Privacy Policy
Effective 2026-05-11
PayStub ("we") provides payroll software to small US employers. This policy explains what data we collect, why, how we use it, and your rights to access and delete it.
Data controllers vs. processors
For data your company (the "Customer") puts into PayStub about its employees and contractors, the Customer is the data controller and PayStub is the data processor. The Customer is responsible for obtaining consent from its workers to share their information with us.
What we collect
- Account data: name, email, password hash, MFA secret (encrypted).
- Company data: legal name, EIN (encrypted), addresses, payroll defaults.
- Worker data: name, address, email, last-4 SSN (encrypted), classification, wage rate, tax profile, optional bank info (encrypted).
- Payroll records: pay runs, paystubs, earnings, deductions, taxes.
- Operational logs: IP, user agent, request id, audit-log entries.
- Billing data: handled by Stripe; we only see customer IDs + subscription metadata.
How we use it
- Run payroll and generate paystubs.
- Send paystub-ready notifications.
- Bill the Customer.
- Detect abuse, debug failures, and meet IRS / EDD retention requirements.
Sharing
We do not sell your data. We share with these processors only:
- Stripe (billing)
- Resend (email delivery)
- DigitalOcean (managed Postgres + object storage + compute)
- Sentry (error monitoring)
- Axiom (log storage)
- Cloudflare Turnstile (bot detection on sign-up)
Retention
Payroll records are retained for 7 years to satisfy IRS and most state requirements. On account deletion request, we cancel billing, redact PII (names, addresses, emails, SSN-last-4, bank info), delete file artifacts (voided checks, PDFs), and keep aggregate financial figures for the 7-year tax-record window.
Your rights
- Access — download a JSON + CSV export at any time.
- Correction — edit your data directly in the app.
- Deletion — Owner can request account deletion from the Billing page.
- Portability — export covers everything.