Your Data Stays Yours. Our Ledger Stays Closed.
We process sensitive financial data every day. We know the weight of that trust. This policy isn’t a legal shield—it’s a operational protocol. We built MyPayroll to handle your payroll with precision, and we apply that same discipline to your privacy. No data brokers, no hidden trackers, no cross-selling. Just secure, compliant processing with a clear audit trail.
What We Collect & Why
MANDATORY FIELDS ONLY. NO GUESSWORK.
Full legal name, SSN/EIN, address. Used strictly for tax filing and employee verification. Stored in a zero-knowledge vault; even we can't read your SSN in plain text.
Wage history, tax withholding, deduction amounts. This is your immutable ledger. We retain this for 7 years to comply with federal audit requirements.
IP address, browser type, session timestamps. Used for security anomaly detection (e.g., login from a new state). Not used for advertising.
Email records, support tickets. We keep these to resolve disputes and improve our documentation. We do not sell or share these insights.
Security Architecture & Encryption
We treat data in transit and at rest with the same paranoia. MyPayroll utilizes bank-grade encryption standards. Our infrastructure is hosted in SOC 2 Type II certified data centers. Access to production databases is restricted to automated systems only; human engineers require multi-factor authentication and explicit justification to touch the ledger. We run automated penetration tests quarterly and maintain a public bug bounty program.
Your Rights & Controls
YOU OWN THE DATA. WE JUST PROCESS IT.
| Right | Action | Turnaround |
|---|---|---|
| Access | Export complete payroll history & audit logs. | Instant (CSV/PDF) |
| Correction | Modify SSN, Name, or Address. Re-run affected tax forms. | Immediate / 24h for IRS resub |
| Deletion | Request account erasure (anonymized history retained). | 30 Days |
| Portability | Move data to a competitor (standard JSON format). | Instant |
We frequently see small business owners sharing a single MyPayroll login with their bookkeeper. This violates our terms and creates a security risk. We cannot distinguish between "Owner" actions and "Contractor" actions in the audit log. Solution: Create an "Office Manager" role with limited permissions.
Have a specific data concern?
Our Data Protection Officer handles all privacy inquiries directly. No ticketing systems. No hold music.