security number for any of these purposes except the first.
Who we give information to, and what each one receives
There are two lists here, and the difference matters. The companies in the first list work for us: we engage each of them to do a specific job, and we do not authorize any of them to use your information for their own purposes. The companies in the second list use information for their own purposes as well as ours, which is why section 9 treats what they receive as "sharing".
Service providers.
Our filing partner (Northwest Registered Agent, trading as Corporate Tools). The company name, the entity type and home state, the organizer's first and last name and email address, the principal address (used as both the principal and the mailing address), the management type, the officials, the contact person, the filer, and the registered-agent details. The telephone number is deliberately sent empty. No Social Security number is sent. They also send information back to us: document metadata, compliance events, and the status of each item on an order.
Government agencies. Through that partner, the state filing office receives the filing itself. Information in a state filing — the company name, the addresses, the names of officers, members and the registered agent — normally becomes a public record once it is filed. That is state law, not a choice we make, and it is why we cannot delete it later.
Our search partner (businessregistry.com). The words you typed and the state you chose, on every search and every live name check. Nothing identifying you is sent with them.
Our payment processor (Stripe; or Maverick, on the NMI platform, when it stands in for Stripe). The card itself, direct from your browser. From us: the amount, your email address, a description containing the company name, the billing name and address, our order reference, and the vault token.
Our email provider (Postmark). Every message we send: the recipient address, the subject and the body. That includes sign-in codes, which appear in the subject line as well as the body. Postmark also tells us whether a message was delivered, bounced, opened, or had a link in it followed, and when: an open is detected by a small image in the message that your mail client requests from Postmark, and a click by a link that passes through Postmark on its way to us, so those requests reach Postmark with your IP address and mail client. The sign-in code message carries neither.
Our object-storage provider (Amazon Web Services, S3). Configured for file uploads, and holding nothing today: no customer file is uploaded to it by any part of the service as it currently works.
Our hosting provider (Amazon Web Services). The server and the disk the database sits on. See section 18.
Third parties, which use information for their own purposes as well.
Google Tag Manager, and the analytics and advertising platforms it feeds. Page views across the marketing site and the portal, and the events listed in section 11. On the formation receipt page only, your email address is placed on the page for Google's conversion tag, which hashes it in the browser before sending it. See section 9.
Our product-analytics and error-tracking provider (PostHog), on its European cloud. Page views across the marketing site, the portal and our own admin console, and the events in section 11 — an application submitted, a payment taken or declined, an extra or a report bought, a sign-in and a sign-out — together with the errors the application reports. A signed-in account is identified to it by its account identifier together with the name and email address on the account and the names and states of the businesses it manages, so that we can find your session when you ask us for help. It is the one recipient in this list that is not a United States company; see section 18.
Google Fonts. Our pages load three typefaces from Google's font service. Every page you open on the marketing site, in the portal, and on the sign-in screens makes that request, and the request discloses your IP address and your browser's user agent to Google. It carries no name, no email address and no cookie of ours. We intend to serve those typefaces from our own server, which will remove the recipient; until we do, it is stated here rather than left out.
Others, in the circumstances named.
Professional advisers — lawyers, accountants and auditors, where they need it to advise us.
Law enforcement, regulators and courts, where we are required to respond, or where it is necessary to enforce our terms or protect somebody's rights, safety or property.
A buyer, if the business or its assets are sold, subject to this policy.
Our address-autocomplete code, which would send address keystrokes to Google Maps, is present in the site but switched off: no key is configured in production, so it does not run. If we turn it on, we will update this policy first.
Selling personal information, and sharing for advertising
We do not sell personal information for money or for other valuable consideration, with the one exception we describe below. No one pays us for information about our customers, and we do not trade or broker it.
The exception is the business-entity reports we sell. They are compiled from public records about companies, and they can name natural persons — officers, directors and registered agents, as those names appear in the state's own record. Our position is that information lawfully made available from government records is "publicly available" and outside the definition of personal information in Cal. Civ. Code § 1798.140(v)(2), so selling a report is not a sale of personal information. Not every state's law carries that exclusion in the same words. Section 10 says what we hold, where it comes from, and what a person named in a report can ask us for.
Advertising and analytics are a different matter. Our tag manager loads on the marketing site and across the portal, and it feeds analytics and advertising platforms. On the formation receipt page, your email address is passed to Google's conversion tag so that the purchase can be matched to the advertisement that produced it. Under the California Consumer Privacy Act, disclosures of that kind are likely to be "sharing" for cross-context behavioral advertising; under the Virginia, Colorado, Connecticut, Texas, Oregon, Montana and similar laws they are "targeted advertising". We treat them as such.
