RightStart LLC, doing business as WageProof, (“we,” “us,” or “our”) operates the S-Corp Reasonable Compensation tool at www.wageproof.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, how we protect it, and what rights you have.
We do not sell your data, and we never share your report inputs or compensation calculations for marketing. We do use Google Ads, Reddit Ads, Meta (Facebook/Instagram) Ads, ChatGPT Ads (OpenAI), Microsoft Advertising (Bing), and LinkedIn Ads to measure which of our ads lead to sign-ups and purchases, and we use Google, Reddit, Meta, and LinkedIn to show our ads to past visitors as they browse other sites or use Reddit, Facebook, Instagram, or LinkedIn (remarketing) — see “Advertising, conversion measurement, and remarketing” in Section 3 for what that involves and how to opt out. We also record, in a first-party cookie tied to your account, how you first arrived at WageProof (for example a campaign link or the referring site) so we can understand which channels work — this is not shared with advertisers and is not tied to your report content (see “Marketing attribution” in Section 1). Separately, using a different random first-party identifier, we record which steps of our site you reach — landing, viewing pricing, starting the report wizard, creating an account, completing a purchase — so we can find and fix drop-off; this funnel record is stored only in our own database, is not tied to your identity until you create an account, and is not shared with advertisers (see “Site funnel measurement” in Section 1). We collect only what we need to generate your report, operate the Service, and run our advertising. We honor browser opt-out signals such as Global Privacy Control (GPC) — see “Your Privacy Choices” in Section 9.
1. Information we collect
Account information
When you create an account, we collect your name and email address through our authentication provider, Clerk. If you sign in via a third-party provider (such as Google), Clerk receives the profile information you authorize.
Google Sign-In data
If you sign in with Google, we receive the following data from your Google account through our authentication provider (Clerk):
- Name — your Google profile display name
- Email address — the email associated with your Google account
- Profile photo URL — used for your account avatar
How we use Google data: We use your name and email solely to create and maintain your WageProof account, identify you when you sign in, and associate your reports with your account. We do not use Google data for advertising, marketing, or profiling.
How we store and protect Google data: Your Google account information is stored by our authentication provider, Clerk, which uses encrypted storage and secure session management. Your email is also stored in our database (hosted on Neon, a SOC 2-compliant PostgreSQL provider) to link your reports to your account. All data is encrypted in transit via TLS.
How we share Google data: We do not share your Google user data with any third parties for marketing, advertising, or any purpose unrelated to providing the Service. Google data is shared only with Clerk (for authentication) and stored in our database (for account association). We do not share it with Stripe or use it for advertising or profiling. One narrow exception applies to your email address: if you make a purchase while signed in, we send Google a one-way hash of your account email for purchase-conversion measurement (Google Enhanced Conversions), as described in Section 3 — never your name, profile photo, or report data.
Retention and deletion: Your Google Sign-In data is retained as long as your account is active. You can request deletion of your account and all associated data at any time by contacting help@wageproof.com. Upon deletion, your Google data will be removed from our systems within 30 days. Deletion of your WageProof account does not affect data independently held by Google or Clerk.
We request only the email and profile scopes from Google — the minimum required to identify you and create your account. We do not request access to your Google Drive, Gmail, Calendar, Contacts, or any other Google service.
Report inputs
To generate a report, you provide:
- Owner name and company name
- Entity type (Corporation or LLC taxed as S-Corp)
- State and county
- Primary occupation and industry
- Tasks selected, time allocation percentages, and proficiency ratings
- Annual hours worked
- Company revenue range and employee count (for report context, not calculations)
This information is used to generate your report and stored so you can access it later.
Tax professional (CPA) accounts
If you use the Service as a tax professional (a “CPA account”), we also collect:
- Firm profile — your firm name, firm email, the name shown as the report preparer, and any logo or brand colors you upload for white-labeled reports
- Client records — information you enter about your clients, including client name, company name, entity type, location, email address, and any notes you add. You are responsible for having the authority to provide this information; we process it on your behalf to generate reports and manage your client list.
- Income Approach figures — for the CPA-only Income Approach (Independent Investor Test), the business’s fair market value, change in value, and target rate of return that you enter. These figures are used only to calculate that approach and appear in the resulting report.
What we do NOT collect
We do not collect Social Security numbers, Employer Identification Numbers (EINs), bank account information, tax returns, or other financial documents.
