Privacy Policy

Last Updated: June 17, 2026

At Tallie, the privacy and security of your organization's data are our highest priorities. Because our Service processes sensitive payroll records, employee counts, pay bands, and demographic variables, this Privacy Policy outlines our strict data handling, privacy compliance, and security standards.

1. Tallie's Role: Service Provider

Under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and related privacy frameworks:

  • Your organization is the Business (or Data Controller) directing the purposes of data collection.
  • Tallie acts strictly as a Service Provider (or Data Processor) processing employee data solely on your behalf to perform calculations and compile reports.
  • We do not sell, share, trade, or monetize any employee payroll files, emails, or personal information uploaded to the Service.

2. Information We Process

We collect and process the following categories of data in connection with the Service:

  • Account Information: Name, work email address, company name, EIN, and billing details (payment details are handled securely directly by Stripe).
  • Uploaded Payroll Records: Employee payroll demographics (gender, race/ethnicity), job titles, SOC codes, hours worked, pay rates, and period dates required for California CRD compliance reporting.
  • Usage & Technical Metadata: IP addresses, browser types, and usage statistics gathered to maintain service stability and detect malicious activity.

3. Data Security and Isolation

We implement enterprise-grade technical and organizational measures to safeguard your data:

  • Encryption: All data is encrypted in transit using TLS 1.3 protocols and at rest using AES-256 encryption.
  • Row Level Security (RLS): Our database is structured using strict PostgreSQL RLS policies. Your organization's data is physically isolated at the query level, ensuring no member of another company can ever view or access your payroll information.
  • Payment Security: Tallie is PCI-compliant by outsourcing card transaction handling and subscription state records directly to Stripe.

4. Retention and Deletion

We retain your uploaded payroll and report history only for as long as your account remains active or to fulfill legal compliance audits.

You have the right to request deletion of all organization data at any time. Upon deleting your organization or cancelling and requesting complete purge, all employee records, mapped rows, and computed reports associated with your workspace will be permanently erased from our production databases within 30 days.

5. Third-Party Subprocessors

We partner with a limited number of subprocessors to maintain the Service. Each is audited to ensure they maintain appropriate security standards:

  • Supabase / AWS: Database hosting, user authentication, and file storage.
  • Stripe: Payment card processing and subscription management.
  • Resend: Transactional email delivery and compliance alert dispatches.

6. Compliance with Privacy Regulations

Because we process employee data at your direction, your organization is responsible for responding to individual employee requests regarding their rights under the CCPA/CPRA (e.g., access, deletion). Tallie will provide reasonable technical cooperation to help you satisfy these requests.

If you have questions about our security controls, subprocessors, or wish to request data purging, please contact us directly at yuseff@openyf.dev.