The categories involved are identifiers, internet or other electronic network activity information, and commercial information. Sensitive personal information is never shared for advertising, and neither are the contents of a support conversation, a document, or a filing.
To opt out, email support@efiling.us.com with the subject "Privacy Opt-Out", or write to the postal address at the foot of this page. If you are a Nevada resident, the same route serves the sale opt-out that Nev. Rev. Stat. § 603A.340 gives you. We act on an opt-out within 15 business days: we ask the advertising platforms to delete what they hold about you, and we stop using your information to target advertising to you.
What that opt-out does not yet do, stated plainly. There is no switch in our system that suppresses the tag manager or the receipt page's hand-off of your email address for a particular person. An opt-out is therefore carried out by a person here, through the platforms, and not by our own pages. Two things do work immediately and are in your hands: blocking cookies and scripts for our sites in your browser stops the tags loading at all, and a browser extension that blocks the tag manager has the same effect. We are building the switch, and this paragraph will say so when it exists.
Our site does not yet detect browser-based opt-out preference signals such as Global Privacy Control. Until it does, please use the route above.
We have no actual knowledge that we sell or share the personal information of anyone under 16.
People named in a business-entity report
A business-entity report is about a company, but a company's public record names people. A report can carry the officers and directors as filed, the registered agent, the filing history, and matters drawn from other public sources such as court, lien and trademark records. The names come from those records. They do not come from us, we do not add anything to them, and we do not compile a report about a natural person.
If you are named in a report we have sold and you want to know what it said about you, or you want us to stop including you, write to support@efiling.us.com with the subject "Privacy Request". Tell us the company and the name you are asking about. We will tell you what our record shows and, where the source allows it, stop returning it. What we cannot do is change the state's own record: that is held by the state, and it is corrected by filing with the state.
We hold no separate database of people. A report is assembled when it is ordered, from records held by our search partner and other public sources, and what remains on our servers afterwards is the order — who bought it, for which company, at what price.
Whether this activity makes us a data broker in a state that registers them is a question we are working through, and this section will name any registration we hold once that is settled.
Email, text messages, and marketing sequences
We send email through Postmark. Everything we send passes through them.
Messages about your order and your account.
- The sign-in code. The six digits appear in the subject line as well as the body, so treat that message as you would a key.
- Formation progress — received, in review, filed, approved. These are written deliberately thin: they name no business, no state and no price.
- Replies to a contact form message or a support request.
Messages carrying the detail of an order — what was bought, for whom, at what price — go to our own operations address, with you as the reply-to, because a person here has to act on the order.
Marketing sequences. We run email sequences to people who started an application and did not finish it, and to customers who may want the other services we sell. They are switched off as of the date at the top of this page, and when one is switched on it enrolls only people who apply or buy afterwards; nobody is enrolled retrospectively.
Every message in a sequence carries an unsubscribe link, a one-click unsubscribe header that your mail provider can use, and our postal address. You may also email support@efiling.us.com and ask to be removed. An unsubscribe is recorded against your email address, not your account, and it is checked before anybody is enrolled and again before each message is sent, so it stops a sequence already running. The unsubscribe link keeps working after the rest of the links in the message have expired.
We record, on our own servers, whether a message was sent, delivered, opened, or had its link followed, and when. Opens are detected by a small image in the message that your mail client requests from Postmark; clicks by a link that passes through Postmark on its way to us. Most mail clients now load such images on your behalf, so an "open" is a rough signal and we treat it as one. When a link is followed, the page it opens is tagged with the campaign and the step so that we can see in analytics whether the sequence produced an order; those tags are derived from the message we sent, never read from the address bar. The unsubscribe link carries no tags at all.
Text messages. The application carries a box, selected by default, consenting to service-related text messages about your order. You can clear it before you submit, or email support@efiling.us.com and we will clear it. We send no text messages: there is no messaging provider connected to this service. If that changes, we will tell you before the first one is sent.
Registered agent service, and the documents in your portal
Where you buy registered agent service, it is provided through our filing partner. Service of process, government mail and other official documents addressed to your company arrive with them.
Those documents appear in your portal. What is stored on our servers is the metadata — the title, the kind, the number of pages, the date it was received, where it came from, and the partner's identifier. The document itself is streamed from the partner at the moment you open it and is not stored on our disk.
Documents of this kind may contain personal information about you or about other people. We handle them only to provide the service.