Payment information
Payments are processed by Stripe. Your payment details are collected directly by Stripe. We do not see or store your card number or other card details. We receive a payment confirmation and transaction details — such as the amount, currency, and Stripe identifiers — needed to manage your account and report credits. Your card details and billing address stay with Stripe; we do not store them.
Usage data
We automatically collect standard technical information:
- IP address, browser type, operating system, device
- Pages visited, time spent, referring URL
- Web server logs maintained by our hosting provider (Vercel)
- Aggregate, privacy-friendly usage and performance analytics (Vercel Web Analytics and Speed Insights), which do not use tracking cookies
- Application error and performance reports (Sentry), which we configure not to attach personal identifiers
We use this to monitor performance, diagnose issues, and understand usage in aggregate.
Referral information
We may operate a referral or affiliate program. If you arrive at WageProof through an affiliate’s referral link, we and a third-party affiliate-tracking provider (acting as our processor) record that a referral occurred and which affiliate referred you, so that — if you later become a paying customer — we can attribute and pay the referral. This is tied to a first-party referral cookie (see Section 7), not to your report content. The affiliate who referred you does not receive your name, email, or any information that identifies you; only our affiliate-tracking provider does, and only to administer the program.
Marketing attribution
To understand which marketing channels work, we record how you arrived at WageProof: any campaign parameters in the link you clicked (such as utm_source), an ad click identifier if present (such as Google’s gclid, or a Microsoft, Meta, Reddit, OpenAI, or LinkedIn click ID), the site that referred you, and the first page you landed on, together with the date. We keep this in a first-party cookie tied to your account (see Section 7) and associate it with your account when you sign up or make a purchase, so we can attribute a sign-up or sale to a channel after the fact.
This marketing-source information is not shared with advertisers and is not tied to your report inputs or compensation figures. When your browser sends a Global Privacy Control signal we still keep this first-party cookie (it is not a sale or share), but we suppress the third-party advertising and analytics tags described in Section 3 — see “Your Privacy Choices” in Section 9.
Site funnel measurement
To see where people drop off between arriving and finishing, we record which steps of our site you reach — landing, viewing pricing, starting the report wizard, creating an account, completing a purchase — and when. These steps are tied to a first-party analytics identifier we generate (a random value in the wp_sid cookie), not to your identity, until you create an account — at which point we associate that browser’s earlier steps with your account so we can measure which channels and steps lead to sign-ups.
This funnel record is stored only in our own database and is not shared with advertisers or any third party; separately, the ad-conversion measurement in Section 3 reports the event names (not this stored record) to ad platforms as disclosed there. It does not include your report inputs or compensation figures. Because this is first-party measurement and not a sale or share, the funnel record keeps operating even when your browser sends a Global Privacy Control signal (the third-party tags in Section 3 are still suppressed) — see “Your Privacy Choices” in Section 9.
2. How we use your information
We use collected information to:
- Generate your report — your inputs are combined with public BLS wage data to calculate compensation figures and produce your PDF
- Maintain your account — identify you, give you access to past reports, send transactional emails
- Process payments — share your email and payment intent with Stripe
- Improve the Service — aggregate usage analysis (not individual-level) to fix bugs and improve UX
- Advertise the Service — measure which sign-ups and purchases came from our Google, Reddit, Meta, ChatGPT (OpenAI), Microsoft (Bing), and LinkedIn ads, and show our ads to past visitors as they browse other sites or use Reddit, Facebook, Instagram, or LinkedIn (Google Ads, Reddit, Meta, and LinkedIn remarketing) — see Section 3
- Measure which channels work — associate the marketing source we recorded when you arrived (Section 1) with your sign-up or purchase, so we know which campaigns and channels drive new customers
- Measure how visitors move through our site — record which steps of our site you reach (Section 1) to find and fix drop-off between arriving and finishing, and to detect unreliable ad-platform conversion reports
- Operate our referral program — if you arrive through an affiliate’s referral link, attribute the referral and calculate any reward owed to the referring affiliate (see Section 3)
- Comply with legal obligations — retain or disclose information if required by law
We do not sell, rent, or trade your personal information, and we never send Google, Reddit, Meta, OpenAI, Microsoft, or LinkedIn your report inputs or compensation figures. We use Google Ads, Reddit, Meta, and LinkedIn remarketing, which let those platforms show our ads to people who have visited WageProof as they browse other sites and apps in Google’s network or use Reddit, Facebook, Instagram, or LinkedIn. This remarketing is based on your activity on our site (via advertising cookies) — not on your report content. Separately, when you complete a purchase while signed in, we send Google and LinkedIn a one-way (SHA-256) hash of your account email so they can measure that the purchase came from one of our ads (Google Enhanced Conversions and LinkedIn’s Conversions API); the email is hashed in your browser and never sent in plaintext. This is described in the Google Ads and LinkedIn entries in Section 3, is suppressed when your browser sends a Global Privacy Control signal, and never includes your report content. You can opt out at any time, as described in Section 3.
