Privacy Policy

Effective: February 10, 2026

ExemptPay ("we," "us," "our") operates the website at exemptpay.com. This Privacy Policy explains what information we collect, how we use it, and your choices. We believe in being straightforward — no legalese traps.

1. Information We Collect

Information you provide:

  • Account information: Email address when you sign up. Name and organization name if you choose to add them to your profile.
  • Payment information: When you subscribe to a paid plan, payment details are collected and processed directly by Stripe. We do not receive or store your credit card number. We receive only a confirmation of payment status and a truncated card identifier (e.g., "**** 4242").
  • Organization profile data: If you use our compensation report features, you may provide information about your organization (EIN, budget size, state) and the positions you want to benchmark.

Information collected automatically:

  • Usage data: Which features you use, searches you perform, and reports you generate. We use this to enforce usage limits and improve the product.
  • Log data: Your IP address, browser type, and referring URL when you visit our site. This is standard web server logging.

2. How We Use Your Information

  • Provide the service: Authenticate your account, process your searches, generate reports, track usage against your plan limits.
  • Process payments: Manage your subscription and billing through Stripe.
  • Improve the product: Understand how features are used so we can make them better.
  • Communicate with you: Send transactional emails (account confirmation, password reset, billing receipts). We do not send marketing emails unless you opt in.

3. Third-Party Services

We use the following third-party services to operate ExemptPay:

  • Supabase — Hosts our database and handles user authentication. Your account data and usage records are stored on Supabase infrastructure.
  • Stripe — Processes payments. Stripe receives your payment details directly. See Stripe's Privacy Policy.
  • OpenAI — We use AI models to normalize and classify job titles in our data pipeline. When you search for a position, your search query may be sent to OpenAI for title matching. We do not send your personal information, payment data, or organization details to OpenAI.
  • Analytics — We may use web analytics tools to understand site traffic and usage patterns. If and when we add analytics, we will update this policy to disclose the specific service used.
  • Vercel — Hosts our website. See Vercel's Privacy Policy.

4. What We Don't Do

  • We do not sell your personal information to anyone.
  • We do not store your credit card numbers. Stripe handles that entirely.
  • We do not track you across other websites.
  • We do not serve third-party advertising.
  • We do not share your data with data brokers or marketing platforms.

5. Cookies and Local Storage

We use cookies and browser local storage for functional purposes only:

  • Authentication cookies: To keep you signed in to your account.
  • Session data: To remember your preferences during a session (e.g., selected filters).

We do not use third-party advertising or tracking cookies.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain records for legal or financial compliance (e.g., billing records).

Anonymized and aggregated usage data (which cannot identify you) may be retained indefinitely for product improvement purposes.

7. Your Rights

You can:

  • Access your personal data through your account profile.
  • Correct your information by updating your profile.
  • Delete your account and associated data through your account settings, or by emailing us.
  • Export your data by contacting us at support@exemptpay.com.

If you are located in a jurisdiction with specific data protection laws (such as GDPR or CCPA), you may have additional rights. Contact us and we will work with you to honor applicable requirements.

8. IRS Form 990 Data

ExemptPay displays compensation information from IRS Form 990 filings. These are public records filed by tax-exempt organizations and made available by the IRS. The names, titles, and compensation figures of individuals listed in Form 990 filings are part of the public record.

Our display and analysis of this publicly available information does not create a privacy obligation to the individuals or organizations named in those filings. If you believe information displayed about you is inaccurate, please contact us and we will review it — but note that we present the data as filed with the IRS.

9. Children's Privacy

ExemptPay is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child under 13 has provided us with personal information, contact us and we will delete it.

10. Security

We use industry-standard security measures to protect your data, including encryption in transit (TLS/HTTPS), access controls, and secure authentication. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated effective date. Material changes will be communicated via email to registered users where practical.

12. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at support@exemptpay.com.