1. Information collected
- Account identity, authentication, invitations, roles, and session records.
- Company identity, filing-account configuration, jurisdictions, forms, periods, and authority identifiers.
- Files and records you submit, reviewed extraction fields, evidence, findings, reports, and support messages.
- Connection status, consent, operational events, security logs, billing identifiers, and limited product analytics.
Do not submit portal passwords, MFA codes, or unrelated personal information.
2. How information is used
Information is used to authenticate users, isolate company workspaces, process and compare evidence, explain findings, deliver reports and notices, operate billing, prevent abuse, respond to support, fulfill exports or deletion requests, and improve reliability.
3. AI-assisted processing
When document AI is enabled, relevant submitted document content is sent to the configured model provider to propose structured fields and grounded explanations. Proposals retain provenance and require customer review before promotion into accepted filing records. AI output is not independent authority evidence.
4. Service providers
Checkfiled uses infrastructure, database/storage, authentication, email, AI, payment, and monitoring providers to operate the service. Stripe receives payment details directly; Checkfiled stores billing identifiers and status rather than complete card numbers. Providers receive only the information needed for their role and are subject to their own processing terms.
5. Sharing and sales
Information may be disclosed to authorized workspace members, service providers, professional advisers, or authorities when legally required or necessary to protect the service. Checkfiled does not use customer tax documents for third-party advertising and does not sell them.
6. Retention and deletion
Evidence and audit history are retained while needed to provide the service, preserve requested records, meet contractual or legal duties, resolve disputes, and maintain security. Owners can request a company export and a cooling-off deletion. Personal account deletion is blocked while company responsibilities remain. Backups and provider systems may follow documented recovery and deletion windows.
7. Security and incidents
Controls include private storage, expiring access, role-based authorization, row-level tenant isolation, service-only operations, session revocation, and incident communication. No system can promise absolute security. Material incidents are communicated through the product status process as appropriate.
8. Choices and requests
Users can manage notifications and sessions. Owners can manage membership, exports, subscriptions, and company deletion. Requests to access, correct, export, or delete information can also be submitted through the in-product support and data-request controls, subject to identity, authority, and legal verification.
9. Children and changes
The service is for business users and is not directed to children. Material notice changes will receive a new effective date and appropriate notice. Jurisdiction-specific rights and required business disclosures must be reviewed before this draft is approved.
Contact
Contact information will be published when this document is approved.