Marketing communications
We will send marketing emails — occasional updates on new features, reasonable-compensation tips, and product changes — only if you give separate opt-in consent. We collect that consent through a one-time prompt after you sign in and record your choice, including the exact wording shown and the date. You can grant or withdraw consent at any time from the marketing-email toggle in your account settings. If we send marketing emails, each will include an unsubscribe link. We keep these consent records for as long as your account is active and as needed to comply with applicable law; on a verified deletion request, we delete or de-identify them.
3. Third-party services
We use a number of third-party service providers to operate, support, and promote the Service. Each receives only the data it needs for its role, and we may add or change service providers over time. We do not share your report inputs or compensation calculations with any third party for unrelated purposes.
Google (Sign-In)
If you choose to sign in with Google, we receive your name, email, and profile photo via Google’s OAuth 2.0 service. We request only the email and profile scopes. We do not access any other Google services. Google Privacy Policy
Google Ads (advertising, conversion measurement, and remarketing)
We advertise WageProof through Google Ads. We use Google’s conversion tracking to measure which ads lead to sign-ups and purchases (reporting events such as “reached pricing” or “purchased a report”), and we use Google Ads remarketing to show our ads to people who have visited WageProof as they browse other sites and apps in Google’s network. Both rely on advertising cookies and Google’s ad-personalization signals tied to your browser or device. We do not send Google your report inputs or compensation figures. When you complete a purchase while signed in, we also send Google a one-way SHA-256 hash of your account email address (Google Enhanced Conversions) so Google can match the purchase to the ad you clicked, including across your devices; the email is hashed in your browser and is never sent to Google in plaintext, and we suppress it entirely when your browser sends a Global Privacy Control signal. You can opt out by turning off ad personalization in your Google Ad Center or by blocking cookies in your browser. Google Privacy Policy
Google Analytics 4 (site analytics)
We use Google Analytics 4 (GA4) to understand how visitors use the site — which pages they view and which steps they complete — so we can improve it. GA4 runs on the same Google tag as our ads (it does not load a second tracker) and sets analytics cookies such as _ga and _gid to recognize returning browsers. We have Google Signals enabled, which lets GA4 join this activity with your Google account’s activity across devices when you’re signed into Google with ads personalization on, and lets us see aggregate demographics and interest categories about our visitors. We do not send GA4 your report inputs or compensation figures (report pages are identified only by anonymous IDs). Your IP address is not retained by GA4, and data retention is set to 14 months. You can opt out by enabling a Global Privacy Control signal (which we honor — see Section 9), by turning off ad personalization in your Google account, or by blocking cookies in your browser. Google Privacy Policy
Reddit Ads (advertising, conversion measurement, and remarketing)
We advertise WageProof through Reddit Ads. We use the Reddit Pixel and Reddit’s Conversions API (a server-to-server version of the same measurement) to measure which ads lead to sign-ups and purchases, and to show our ads to people who have visited WageProof while they use Reddit (remarketing). These rely on advertising cookies and device or browser signals (such as your IP address, browser/user-agent, and a Reddit-set device identifier) to attribute conversions to a Reddit ad. We do not send Reddit your report inputs, your compensation figures, your report contents, or your email or phone number (we do not use Reddit’s advanced matching). You can opt out of personalized Reddit ads in your Reddit account settings (Settings → Privacy → personalized advertising) or by blocking cookies in your browser. Reddit Privacy Policy
