The privacy of your data — and it is your data, not ours! — is a big deal to us. In this policy, we lay out: what data we collect and why; how your data is handled; and your rights to your data. We promise we never sell your data: never have, never will.
This policy applies to all products built and maintained by W9Vault, including the secure W-9 collection platform and any future services.
What We Collect and Why
Our guiding principle is to collect only what we need. Here's what that means in practice:
Identity & Access
When you sign up for W9Vault, we ask for identifying information such as your name, email address, and company name. That's just so you can personalize your new account, and we can send you invoices, updates, or other essential information. We'll never sell your personal info to third parties, and we won't use your name or company in marketing statements without your permission either.
Billing Information
When you pay for W9Vault, we ask for your credit card and billing address. That's so we can charge you for service, calculate taxes due, and send you invoices. Your credit card is passed directly to our payment processor Stripe, and doesn't ever go through our servers. We store a record of the payment transaction, including the last 4 digits of the credit card number and billing address, for account history, invoicing, and billing support. We store your billing address to calculate any sales tax due in the United States, to detect fraudulent credit card transactions, and to print on your invoices.
Document Upload Information
When you create W-9 requests, we collect:
- Vendor contact details you provide (name, email, company)
- Document types requested (W-9, W-8BEN, invoice, etc.)
- Request metadata (creation date, expiration, status)
- Uploaded document files (encrypted client-side before reaching our servers)
Geolocation Data
We log all access to all accounts by full IP address so that we can always verify no unauthorized access has happened. We keep this login data for as long as your product account is active. We also log full IP addresses used to sign up a product account. We keep this record for our security monitoring because they help us mitigate spammy signups. Web analytics data are also tied temporarily to IP addresses to assist with troubleshooting cases. We anonymize all web analytics data after 30 days.
Website Interactions
When you browse our marketing pages or applications, your browser automatically shares certain information such as which operating system and browser version you are using. We track that information, along with the pages you are visiting, page load timing, and which website referred you for statistical purposes like conversion rates and to test new designs. We sometimes track specific link clicks to help inform design decisions. These web analytics data are tied to your IP address and user account if applicable. We anonymize all of these individual identifiers after 30 days.
Anti-Bot Assessments
We use security measures across our applications to mitigate brute force logins and spam protection. We have a legitimate interest in protecting our apps and the broader Internet community from credential stuffing attacks and spam. When you log into your accounts, our security systems evaluate various information (e.g., IP address, how long the visitor has been on the app, request patterns) to check whether the data is possibly filled out by an automated program instead of a human.
Voluntary Correspondence
When you write W9Vault with a question or to ask for help, we keep that correspondence, including the email address, so that we have a history of past correspondences to reference if you reach out in the future. We also store any information you volunteer like surveys or feedback.
Information We Do Not Collect
We don't collect any characteristics of protected classifications including age, race, gender, religion, sexual orientation, gender identity, gender expression, or physical and mental abilities or disabilities. You may provide these data voluntarily, such as if you include a pronoun preference in your email signature when writing to our Support team.
We also do not collect any biometric data. Our zero-knowledge encryption means we cannot read the contents of uploaded documents — they are encrypted in the vendor's browser before upload.
When We Access or Share Your Information
Our default practice is to not access your information. The only times we'll ever access or share your info are:
To Provide Services You've Requested
We do use some third-party services to run our applications and only to the extent necessary process some or all of your personal information via these third parties:
- Supabase: Database, authentication, and file storage
- Stripe: Payment processing (PCI DSS compliant)
- Resend: Email delivery services
- Vercel: Hosting and content delivery
- Sentry: Error tracking and performance monitoring (with data scrubbing)
Having sub-processors means we are using technology to access your data. No W9Vault human looks at your data for these purposes unless an error occurs that stops an automated process from working and requires manual intervention to fix. These are rare cases and when they happen, we look for root cause solutions as much as possible to avoid them from reoccurring.
To Help You Troubleshoot or Squash a Software Bug, With Your Permission
If at any point we need to access your account to help you with a Support case, we will ask for your consent before proceeding.
