Privacy
Privacy notice
- Last updated
- Aug 26, 2026
- Clauses
- 11
- 01
What WithholdWatch deliberately does not collect
WithholdWatch does not store a full taxpayer identification number. Not encrypted, not masked, not briefly. There is no field anywhere in the product that accepts one: the W-9 screen takes exactly four digits and rejects anything else with that reason, and a CSV row containing what looks like a complete number is refused at the validation preview before anything is written. It is not truncated and stored — the row is skipped and you are told which one.
The database reserves a column for a future encrypted value. The application never writes it, and the signed-in database role is not granted permission to read it, so it cannot be reached through the API even by a member of your own workspace.
The consequence is that WithholdWatch cannot file a return for you and cannot verify a W-9 against the IRS, because both need the number it refuses to hold. That is the trade, made deliberately.
- 02
What WithholdWatch does collect
Three kinds of data, and no more:
- Account data: your email address, and the sign-in identifiers issued by the authentication provider. WithholdWatch does not store passwords.
- Workspace data: the contractors you record — legal name, any trading name, email address, tax classification, W-9 status and dates, the last four digits of a taxpayer number if you enter them — and the payments you record against them: date, amount, method and any memo you write.
- Operational data: an activity log of who in your workspace changed what and when, and standard server logs. Import batches are retained so that an import can be reverted.
- 03
Why it is collected
To compute the figures that are the entire product: which contractors have crossed a reporting threshold, on which payment, and what backup withholding was already required on payments made to them. Nothing is collected because it might be useful later.
Contractor email addresses are collected so you can request a W-9. WithholdWatch does not send marketing to them and does not use them for anything else.
- 04
Who can see it
The members of your workspace, and no one else’s. Isolation is enforced by the database on every query, not by application code that has to remember to filter — a query that forgets its workspace filter returns nothing rather than everything.
The two reference tables WithholdWatch reads — published thresholds and published rates — contain no customer data and are deliberately readable by anonymous visitors, so that the public exposure calculator runs against the same figures the product uses rather than a copy.
Operators of the service can access data where necessary to run it or to investigate a fault you report. There is no routine access, and no access at all to full taxpayer numbers, because none are stored.
One thing is visible without signing in, and it is stated here rather than left to be discovered: an outstanding invitation link is itself the credential. Whoever holds it — including anyone the invitation email was forwarded to — can open the invite page and see the invited person’s email address, the name of the workspace they were invited to and the role they were offered. That is what lets somebody with no account yet see what they are being asked to join. The link carries 32 random bytes, so it cannot be guessed, but it travels through mail servers and browser history like any other URL. Accepting the invitation, revoking it, or letting it expire closes that view: after any of those the page will no longer name the workspace or the person.
- 05
Processors
WithholdWatch relies on a small number of services, each for one job:
- Database, authentication and hosting: your workspace data and account data are stored and served here.
- Stripe, for subscription billing. Card details are entered on Stripe’s own hosted checkout page and are never posted to WithholdWatch, so there is no card data in this product at all.
- Transactional email, for sign-in links and W-9 requests.
- Aggregate, non-identifying page analytics for the public pages of this website.
- 06
How long it is kept
Workspace data is kept for as long as the workspace exists. Deleting your workspace deletes its contractors, payments, import batches and activity log; WithholdWatch does not keep a shadow copy for its own purposes.
Cancelling a paid plan does not delete anything. The workspace continues on the Free plan within its caps.
- 07
Getting your data out
Four CSV exports are available on every plan, including the free one: a 1099-NEC worksheet, a W-9 gap list, the payment ledger and the exposure detail. Between them they contain everything you put in. Export does not require a subscription and is not rate-limited.
- 08
Contractors are people too
The contractors in your workspace did not sign up for WithholdWatch; you entered them. You are responsible for having a lawful basis for holding their details, and for responding if one of them asks you what you hold. WithholdWatch stores no more about them than the fields listed above, which is deliberately less than an accounting system holds.
- 10
Security, and what has not been done
The security page sets out the specific measures — per-workspace isolation enforced in the database, policies split by verb and never granted to the public role, and views that run as the caller rather than their owner.
It also states what has not been done: there is no third-party audit, no SOC 2 report and no penetration test. That is repeated here so that this notice cannot be read as implying otherwise.
- 11
Data controller and jurisdiction
A privacy notice should name the entity responsible for your data and the jurisdiction whose rules apply. WithholdWatch has not yet named a legal operating entity, and printing a placeholder here would be worse than saying so.
Outstanding
The controlling entity, its address and the applicable jurisdiction will be named here before WithholdWatch accepts a payment. Until then, no paid plan is sold and every other statement above describes what the product actually does.