Meta — Facebook & Instagram (advertising, conversion measurement, and remarketing)
We advertise WageProof through Meta Ads (Facebook and Instagram). We use the Meta Pixel and Meta’s Conversions API (a server-to-server version of the same measurement) to measure which ads lead to sign-ups and purchases, and to show our ads to people who have visited WageProof while they use Facebook or Instagram (remarketing). These rely on advertising cookies and device or browser signals (such as your IP address, browser/user-agent, and Meta’s _fbp and _fbc cookies) to attribute conversions to a Meta ad; for a purchase we also send the transaction amount. We do not send Meta your report inputs, your compensation figures, your report contents, or your email or phone number (we do not use Meta’s advanced matching). You can opt out of personalized ads in your Meta ad preferences or by blocking cookies in your browser. Meta Privacy Policy
ChatGPT Ads — OpenAI (advertising, conversion measurement)
We advertise WageProof through ChatGPT Ads (OpenAI). We use the OpenAI pixel and OpenAI’s Conversions API (a server-to-server version of the same measurement) to measure which ad interactions lead to sign-ups and purchases. ChatGPT ads are matched to the topic of a conversation rather than to a profile of you, so we do not use remarketing with ChatGPT Ads. These rely on device or browser signals (such as your IP address and browser/user-agent) to attribute conversions to a ChatGPT ad; for a purchase we also send the transaction amount. We do not send OpenAI your report inputs, your compensation figures, your report contents, or your email or phone number (no advanced matching). You can opt out by blocking cookies in your browser or via Global Privacy Control (Section 9). OpenAI Privacy Policy
Microsoft Advertising — Bing (advertising, conversion measurement)
We advertise WageProof through Microsoft Advertising (search ads on Bing). We use Microsoft’s Universal Event Tracking (UET) tag to measure which ad interactions lead to sign-ups and purchases. We do not use remarketing with Microsoft Advertising. The UET tag relies on device or browser signals (such as your IP address and browser/user-agent) and a Microsoft-set click identifier to attribute conversions to a Microsoft ad; for a purchase we also send the transaction amount. We do not send Microsoft your report inputs, your compensation figures, your report contents, or your email or phone number (no advanced matching). You can opt out by blocking cookies in your browser or via Global Privacy Control (Section 9). Microsoft Privacy Statement
LinkedIn Ads (advertising, conversion measurement, remarketing, and lead forms)
We advertise WageProof to tax professionals through LinkedIn Ads. We use the LinkedIn Insight Tag and LinkedIn’s Conversions API (a server-to-server version of the same measurement) to measure which ad interactions lead to sign-ups and purchases, and the Insight Tag also lets us show our ads on LinkedIn to people who have visited WageProof (remarketing) and gives us aggregate, non-identifying reporting about the professional makeup of our visitors. These rely on advertising cookies and device or browser signals (such as your IP address, browser/user-agent, and LinkedIn’s li_fat_id click identifier) to attribute conversions to a LinkedIn ad; for a purchase we also send the transaction amount. For a purchase made while you are signed in, we additionally send LinkedIn’s Conversions API a one-way (SHA-256) hash of your account email so LinkedIn can match the purchase to an ad click — the email is hashed in your browser and is never sent in plaintext. We do not send LinkedIn your report inputs, your compensation figures, or your report contents. We honor Global Privacy Control: when your browser sends it, the Insight Tag does not load and the Conversions API call (including the hashed email) is suppressed (Section 9).
