Privacy Policy
Last updated: March 2026
1. Information We Collect
We collect the following categories of information:
- Account information: Email address, full name, and organization details provided during registration.
- Employee data: First name, last name, last four digits of SSN, job classification (TTOC code), hourly rate, and filing status. We never collect or store full Social Security Numbers.
- Financial data: Tip amounts, overtime hours, and related compensation data entered by you.
- Usage data: Pages visited, features used, and general interaction patterns to improve the Service.
- Payment information: When paid plans are activated, payment data will be processed securely by our third-party payment processor. We do not store credit card numbers on our servers.
2. How We Use Your Information
- Provide, maintain, and improve the Service.
- Calculate FLSA overtime premiums, track OBBBA deduction caps, and generate W-2 export files.
- Send transactional emails (welcome, weekly reminders, cap alerts, billing notifications).
- Process payments and manage subscriptions.
- Respond to support requests and communicate Service updates.
3. Third-Party Services
We use the following third-party services to operate TipFort:
- Supabase: Database hosting and user authentication. Data is stored in Supabase's cloud infrastructure with row-level security.
- Stripe: Payment processing (when paid plans are activated). Stripe handles all payment information per PCI DSS standards.
- Brevo (Sendinblue): Transactional email delivery (welcome emails, reminders, cap alerts).
- Vercel: Application hosting and deployment.
- Microsoft Clarity: Product analytics and session replay. Clarity captures aggregated usage metrics, heatmaps, and anonymized session recordings to help us understand how the Service is used and improve it. Microsoft may use this data in accordance with its own privacy practices. See the Microsoft Privacy Statement. Clarity only loads after you accept analytics cookies.
- Google Analytics: Aggregated website traffic and usage analytics. Loads only after you accept analytics cookies.
4. Data Security
We implement industry-standard security measures including encrypted connections (TLS), row-level security in our database, and scoped access controls. All data is isolated per organization; no organization can access another's data.
5. Data Retention
Your data is retained as long as your account is active. If you cancel your subscription, your data remains accessible in read-only mode. If you request account deletion, all your data will be permanently removed within 30 days.
6. Your Rights
You have the right to:
- Access and export your data at any time through the Service.
- Correct inaccurate information through the Settings or employee management pages.
- Request deletion of your account and all associated data.
- Opt out of non-essential communications.
7. Cookies
We use the following types of cookies:
- Authentication cookies: Session tokens that keep you logged in. These are strictly necessary for the Service to function and cannot be disabled.
- Security cookies: Used to prevent cross-site request forgery and protect your account.
- Analytics cookies: Set by Microsoft Clarity and Google Analytics to measure usage and improve the Service. These are optional and only set after you give consent via the cookie banner.
We do not use advertising cookies or cross-site tracking cookies for marketing. Analytics cookies are loaded only with your consent; you can decline them through the cookie consent banner without affecting your ability to use the Service. Strictly necessary authentication and security cookies cannot be disabled.
8. Children's Privacy
The Service is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact
For privacy-related inquiries, contact us at privacy@tipfort.com.
Related Policies
Use these pages to review billing terms, refund timing, and support contacts alongside our privacy commitments.