How long we keep information
- Social Security number — until the filing that required it is complete, and in any event no later than 30 days after that filing is completed, refused without a further attempt, or abandoned — see section 5.
- Filing and payment records — 7 years from the filing or the payment, for tax and business record-keeping, and to resolve disputes.
- Business, document, deadline and notification records — for as long as the business is on your account, then with the filing records above.
- An application you started and did not finish — until you finish it, ask us to delete it, or 18 months pass, whichever is first.
- Business-entity report orders — with the payment records above; report waiting-list entries for 24 months.
- Contact form messages and support conversations — 3 years from the last message.
- Sessions and sign-in codes — a session stops working after 30 days without use, and signing out deletes it; a sign-in code lasts 10 minutes and is replaced when you ask for another; the single-use link that carries you from a completed order into your portal lasts 15 minutes; a link in a marketing sequence lasts as long as that campaign sets, 30 days in the ones we run.
- Passkeys — until you delete the credential, or until an anomaly in its signature counter causes us to retire it.
- Unsubscribe records — indefinitely; this is the record that stops us emailing you.
- Analytics and advertising records — these sit on the platforms themselves. We do not configure any of them to keep records about an individual for longer than 14 months.
Several of these are enforced by a person here rather than by an automatic process, including the deletion of an unfinished application and the erasure of a Social Security number. If you want something deleted sooner, ask us under section 16 and we will do it, unless we are required to keep it.
We cannot delete information that has already been filed with a state agency. Once a filing is made, the record belongs to that agency and is normally public.
How we protect information
What we do:
- Everything is served over TLS. The production site refuses plain HTTP.
- The Social Security number is encrypted at rest, with a key held outside the database, and non-deterministically, so identical numbers do not produce identical ciphertext. Other fields in the database are not individually encrypted; they are protected by the controls below and by the security of the server itself.
- There are no passwords. We store none, because we use none. Sign-in is a one-time code or a passkey.
- Anything credential-shaped is stored as a bcrypt digest and compared in constant time — sign-in codes, the single-use link from a completed order into your portal, and the tokens in marketing emails.
- Sessions live in the database and can be revoked. Signing out is a deletion, not just a cleared cookie.
- Passkeys are phishing-resistant. User verification is required in both directions, the credential is bound to the portal host so that it cannot be used from the marketing site, challenges are single-use, and anything the verification cannot check is refused.
- Sign-in does not reveal who has an account. A known and an unknown address get the same response.
- The portal is closed by default. Every portal screen requires a session, and a test asserts it for every route on the portal host. Every query for your records is scoped to your account, so somebody else's identifier returns nothing.
- Sensitive fields are filtered out of our logs — see section 3.
- Sign-in, registration, the contact form, support, drafts, report orders and the funnel are rate-limited.
- Incoming webhooks are authenticated, and an unverifiable delivery is rejected and never recorded.
No method of transmission or storage is completely secure, and we do not claim otherwise. If a breach affecting your personal information occurs, we will notify you and the regulators as the law requires.
Your rights, and how to use them
Depending on where you live, you may have the right to:
- Know and access what personal information we hold about you, where it came from, why we hold it, and who we have disclosed it to.
- Correct information that is wrong.
- Delete information, subject to what we must keep and to what is already a public filing.
- Receive a copy in a portable, machine-readable format.
- Opt out of sharing for cross-context behavioral advertising and of targeted advertising — see section 9 — and of profiling that produces legal or similarly significant effects. We do no such profiling.
- Limit the use of sensitive personal information. We use the one category we hold only for the filing it was collected for, so there is nothing further to switch off; see section 5.
- Not be discriminated against for exercising any of these rights.
- Appeal a decision, where your state's law provides for one.
Twenty states have comprehensive privacy laws in force today: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia.
We extend access, correction and deletion to every customer, wherever they live.
How to make a request. Email support@efiling.us.com with the subject "Privacy Request", or write to the postal address at the foot of this page. Tell us what you want done. There is no button in the portal for this; a person here handles each request.
How we verify you. We match the request against the email address on the account and the details of an order. For a deletion request, or a request about a Social Security number, we may ask you to confirm from the address on the account before we act.
How long we take. We confirm that we have received a request within 10 business days and tell you how we will handle it. We answer within 45 days. If a request is complex we may take a further 45 days, and we will tell you before the first period is up if we need to. An opt-out under section 9 is acted on within 15 business days.
Authorized agents. Somebody may make a request for you if they give us written authorization signed by you. We may still contact you to confirm that you gave it, and to confirm your identity directly.