If you respond to one of our LinkedIn ads using a LinkedIn Lead Gen Form, LinkedIn shares with us the contact details you submit (such as your name, work email, job title, and company) so we can send you the requested material and follow up about WageProof. We use those details only for that purpose. Where the form includes an optional marketing-consent checkbox, we send you marketing email only if you check it, and you can withdraw consent or unsubscribe at any time. You can review the data LinkedIn collects and opt out of personalized LinkedIn ads in your LinkedIn account settings (Settings & Privacy → Advertising data). LinkedIn Privacy Policy
Clerk (Authentication)
Manages accounts and sign-in. Receives name, email, and credentials. Clerk’s sign-in pages run a Cloudflare Turnstile bot check; Cloudflare receives technical signals such as your IP address and browser type to verify you are human. clerk.com/legal/privacy
Stripe (Payments)
Processes payments and subscriptions. Receives billing information and payment method. We also attach a compact marketing-source label to the checkout (such as a campaign name or ad click identifier) so we can attribute a purchase to a channel; we never attach your report inputs or compensation figures. PCI-DSS Level 1 certified. stripe.com/privacy
Vercel (Hosting & Analytics)
Hosts the website and provides privacy-friendly, cookieless analytics (Vercel Web Analytics and Speed Insights). Receives standard web server logs and aggregate page-view and performance data. Finalized report PDFs are stored in Vercel’s private, access-controlled Blob storage, and short-lived counters used to rate-limit requests (keyed to IP address) are held in Vercel KV. vercel.com/legal/privacy-policy
Neon (Database)
Serverless PostgreSQL database for account and report data, and for first-party site-funnel/analytics events (which steps of our site visitors reach, tied to a random first-party identifier). SOC 2-compliant infrastructure. neon.tech/privacy-policy
Sentry (Error monitoring)
Captures application errors and performance traces so we can diagnose and fix problems. Receives technical error details (such as stack traces, IP address, and browser information). We configure Sentry not to attach personal identifiers, and we do not send it your report inputs or compensation figures. sentry.io/privacy
Resend (Email delivery)
Sends transactional and notification emails (such as report and questionnaire notifications). Receives the recipient email address and the message content. resend.com/legal/privacy-policy
Slack (internal team alerts)
When you submit our contact form or an in-app support request, the contents of your message — including your name, email address, and the message text — are sent to our internal Slack workspace so our team can see and respond to it. Slack acts as our service provider for this purpose only. Slack Privacy Policy
Rewardful (affiliate / referral tracking)
We run a referral and affiliate program using Rewardful, a third-party affiliate-tracking service that acts as our data processor. If you arrive at WageProof through an affiliate’s referral link, Rewardful sets a first-party cookie to remember which affiliate referred you. If you then create an account and make a purchase, Rewardful receives — through Stripe — the information needed to attribute and pay the referral, which may include your name, email address, and purchase details (such as the plan, amount, currency, and transaction identifiers). We do not send it your report inputs, your compensation figures, or your report contents, and we require it by contract to use this information only to administer the referral program on our behalf, not for its own advertising. Rewardful Privacy Policy
4. Data security
We implement reasonable measures to protect your data:
- All data in transit is encrypted via TLS (HTTPS)
- Database access is restricted and authenticated
- Payments handled by Stripe (PCI-DSS Level 1) — we never see full card numbers
- Authentication managed by Clerk with secure session management
- Production infrastructure access limited to authorized personnel
We treat the business financial figures you enter — such as compensation totals, revenue range, and any Income Approach values — as confidential and protect them with the measures above.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.
5. Data retention
- Account information is retained while your account is active.
- Report data is retained while your account is active so you can access past reports. Because reports may be relevant to tax filings and IRS audits, we recommend keeping your account active for at least the applicable IRS statute of limitations (generally three to six years).
- Payment records are retained as required for accounting and legal compliance.
- Server logs are retained by Vercel per their standard policies.
- Analytics data in Google Analytics 4 is retained for 14 months; your IP address is not retained by GA4.
- Marketing-attribution data (the first-party
wp_attributioncookie and the marketing source associated with your account) is retained while your account is active; the cookie itself expires after 90 days. - Site funnel/analytics events (which steps of our site you reach) are retained for up to 24 months, then deleted; the
wp_sidcookie expires after 180 days. Once these steps are tied to an account, we keep that association while your account is active — because the purpose of this data (measuring which channels and steps lead to sign-ups, and detecting unreliable ad-platform conversion reports) requires linking a customer’s earlier steps to their eventual sign-up or purchase across the multi-week evaluation cycle.
If you ask us to delete your account (by emailing us at the address in Section 13), we will delete or de-identify your account information and any in-progress (draft) report data within 30 days. Two categories are handled differently: (i) finalized reports and their PDF files are moved to a private, non-public, voided state and retained rather than erased, so they remain available to you for tax-filing and IRS-audit defense and so we can meet our legal and accounting obligations; and (ii) payment and credit records are retained as required for accounting, tax, and fraud-prevention purposes. Where your request is subject to one of these retention practices or to a legal exception, we will tell you which applies. We handle deletion and other rights requests manually (there is no self-service deletion tool) — email us at the address in Section 13. Deletion of your WageProof account does not affect data independently held by Stripe or Clerk, which is governed by their respective privacy policies.
