1. Who is responsible for your information
CERTA ITIN LLC operates the Certa platform and is responsible for the account, application, payment, support, security, and service-delivery information described here. Toa Tax Professional separately performs regulated tax-preparation and IRS-authorized Certifying Acceptance Agent (CAA) work and may have independent legal duties for professional records it creates or receives.
This Policy applies to certaitin.com, Certa accounts, applications, support interactions, document custody, and related services. It does not govern the IRS, carriers, banks, or other organizations acting under their own privacy notices.
2. Information we collect
- Account and contact data: name, email, phone number, address, language, credentials, and communication preferences.
- Application and family data: citizenship, immigration and visa details, birth information, foreign and U.S. addresses, ITIN reason, spouse, parent, guardian, student, and dependent information.
- Identity evidence: passport, national identification card, foreign voter-registration card, birth certificate, school record, certified copies, document numbers, photographs, issue and expiration dates, and authenticity findings.
- Tax and financial data: income, filing status, tax forms, prepared returns, tax balance or refund status, payment authorization, funding references, and money-order evidence. Stripe processes card details; Certa ordinarily receives a payment token, status, amount, and limited card metadata rather than the full card number.
- Custody and filing data: carrier, tracking details, return address, receipt condition, storage reference, incidents, signatures, package versions, mailing receipts, and IRS correspondence.
- Interview and support data: appointment details, attendance and room-join evidence, authentication decisions, support messages, and call notes. Certa does not record a verification interview unless it clearly tells participants and obtains any consent required by law.
- Referral and payout data: referral code and link, attribution date, visits or conversion events, program acceptance, declared country of residence, connection-derived country when available, country mismatch signals, commission and adjustment history, payout country and currency, tax-document status, fraud-review signals, and the payout recipient identifier and masked destination returned by our payout provider. When hosted onboarding is available, payout credentials are submitted directly to the provider rather than Certa.
- Technical data: IP address, device and browser data, login and security events, audit logs, diagnostics, and essential cookie or session identifiers.
3. Sensitive information and information about children
Identity documents, tax records, precise financial details, authentication evidence, and information about immigration or citizenship may be sensitive under applicable law. We use this information only as reasonably necessary to provide the requested service, comply with professional and legal obligations, prevent fraud, or with consent where required.
Certa accounts are for adults. An authorized parent, guardian, or other legally permitted adult may submit information for a child or dependent. We do not knowingly solicit children to create accounts or use their information for advertising. Contact us if you believe a child's information was submitted without proper authority.
4. Why we use information
- create and secure accounts, assess eligibility, and save application progress;
- prepare Form W-7 and, when purchased, a federal tax return;
- authenticate identity evidence, manage physical custody, and return originals;
- collect service fees, document tax-funding instructions, and prevent payment fraud;
- attribute referrals, prefill country from connection data where available, route payout methods, investigate country mismatches, calculate and review commissions, onboard eligible payout recipients, issue and reconcile payouts, and meet tax-reporting duties;
- assemble, dispatch, track, and support the filing package;
- communicate case actions, appointments, incidents, and IRS updates;
- meet tax-professional, acceptance-agent, accounting, security, and legal obligations;
- protect applicants and the Service, troubleshoot failures, and maintain an auditable record; and
- improve accessibility and service quality using aggregated or de-identified information where practical.
Depending on your location, our legal bases may include performing a contract, taking steps you request before a contract, complying with law, protecting vital interests, our legitimate interests in operating and securing the Service, and consent. You may withdraw consent for future processing where consent is the basis, without affecting prior lawful processing.
Information furnished in connection with preparation of a U.S. income-tax return is also protected by Internal Revenue Code section 7216 and related regulations. We do not use or disclose that information for another purpose unless a legal exception applies or the taxpayer first provides a valid, separate consent in the form federal law requires. Accepting this Notice or the Terms is not such a consent.
5. Professional review and automated checks
Certa uses rules and automated checks to flag common omissions, inconsistencies, or document issues. These tools assist applicants and staff; they do not solely determine ITIN eligibility, document authenticity, tax positions, filing readiness, or an IRS outcome. A qualified professional reviews material case decisions, and you may ask for human review or correction.
6. When we disclose information
We disclose only what is reasonably necessary to the following recipients:
- Toa Tax Professional and authorized Certa personnel working on your case;
- the IRS and other authorities when you direct us to file, authorize disclosure, or the law requires it;
- service providers that host, secure, communicate, process payment for, or support the Service;
- Stripe or another approved payout provider for hosted recipient onboarding, identity or eligibility checks, bank-detail collection, payout processing, sanctions screening, and reconciliation;
- postal and delivery carriers for tracked document and package transport;
- professional advisers, insurers, auditors, or law enforcement when legally permitted and necessary; and
- a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.
We do not sell personal information, provide it to data brokers, or use it for cross-context behavioral or targeted advertising. We do not share tax-return information for unrelated marketing or use identifiable tax-return information to train general-purpose artificial-intelligence models. A referrer receives aggregated referral and commission status only; we do not disclose the referred customer's name, contact information, application status, documents, or tax information to the referrer.
Service providers receiving tax-return information are limited to the information needed for the contracted tax-preparation or auxiliary service and are subject to confidentiality, security, and tax-information restrictions where required. Access by a person located outside the United States is permitted only when federal tax law allows it, including a valid separate taxpayer consent where required.
