Privacy policy
This policy explains what WagePilot collects, why it is used, who receives it, and the choices available when you use our website and certified-payroll review service.
Effective and last updated August 26, 20261. Scope and responsibility
This policy applies to WagePilot’s website, diagnostic, account workspace, and related communications. WagePilot determines how account and website data is used. When a business uploads payroll information, that business remains responsible for having authority to provide and process it.
2. Information we collect
- Account information: work email, authentication state, project names, and subscription status.
- Payroll and project information: uploaded payroll or WH-347 content, jurisdiction, wage-determination rows, worker names, classifications, hours, rates, findings, evidence, and review decisions.
- Payment information: Stripe processes checkout and payment details. WagePilot stores Stripe customer, subscription, checkout identifiers, plan, and status—not full card numbers.
- Website and campaign information: page paths, campaign parameters, product-funnel events, device/browser data, and advertising attribution only according to your consent choices.
- Support information: information you send when requesting help, exercising a privacy right, or responding to a WagePilot communication.
3. How uploads are handled
CSV and XLSX files are parsed in API memory. PDFs are sent to OpenAI for structured extraction with response storage disabled; the temporary OpenAI file is deleted after processing. WagePilot does not intentionally retain the original uploaded file in this MVP. If you choose to save a review, WagePilot stores the structured project, worker, wage-rule, finding, and decision data needed for project history.
4. Why we use information
We use information to provide and secure the service, perform requested payroll checks, maintain project history, authenticate users, process subscriptions, respond to support, prevent abuse, troubleshoot, comply with law, and—with consent—measure website performance and paid-search effectiveness.
5. Service providers and disclosures
Information may be processed by infrastructure and database hosts, OpenAI for PDF extraction and contextual review, Stripe for billing, an email-delivery provider for sign-in codes, and Google for analytics or advertising when you consent. We may also disclose information to comply with law, protect users or the service, or as part of a corporate transaction. WagePilot does not sell payroll records or use them for shared-model training.
6. Cookies and measurement choices
Necessary storage supports authentication, security, and remembering your privacy preference. Analytics and advertising tags remain blocked until you choose those categories. You can reject optional storage or change your selection at any time using Cookie settings in the footer. See the Cookie policy for details.
7. Retention and deletion
Original uploads are not intentionally retained after processing. Saved structured records remain while the account or project is active and as reasonably needed for the service, security, dispute resolution, and legal obligations. Authentication codes expire after 10 minutes; sessions expire after 30 days. Consent choices are retained for up to 180 days. During the MVP, deletion and access requests are handled through the contact below.
8. Security
WagePilot uses scoped account queries, hashed session tokens, HTTP-only cookies, upload limits, API throttling, and encrypted transport in production. No system is completely secure. Do not upload payroll data unless you are authorized to do so, and remove unnecessary sensitive fields where possible.
9. Your choices and rights
Depending on where you live, you may request access, correction, deletion, portability, restriction, or information about disclosures; withdraw consent; or object to certain processing. You may also opt out of advertising measurement through Cookie settings. We may need to verify your identity and authority before completing a request. You may appeal a denied request by replying to our decision.
10. International use and children
WagePilot is intended for United States business users and may process information in the United States and other locations used by our providers. It is not intended for children under 18.
11. Changes and contact
We will update the date above when this policy changes and provide additional notice for material changes where required. Privacy questions and requests can be sent to privacy@wagepilot.ai.