6. Your rights
You have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — ask us to correct inaccurate information
- Deletion — request that we delete your account and data. We delete account information and draft reports within 30 days; finalized reports, their PDFs, and payment records are retained as described in Section 5 (Data retention)
- Data portability — request a copy of your report data; your generated reports are available to download as PDFs
- Withdraw consent — where we rely on consent, you can withdraw it at any time
Contact us at the email below to exercise these rights. We will respond within 45 days (extendable by up to 45 additional days where reasonably necessary, with notice to you).
7. Cookies and tracking
We use the following categories of cookies and similar technologies:
- Essential / authentication — required for sign-in (Clerk) and basic functionality. Cannot be disabled.
- Functional (first-party) — the marketing-attribution cookie (
wp_attribution), the first-party funnel-analytics identifier (wp_sid), and, if you arrived via a referral, the first-party referral cookie. Described below. - Analytics — Vercel’s cookieless analytics and Google Analytics 4 cookies (
_ga,_gid). - Advertising — Google Ads, Reddit, Meta, OpenAI, and Microsoft (Bing) advertising cookies used to measure ad conversions and, for Google/Reddit/Meta, remarketing. Suppressed under Global Privacy Control (Section 9).
We use Vercel Web Analytics and Speed Insights — privacy-friendly, cookieless analytics that measure aggregate page views and site performance without setting analytics cookies or tracking you across other sites. We also use Google Analytics 4 (GA4) for site analytics, which sets first-party analytics cookies such as _ga and _gid to recognize returning browsers; GA4 data retention is set to 14 months and your IP address is not retained by GA4 (see the Google Analytics 4 entry in Section 3). You can opt out of GA4 by enabling a Global Privacy Control signal (Section 9) or by blocking cookies in your browser.
We use Google Ads, Reddit, Meta, OpenAI, and Microsoft (Bing) advertising cookies to measure which of our ads lead to sign-ups and purchases (see Section 3). For Google, Reddit, and Meta we additionally use them for remarketing — letting Google, Reddit, and Meta show our ads to you on other sites and apps (or on Reddit, Facebook, or Instagram) after you have visited WageProof. You can opt out by turning off ad personalization in your Google Ad Center, in your Reddit account settings (Settings → Privacy → personalized advertising), in your Meta ad preferences (Facebook/Instagram), or by blocking cookies in your browser.
If we are running our referral program, we also use a first-party referral cookie, set by our third-party affiliate-tracking provider, to remember which affiliate referred you when you arrive through a referral link. It records only the referring affiliate’s identifier and the date you arrived — not your report content or compensation figures — and it expires after the referral attribution window (currently 60 days). You can prevent or remove it by blocking or clearing cookies in your browser; doing so does not affect your ability to use the Service.
We also use a first-party marketing-attribution cookie (named wp_attribution) to remember how you first arrived — the campaign parameters, ad click identifier, and referring site described in Section 1. It is a first-party cookie (it is not used to track you across other sites), it stores only that marketing source (not your report content), and it expires after 90 days. You can prevent or remove it by blocking or clearing cookies in your browser; doing so does not affect your ability to use the Service.
We also use a first-party funnel-analytics cookie (named wp_sid) that stores a random identifier so we can record which steps of our site you reach (Section 1). It is a first-party cookie (it is not used to track you across other sites), it stores only that random value (not your report content), and it expires after 180 days. You can prevent or remove it by blocking or clearing cookies in your browser; doing so does not affect your ability to use the Service.
When your browser sends an opt-out preference signal such as Global Privacy Control (GPC), we suppress the Google Analytics, Google Ads, Reddit, Meta, OpenAI, and Microsoft (Bing) advertising and analytics cookies and tags above for that browser, and set advertising and analytics consent signals to “denied.” The essential and first-party functional cookies — including wp_attribution and wp_sid, which are first-party measurement and not a sale or share — still operate. See “Your Privacy Choices” in Section 9.
8. California privacy rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides additional rights.
Sources of personal information
We collect personal information from: (1) directly from you when you create an account or enter report inputs; (2) from authentication providers (Clerk/Google) when you sign in; (3) automatically from your device when you use the Service, including a first-party analytics identifier we generate to measure which steps of our site you reach.