To Investigate, Prevent, or Take Action Regarding Restricted Uses
Accessing a customer's account when investigating potential abuse is a measure of last resort. We have an obligation to protect the privacy and safety of both our customers and the people reporting issues to us. We do our best to balance those responsibilities throughout the process. If we do discover you are using our products for a restricted purpose, we will report the incident to the appropriate authorities.
When Required Under Applicable Law
W9Vault is a US company and all data infrastructure is located in the US.
If US law enforcement authorities have the necessary warrant, criminal subpoena, or court order requiring we share data, we have to comply. Otherwise, we flat-out reject requests from local and federal law enforcement when they seek data. Unless we're legally prevented from doing so, we'll always inform you when such requests are made.
If W9Vault receives a request to preserve data, we refuse unless compelled by either the US Federal Stored Communications Act or a properly served US subpoena for civil matters. In these situations, we notify affected customers as soon as possible unless we are legally prohibited from doing so.
If we get an informal request from any person, organization, or entity, we do not assist.
If we are audited by a tax authority, we may be required to share billing-related information. If that happens, we only share the bare minimum needed such as billing addresses and tax exemption information.
Finally, if W9Vault is acquired by or merged with another company — we don't plan on that, but if it happens — we'll notify you well before any info about you is transferred and becomes subject to a different privacy policy.
How We Secure Your Data
All data is encrypted via TLS when transmitted from our servers to your browser. The database backups are also encrypted.
Client-Side Encryption
We've gone even further by implementing zero-knowledge encryption. Every uploaded document is encrypted in the vendor's browser using TweetNaCl XSalsa20-Poly1305 encryption before it ever reaches our servers. Each file has its own unique encryption key generated with cryptographically secure random number generators. This means we literally cannot read the contents of uploaded files — they are meaningless encrypted data to us.
Database Security
Every field containing personal data is encrypted with its own key. The disks storing the data keys are encrypted as well. Our servers decrypt the data to send it to you when you need it.
Automatic Deletion
All uploaded documents are automatically deleted after 30 days. There's no option to extend this period — it's by design for your privacy protection.
What Happens When You Delete Data
In W9Vault, we give you the option to delete data. Anything deleted in your product accounts while they are active will be kept in an accessible trash for up to 30 days. After that, the deleted data are no longer accessible via the application and are deleted from our active servers within the next 30 days. We also have some backups of our application databases, which are kept for up to another 30 days. In total, when you delete things in our applications, they are purged within 90 days from all of our systems and logs.
We also delete your data after an account is cancelled. In this case, there is no period of data being kept in an accessible trash so your data are purged within 60 days. This applies both for cases when an account owner directly cancels and for auto-cancelled accounts.
Automatic Document Deletion: Remember, all uploaded documents are automatically deleted after 30 days regardless of your account status. This is a core security feature of our platform.
Your Rights With Respect to Your Information
At W9Vault, we apply the same data rights to all customers, regardless of their location. We recognize all of the rights granted in privacy regulations like GDPR and CCPA. These rights include:
- Right to Know: What personal information is collected, used, shared or sold
- Right of Access: Access the personal information we gather about you
- Right to Correction: Request correction of your personal information
- Right to Erasure: Request that your personal information be erased from our possession
- Right to Restrict Processing: Request restriction of how and why your personal information is used
- Right to Object: Object to how or why your personal information is processed
- Right to Portability: Receive your personal information and transmit it to another party
- Right to Non-Discrimination: We won't charge you differently or provide different service levels because you exercised your privacy rights
Many of these rights can be exercised by signing in and directly updating your account information. If you have questions about exercising these rights or need assistance, please contact us at privacy@w9vault.com.
Location of Site and Data
Our products and other web properties are operated in the United States. If you are located in the European Union or elsewhere outside of the United States, please be aware that any information you provide to us will be transferred to and stored in the United States. By using our Site, participating in any of our services and/or providing us with your information, you consent to this transfer.
Changes & Questions
We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change to our policies, we will also send an email to all of our subscribers. If you have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information, please get in touch by emailing us at privacy@w9vault.com and we'll be happy to answer them!