7. Key service providers
| Provider | Purpose | Typical data |
|---|---|---|
| Railway | Application and database hosting | Account, case, audit, and technical data |
| Cloudflare R2 | Private file storage and delivery security | Uploaded and generated case documents |
| Stripe | Checkout, payment and fraud controls; hosted referral-payout onboarding and payouts where available | Contact, amount, status, limited card metadata, recipient details, payout credentials, and verification results |
| Resend | Transactional email | Email address and message content |
| Daily | Secure verification interviews | Room access and attendance metadata |
| USPS and other carriers | Tracked transport | Name, address, shipment, and tracking data |
Providers are permitted to use information only for contracted services or their legal obligations. We evaluate providers based on the data they receive, location of processing, security controls, and contractual protections. Their own policies may also apply when you interact with them directly.
8. Cookies and analytics
Certa uses necessary cookies or equivalent browser storage for login, session security, saved progress, support chat, consent preferences, and fraud prevention. These functions remain available when optional cookies are refused.
With permission, Certa uses one first-party referral cookie for up to 30 days to credit the person whose referral link you followed. The referral cookie is disabled by default, is not used for advertising or behavioral tracking, and can be refused or withdrawn through Cookie preferences in the footer. See the Cookie Notice for the current storage list.
9. Security and document handling
We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including encrypted transport, private object storage, access controls, staff multi-factor authentication, malware screening, audit trails, backups, incident procedures, and tracked physical custody. No method is risk-free. Notify us immediately if you suspect account misuse, lost credentials, or a custody problem.
10. Retention
We keep information only as long as needed for the service, professional and legal duties, security, disputes, and accounting. Typical periods are:
| Record | Typical retention |
|---|---|
| Raw identity-document uploads | Normally deleted within 30 days of upload, unless needed for an active incident, legal hold, or professional record |
| Physical originals | Held only through receipt, authentication, and tracked return; ordinarily return-dispatched within one business day after authentication |
| CAA, W-7, tax, signature, and filing evidence | At least three calendar years following the year the ITIN application is mailed, or longer when tax, due-diligence, or professional rules require |
| Payment and accounting records | Up to seven years |
| Referral, commission, payout, and tax records | Up to seven years after the related transaction or longer when tax, fraud, dispute, or legal obligations require |
| Support conversations | Pre-application chats normally up to one year; general account chats normally up to two years; case-linked messages follow the case-record retention period |
| Security and audit logs | Normally up to 24 months, longer for an investigation or legal hold |
| Closed-account operational profile | Normally deleted or de-identified within 30 days; regulated case records remain for their required period |
These are default periods, not promises to retain every item for the maximum time. We may retain data longer where law, an audit, fraud prevention, litigation, or an unresolved IRS matter requires it, and may delete it sooner where lawful and no longer needed.
11. Your privacy choices and rights
Where applicable, you may ask to access, correct, obtain a copy of, delete, restrict, or object to processing of your information; withdraw consent; or appeal a denied request. You may also close your account and opt out of non-essential communications. We honor these rights worldwide where reasonably possible, subject to identity verification and exceptions for tax, CAA, accounting, security, legal, and filing records.
Send requests to support@certaitin.com. We generally respond within 30 days, or within the period required by your law. You may complain to your local data-protection or consumer-protection authority. We will not discriminate against you for exercising a right.
12. International processing
Certa is based in the United States and the case service is directed from the United States. If you submit information from another country, your information is transferred to and processed in the United States. A provider may also process limited information in another country as described in its service documentation and as permitted by law. Privacy protections and government-access rules may differ from those in your country.
Where applicable law requires a transfer mechanism, representative, or additional contractual safeguard, we will put it in place before intentionally offering the affected processing in that jurisdiction. A cross-border transfer of tax-return information is also subject to the separate restrictions described in section 4; this Notice does not authorize an otherwise restricted foreign disclosure.
Referral payout availability is separate from availability of Certa's applicant services. If you request a payout, your recipient and payout information may be processed in the United States and in countries used by the payout provider and its banking partners. Supported recipient countries, currencies, verification requirements, fees, and transfer times vary and may change. Certa does not represent that referral payouts are available worldwide.
13. U.S. financial privacy and safeguards
Tax-preparation firms may be financial institutions under the Gramm-Leach-Bliley Act and FTC rules. This Notice serves as Certa's initial privacy notice for the nonpublic personal information covered by those rules. We collect the categories described in section 2 and disclose them only for the service-provider, processing, legal, fraud-prevention, and other purposes described in section 6.
We do not currently disclose covered nonpublic personal information to nonaffiliated third parties in a way that gives rise to a federal financial-privacy opt-out right. If that practice changes, we will provide any required notice and opt-out before the disclosure. Federal financial-privacy rules do not relax the stricter restrictions that may apply to tax-return information.
Certa maintains a written information-security program proportionate to its size, systems, and sensitive records. This includes risk assessment, access management, encryption, provider oversight, monitoring, incident response, secure disposal, and periodic review.
14. Changes and contact
We may update this Policy as the Service, providers, or law changes. Material changes will be posted with a new effective date and communicated when appropriate. We will request renewed acknowledgement where required.
CERTA ITIN LLC3205 Kyle Ave
Upper Marlboro, MD 20774, United States
Email: support@certaitin.com