Appeals. If we refuse a request, reply to our decision with the subject "Privacy Appeal". A different person will look at it and answer within 45 days, with the reasons. If you disagree with the outcome, you may complain to your state's Attorney General, or, in California, to the California Privacy Protection Agency.
Non-discrimination. We will not deny you a service, charge you a different price, or give you a lower standard of service because you exercised a privacy right. We run no loyalty program and no discount conditioned on giving us personal information.
Children
This service is for adults forming a business. We do not knowingly collect personal information from anyone under 18. Two lower thresholds appear in law and we state our position on both: we collect nothing from a child under 13, and we have no actual knowledge that we sell or share the personal information of anyone under 16. We do not ask for an age or a date of birth anywhere, and there is no field in our records for one.
If you believe someone under 18 has given us personal information, email support@efiling.us.com and we will delete it.
Where your information is kept
The service is offered in the United States, for filings made with United States state agencies, and we do not offer it elsewhere.
Our servers are in the United States. The application server and the disk holding the database run on Amazon Web Services in Northern Virginia, and the object storage configured for file uploads is in the same region. Your information — including the encrypted Social Security number — rests there.
Our filing partner, our payment gateway, our search partner, our email provider and our analytics and advertising platforms are United States companies and process the information described in section 8 in the United States and wherever else they operate.
One recipient is not. Our product-analytics and error-tracking provider (PostHog) runs on its European cloud, so the page views, events and error reports described in section 8 are processed in the European Union. That is a transfer out of the United States of the information named there, and of nothing else: your filing, your documents, your payments and the encrypted Social Security number stay on the servers described above.
The state privacy laws in section 16 and the state breach-notification laws in section 15 apply to us wherever the servers are. If we move the service outside the United States, we will update this section before the move.
Changes to this policy
We may update this policy. When we do, we post the new version here with a new "Last updated" date, and we review the policy at least once every 12 months.
If a change is material — a new category of information, a new purpose, or a new kind of recipient — we will tell you by email or by a notice on the site before it takes effect.
The Social Security number
When we ask. In the LLC application, and only when the state of formation is Colorado, the District of Columbia or Mississippi, whose own filing processes ask for the responsible party's Social Security number to verify the filing account. In every other state the field is not shown and the number is not collected.
The federal tax identification number (EIN) service. The Internal Revenue Service asks for the responsible party's Social Security number or ITIN on Form SS-4. Our application does not collect that number for this service, and no part of this service transmits one for that purpose. If that ever changes, we will say so in this policy before we start holding it. There is no third case.
What the field itself says. Where the field is shown, the application says beside it why the state's process asks for the number, that it is encrypted, and that it is not part of the public LLC filing.
What we do with it. The filing it was collected for. We also make two further uses of the number we already hold: to verify that the person applying is who they say they are, and to tell whether you have a Social Security number or will need an ITIN instead. Neither of those widens what we collect, and neither sends the number anywhere: the recipients are still the ones named below. It is not used for marketing, for advertising, for profiling, for scoring, or to identify you anywhere else in the service. It is never sold and never shared for advertising.
How it is stored. Encrypted at rest in our database with a key that is not kept in the database, and encrypted non-deterministically — two identical numbers produce different ciphertext, so the column cannot be searched or compared, by us or by anyone reading the file. It is not written to our logs. It is not saved into your browser's local storage and it is not part of the draft that autosaves to our servers.
It is never displayed back. No screen in the portal, no receipt, no email and no screen in our own admin console shows the number once it has been entered. The only place it is ever visible is the field you typed it into.
Who else receives it. The state filing office whose own process requires it, as part of the filing it was collected for, and no one else. It is not sent to our filing partner, our payment gateway, our email provider, our search partner, or any analytics or advertising platform.
How long we keep it. Only until the filing that required it is complete, and in any event no later than 30 days after that filing is completed, refused without a further attempt, or abandoned. We erase it from the record at that point, and there is no second copy to erase. Erasure is carried out by a member of our team rather than by an automatic process.
Your rights over it. California treats a Social Security number as sensitive personal information, and Connecticut will do the same from 1 July 2026. Because we use it only for the filing you asked us to make and for the record-keeping the law requires, there is nothing further for a request to limit the use of sensitive personal information to switch off. You may ask us to delete it under section 16, and we will, subject only to a filing already in progress.
Connecticut law will require your consent before that number is processed. The application does not ask for that consent as a separate step today. If you are in Connecticut and would rather we did not hold the number, do not enter it: tell us instead. The three states above will not accept the filing without it, so the filing cannot be made, and the Refund Policy says what happens to what you paid.
Refund Policy