Partnership Order Privacy Notice
Version: partnership_order_privacy_2026_08_01_v1
Effective: July 27, 2026
1. Scope
This notice covers the protected partnership preflight, order, Stripe payment, order-status, provider-handoff, refund, and artifact authorization workflow. Our general Privacy Policy also applies.
2. Preflight and tax facts
Canonical partnership facts sent to server preflight are processed transiently to evaluate the route and create a keyed fact digest. The order ledger does not retain the canonical filing payload, names, addresses, EINs, TINs, partnership-representative identifiers, or generated return PDFs.
The keyed digest covers the complete canonical return payload, normalized route facts, decision, and contract versions. It cannot be recomputed without a server-held secret. We do not place raw or plain-hashed TINs or representative identifiers in the ledger.
3. What the order ledger stores
- an opaque keyed account identifier and order ID;
- the keyed fact digest and non-sensitive version identifiers;
- exact product, capability, builder, artifact, provider, price, legal, and approval contract identifiers;
- Stripe session, PaymentIntent, charge, refund, and dispute IDs;
- payment, fulfillment, revocation, event, and refund-queue state.
4. Stripe metadata
Stripe receives payment and account-email information needed to process payment. Partnership metadata is limited to opaque order, keyed digest, tax-year, capability, contract, and artifact-version identifiers. It must not contain names, EINs, TINs, representative identifiers, addresses, income, deductions, or the filing payload.
5. Providers and professionals
No filing facts are sent to an e-file provider, CPA/EA, CAA, or partnership-representative service unless the exact route is operational, the customer sees the named provider and disclosure, and the required consent and secure-transfer step occurs. A checkout selector alone cannot authorize a provider.
6. Logs and analytics
Ordinary application logs and analytics must not contain the filing payload, TINs, representative identifiers, names, EINs, addresses, or generated artifacts. Operational logs may contain opaque order, Stripe object, event, and non-sensitive outcome codes.
7. Retention and deletion
Order, payment, event, dispute, and refund records are retained for financial, fraud-prevention, support, and legal obligations. Tax payloads and completed PDFs are not retained by this order ledger. Account deletion requests do not erase records we must retain, but eligible account data can be deleted or de-identified. Contact info@foreignllctax.com to request access, correction, or deletion.
8. Security limits
Your order is protected by authenticated ownership checks, keyed cryptographic identifiers, and signed Stripe webhooks, and card details are entered only on Stripe — never on this site. Keep your own copy of the final filing package with your records.