TaxDo Logo

Privacy Policy

Effective January 5, 2026 · Version 5.0

TaxDo helps businesses verify tax identities. This policy explains what personal information we collect when you visit our websites, use our services, or deal with us as a customer or supplier — and what we do with it.

Most of the information our customers send to the Services is not covered by this policy. When a customer submits a query, that customer decides what to send and why. We handle it on their instructions under a data processing agreement, and their privacy policy applies, not ours. Section 1 explains the difference and how to reach them.

1. Who we are, and what this policy covers

TaxDo Inc., doing business as TaxDo (“TaxDo”, “we”, “us”), is a Florida corporation with its registered office at 7901 4th St N, St. Petersburg, FL 33702, United States.

1.1 Where we decide how information is used

This policy applies where TaxDo determines why and how personal information is used. That covers people who visit our websites, contact us, request a demo or subscribe to our communications; individual users and administrators of accounts held by our business customers; and our billing, supplier and account-administration records.

1.2 Where our customers decide

When a business customer submits information to the Services, that customer is the controller of it and we act as its processor under a data processing agreement. We use that information only to return the result the customer asked for.

If you believe one of our customers has submitted information about you, please contact that organisation directly — they can tell you what they hold and why. If you write to us instead, we will refer your request to them and support them in responding.

2. What we collect, and how we use it

What we collect depends on how you interact with us. This section is organised by the ways people deal with TaxDo, so you can read the part that applies to you.

2.1 If you visit our websites

What we collect. Information about your device and how you use the site, including IP address, browser and device characteristics, operating system, language, referring page, pages viewed and general interaction data. We derive an approximate location — typically country or region — from your IP address. We do not collect precise device geolocation.

If you fill in a form, request a demo, subscribe or contact us, we also collect what you give us: your name, business email, company, and anything you write to us.

How we use it. To operate and secure the site, to understand how it is used so we can improve it, to respond to you, and for business-to-business marketing. Analytics and advertising technologies are used where you consent to them or, in countries where consent is not required, where you have not opted out. See section 3.1 and our Cookie Policy.

2.2 If you use an account with us

What we collect. Your name, job title, business contact details and the organisation you work for; your username, authentication and session data, and your password in hashed form; your contact preferences; records of your use of the Services; and your correspondence with our support, sales and legal teams.

Where your organisation buys from us directly, we also hold billing contact details, billing address, and subscription and invoice records. Card and bank details are collected and held by our payment processors — we receive a transaction reference and the outcome, not the instrument number.

How we use it. To provide and administer the Services, to secure them and prevent misuse, to bill you and keep accounting records, to support you, to tell you about changes, and to improve what we offer.

2.3 If our customer submits information about you

What we process. The identifiers and records our customer sends for validation, together with what the relevant tax authority or official register returns. Depending on the service the customer uses, that can include a business or individual taxpayer identification number, and in the United States that number may be a Social Security number.

How we use it. Only to perform the check the customer asked for and return the result to that customer. We do not use it for advertising, marketing, profiling, credit assessment or any other purpose, and we do not sell or share it. What we process for each service, and the safeguards that apply, are set out in the data processing agreement we hold with that customer.

2.4 If you are a business contact or supplier

What we collect. Business contact details, the organisation you represent, our correspondence with you, and — where you become a customer or supplier — registration and business activity information about your organisation for onboarding and sanctions screening.

We may also receive business contact information from marketing partners, event organisers, professional networks and business data providers. Where European or United Kingdom law applies and we obtain your information from a source other than you, we will tell you the source within one month, or at our first communication with you.

How we use it. To respond to enquiries, run events, carry out business-to-business marketing, manage our supplier relationships, meet our onboarding and screening obligations, and keep our records. You can opt out of marketing at any time — see section 7.

3. More ways we collect, use and share

3.1 Cookies and similar technologies

We use cookies and similar technologies on our websites. Where the law requires consent, nothing other than a strictly necessary cookie is set until you give it; where consent is not required, you can opt out at any time. You can change or withdraw your choice at any time. Our Cookie Policy explains the categories we use and how to control them, and the cookie settings link in our footer shows what is in use on your visit.

Some of these technologies record general interactions with our public website, such as clicks, scrolling and mouse movement, so that we can see where pages are working and where they are not. They are configured so that text is not captured. They are used on our public website only, and never on the parts of our platform where tax identification data is submitted.

3.2 Service providers

We share personal information with service providers who help us run our business — hosting and cloud infrastructure, payment processing, customer relationship and marketing platforms, analytics and performance monitoring, communications, and professional advisers such as lawyers, auditors and accountants. They may use it only to provide services to us, under written terms that require security and confidentiality.

The service providers we use to process personal information on behalf of our customers are listed at taxdo.com/legal/subprocessors.

3.3 Artificial intelligence

Our three core engines — the Tax Identity Engine, the Global Indirect Tax Compliance Engine and the Global Regulatory Compliance Engine — use no artificial intelligence and no machine learning. They apply published rules to official records and return what those records hold.

Artificial intelligence is used only in certain optional services that support those engines. Those services are switched off unless your organisation chooses to enable them, we identify them in the service or the documentation so you know when you are working with one, and where one interacts with you directly it tells you that you are interacting with an AI system. We do not use customer data to train artificial intelligence models, and our agreements with our model providers prohibit them from doing so.

3.4 Legal, safety and business transfers

We disclose personal information where we are required to by law, regulation, subpoena, court order or governmental request; where it is reasonably necessary to establish, exercise or defend a legal claim; to investigate or prevent fraud, security incidents or misuse of the Services; and to an acquirer or successor in a merger, financing or sale of our business. Where we are lawfully permitted to do so, we give notice before disclosing.