Categories collected
Under CCPA categories, we collect:
- Identifiers — name, email, IP address, and advertising click identifiers (such as
gclid,fbclid, andmsclkid) when present in the link you arrived from, and a first-party analytics identifier we generate (wp_sid) that is not tied to your identity until you create an account - Commercial information — purchase and report history
- Internet activity — browsing on our site, including which steps of our site you reach and, once you create an account, the steps you reached before signing up — used solely for internal funnel measurement, not to build a profile of you or make decisions about you
- Professional information — occupation, industry, tasks (as entered by you)
- Geolocation — state and county (as entered, not tracked from your device)
We do not collect sensitive personal information as defined by the CPRA.
Your CCPA/CPRA rights
- Right to know what personal information we’ve collected
- Right to correct inaccurate personal information
- Right to delete your personal information
- Right to opt out of sale or sharing — we do not sell your personal information. We do “share” limited online activity with Google (including Google Analytics), Reddit, Meta, OpenAI, and Microsoft (Bing) for analytics and advertising measurement — including, for Google, a one-way SHA-256 hash of your account email used to measure purchase conversions — plus remarketing for Google, Reddit, and Meta, (which the CPRA treats as “sharing” / cross-context behavioral advertising); you can opt out as described in Section 3, by turning off ad personalization in your Google, Reddit, and Meta account settings, or by enabling a Global Privacy Control (GPC) signal in your browser, which we honor automatically (see “Your Privacy Choices” in Section 9).
- Right to non-discrimination for exercising your rights
To submit a CCPA request, contact us at the email below. To verify your identity, we will match information you provide against what we have on file (such as your email address). You may also designate an authorized agent to make a request on your behalf. We will respond within 45 days.
9. Other state privacy laws & your privacy choices
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with privacy laws may have similar rights. We do not sell personal information. We do use Google Ads, Reddit, Meta, ChatGPT (OpenAI), and Microsoft (Bing) conversion measurement, plus Google, Reddit, and Meta remarketing (see Section 3), which several state laws treat as “targeted advertising”; you may opt out as described there. For access, correction, or deletion requests, contact us below.
Appeals. If we deny your privacy-rights request, you may appeal by emailing help@wageproof.com with “Privacy Appeal” in the subject line. We will respond in writing within 60 days and explain the basis for our decision. If your appeal is denied, residents of states that provide it (including Virginia, Colorado, Connecticut, Texas, Oregon, and Montana) may submit a complaint to their state Attorney General.
Your Privacy Choices — Global Privacy Control (GPC)
We honor browser-based opt-out preference signals, including Global Privacy Control (GPC). When your browser sends a GPC signal, we automatically treat it as a request to opt out of the “sale” or “sharing” of your personal information for cross-context behavioral advertising: we suppress the Google Analytics, Google Ads, Reddit, Meta, OpenAI, and Microsoft (Bing) advertising and analytics tags and their server-side conversion events, and we set advertising and analytics consent signals to “denied,” for that browser. Because we honor GPC as a frictionless opt-out, we do not maintain a separate “Do Not Sell or Share My Personal Information” link. The first-party marketing-attribution cookie (Section 1) and the first-party funnel-measurement store and its wp_sid identifier (Section 1) are first-party measurement, not a sale or share, and continue to function under GPC; only the third-party advertising and analytics tags are suppressed.
To use GPC, enable it in a supporting browser or extension. You can also opt out through the Google, Reddit, and Meta account settings linked in Section 3, or by blocking cookies in your browser. If you cannot use a GPC-enabled browser, you can email us at help@wageproof.com with the subject “Opt out of sharing” and we will apply the same suppression to your account.
10. International users
This Service is designed for U.S.-based S-Corp owners and tax professionals. It uses U.S. Bureau of Labor Statistics data and addresses U.S. tax law. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. The Service is intended solely for U.S. users; we do not target the EEA or UK and do not operate an EEA/UK cookie-consent banner. If you are located in the EEA or UK, please do not use the Service.
11. Children’s privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn we have, we will delete it promptly. We also do not sell or share (as those terms are defined under California’s CPRA) the personal information of consumers we actually know to be under 16 years of age.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or prominent notice on the site before taking effect. Continued use after changes constitutes acceptance.
13. Contact us
Questions about this policy, data rights requests, or privacy concerns:
WageProof
Email: help@wageproof.com
We aim to respond to privacy-rights requests within 45 days.