Effective August 28, 2026

Privacy Notice

This notice describes how WageComply handles information for the federal certified-payroll service. It is written to match the product’s current data flows rather than future integrations.

Information we process

WageComply processes organization and account information, project and contract facts, worker identifiers and limited worker contact/basic-record information, payroll facts, wage-determination evidence, report artifacts, submission evidence, support requests and operational security metadata needed to provide the service.

Sensitive payroll information

Federal V1 does not require or store a worker's full Social Security number in the WageComply payroll workflow. The product uses a contractor-controlled worker identifying number and may store only the last four SSN digits when a customer chooses to retain them. Customers remain responsible for source records that WageComply references but does not hold.

How information is used

  • Provide tenant-isolated payroll, compliance-review, WH-347, certification, submission and audit-defense workflows.
  • Authenticate users and enforce organization permissions.
  • Process subscription billing and account lifecycle events.
  • Deliver transactional email and verified deadline notifications.
  • Detect abuse, troubleshoot failures and protect the service using minimized operational metadata.

AI boundary

Gemini may be used only to suggest mappings for spreadsheet column headers. It is not authorized to select wage determinations or classifications, calculate payroll, decide compliance, certify reports, or receive authority over certified records. Deterministic validation remains the authoritative path.

Service providers

WageComply currently relies on infrastructure and service providers listed on the Subprocessors page. Payment-card processing is handled through Paddle; WageComply does not need to store raw card numbers.

Retention

Payroll and supporting records may be preserved to satisfy configured federal record-retention and legal-hold requirements. Certified records are immutable in normal application workflows and corrections are retained as amendments rather than silently overwriting originals.

Security and access

Customer data is scoped by organization, protected with PostgreSQL row-level security and private object storage, and exposed through authenticated or short-lived authorized access paths. Operational logs are designed not to contain payroll facts, OTPs, secrets or provider payloads.

Requests and contact

Signed-in customers can use Settings → Support for account, privacy or security requests. Other requesters can use the public paths listed on the Contact page. We may need to verify identity and authority before disclosing, correcting or deleting organization-linked records, and applicable payroll-retention or legal-hold duties may limit deletion.