3.5 Aggregated and de-identified information

We create aggregated and de-identified information that cannot reasonably be used to identify you, and we may use and share it for any purpose, including improving and promoting the Services.

4. Legal bases

Where European, United Kingdom or Swiss data protection law applies to our own use of personal information, we rely on the following.

  • Performance of a contract — to provide the Services, administer accounts, and take payment.
  • Legitimate interests — to secure the Services and prevent fraud and misuse, to respond to enquiries and provide support, to improve what we offer, to carry out business-to-business marketing, and to establish, exercise or defend legal claims. Where we rely on legitimate interests we have considered whether they are overridden by your rights, and you may ask us for a summary of that assessment.
  • Legal obligation — for accounting and tax records, sanctions screening, and responding to courts, regulators and law enforcement.
  • Consent — for non-essential cookies and related technologies, and for marketing where local law requires it. You may withdraw consent at any time; withdrawal does not affect processing already carried out.

Where we act as a processor for our customers, the legal basis is theirs to determine, not ours.

5. Security and retention

We use reasonable organisational, technical and administrative measures designed to protect personal information against unauthorised access, destruction, loss, alteration or misuse. No data transmission or storage system can be guaranteed to be completely secure.

You have a part to play too. Use a strong password, do not reuse it on other sites, and keep it and any API key to yourself. If you believe your account has been compromised, write to [email protected].

We retain personal information for as long as we need it for the purposes described in this policy — while we provide the Services to you or to a customer, and for a period afterwards in which we reasonably foresee continuing to do so. Even after that, we may continue to retain it to:

  • comply with our legal, tax, accounting and regulatory obligations;
  • enable fraud monitoring, detection and prevention;
  • establish, exercise or defend legal claims, and honour any legal hold; and
  • honour an opt-out you have given us, which requires us to keep a record of it.

This means we keep different information for different periods, in accordance with the limitation periods and record-retention obligations imposed by applicable law. Where we act as a processor, retention is set by our customer's data processing agreement, including the evidentiary record that supports a Certificate of Validation, and deletion on written request. When we no longer need information, we delete it or irreversibly anonymise it.

6. International transfers

We are based in the United States. As a global business, it is sometimes necessary for us to transfer personal information to countries other than your own, including the United States. Where we collect information directly from you in the European Economic Area, the United Kingdom or Switzerland, that is not a restricted transfer. For onward disclosures, and for information we receive from our customers, we rely on the European Commission's Standard Contractual Clauses, together with the United Kingdom International Data Transfer Addendum for United Kingdom personal data and the Swiss addendum for Swiss personal data. Copies of the mechanisms we use are available on request.

7. Your rights and choices

Depending on where you are, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to receive it in a portable form, to restrict or object to how we use it, and to withdraw consent. Section 8 sets out the rights that apply in particular regions and how we handle requests.

To exercise any right, write to [email protected]. We may need to verify your identity, and we will not ask for more than is reasonable to do so. You may use an authorised agent; we will ask for written proof of authorisation.

Marketing. You can unsubscribe from our marketing emails using the link in any message, or by writing to us. We will still send you service and account messages.

Cookies and tracking. Use the cookie settings link in our footer, available on every page. You can also manage cookies through your browser settings.

Opt-out preference signals. We honour Global Privacy Control. If your browser or an extension sends that signal, we treat it as a request to opt out of the sale and sharing of your personal information and of targeted advertising, for that browser. We do not respond to legacy Do-Not-Track headers, because no common standard for them was agreed.

Complaints. If you are unhappy with how we have handled your personal information, write to us at [email protected]. We will look into it and respond without undue delay. You may also complain to your supervisory authority; you do not have to come to us first.

8. Region-specific terms

8.1 United States

If you are a resident of a state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use and disclose it; to obtain a copy of it; to correct it; to delete it; to opt out of its sale or sharing and of targeted advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights. Where your state provides for it, you may appeal a decision by writing to us, and you may complain to your state attorney general.

We do not sell personal information for money. Our use of analytics and advertising technologies on our website may amount to a “sale” or “sharing” under some state laws, and you can opt out using the cookie settings link in our footer or by sending an opt-out preference signal. Information submitted to the Services is never used for advertising and is never sold or shared.

8.2 European Economic Area, United Kingdom and Switzerland

You have the rights described in section 7, and you may lodge a complaint with your national supervisory authority, the United Kingdom Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.

Our validation checks are automated: they compare a submitted identifier against official records and return a status. They report whether an identifier matches an official record, and are not assessments of a person's character, creditworthiness, behaviour or reliability. Where applicable law gives you the right to object to automated processing or profiling that produces legal or similarly significant effects, we will tell you how to exercise it.

8.3 Other regions

In Canada we handle personal information under PIPEDA and applicable provincial law, and you may complain to the Office of the Privacy Commissioner of Canada. In Australia and New Zealand we handle it under the Australian Privacy Principles and the New Zealand Information Privacy Principles, and you may complain to the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner. In South Africa we handle it under POPIA, and you may complain to the Information Regulator. In Brazil we handle it under the LGPD, and you may complain to the ANPD.

9. Children

Our Services are for businesses. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, write to [email protected] and we will delete it.

10. Changes to this policy

We may update this policy from time to time. The effective date appears at the top of this page. For material changes we will post a prominent notice on the site or contact you directly, and where a new service involves categories of personal information not described here, we will update this policy before that processing begins.

11. How to contact us

For any privacy question, or to exercise a right, write to [email protected], or to TaxDo Inc., 7901 4th St N, St. Petersburg, FL 33702, United States.