Legal · Version 2026-08-21

Privacy & Financial Information Notice

This Notice explains how Certa handles personal, identity, tax, payment, and document-custody information, including protections that apply to tax-return and nonpublic financial information.

Effective August 21, 2026 · Last updated August 21, 2026

1. Who is responsible for your information

CERTA ITIN LLC operates the Certa platform and is responsible for the account, application, payment, support, security, and service-delivery information described here. Toa Tax Professional separately performs regulated tax-preparation and IRS-authorized Certifying Acceptance Agent (CAA) work and may have independent legal duties for professional records it creates or receives.

This Policy applies to certaitin.com, Certa accounts, applications, support interactions, document custody, and related services. It does not govern the IRS, carriers, banks, or other organizations acting under their own privacy notices.

2. Information we collect

  • Account and contact data: name, email, phone number, address, language, credentials, and communication preferences.
  • Application and family data: citizenship, immigration and visa details, birth information, foreign and U.S. addresses, ITIN reason, spouse, parent, guardian, student, and dependent information.
  • Identity evidence: passport, national identification card, foreign voter-registration card, birth certificate, school record, certified copies, document numbers, photographs, issue and expiration dates, and authenticity findings.
  • Tax and financial data: income, filing status, tax forms, prepared returns, tax balance or refund status, payment authorization, funding references, and money-order evidence. Stripe processes card details; Certa ordinarily receives a payment token, status, amount, and limited card metadata rather than the full card number.
  • Custody and filing data: carrier, tracking details, return address, receipt condition, storage reference, incidents, signatures, package versions, mailing receipts, and IRS correspondence.
  • Interview and support data: appointment details, attendance and room-join evidence, authentication decisions, support messages, and call notes. Certa does not record a verification interview unless it clearly tells participants and obtains any consent required by law.
  • Referral and payout data: referral code and link, attribution date, visits or conversion events, program acceptance, declared country of residence, connection-derived country when available, country mismatch signals, commission and adjustment history, payout country and currency, tax-document status, fraud-review signals, and the payout recipient identifier and masked destination returned by our payout provider. When hosted onboarding is available, payout credentials are submitted directly to the provider rather than Certa.
  • Technical data: IP address, device and browser data, login and security events, audit logs, diagnostics, and essential cookie or session identifiers.

3. Sensitive information and information about children

Identity documents, tax records, precise financial details, authentication evidence, and information about immigration or citizenship may be sensitive under applicable law. We use this information only as reasonably necessary to provide the requested service, comply with professional and legal obligations, prevent fraud, or with consent where required.

Certa accounts are for adults. An authorized parent, guardian, or other legally permitted adult may submit information for a child or dependent. We do not knowingly solicit children to create accounts or use their information for advertising. Contact us if you believe a child's information was submitted without proper authority.

4. Why we use information

  • create and secure accounts, assess eligibility, and save application progress;
  • prepare Form W-7 and, when purchased, a federal tax return;
  • authenticate identity evidence, manage physical custody, and return originals;
  • collect service fees, document tax-funding instructions, and prevent payment fraud;
  • attribute referrals, prefill country from connection data where available, route payout methods, investigate country mismatches, calculate and review commissions, onboard eligible payout recipients, issue and reconcile payouts, and meet tax-reporting duties;
  • assemble, dispatch, track, and support the filing package;
  • communicate case actions, appointments, incidents, and IRS updates;
  • meet tax-professional, acceptance-agent, accounting, security, and legal obligations;
  • protect applicants and the Service, troubleshoot failures, and maintain an auditable record; and
  • improve accessibility and service quality using aggregated or de-identified information where practical.

Depending on your location, our legal bases may include performing a contract, taking steps you request before a contract, complying with law, protecting vital interests, our legitimate interests in operating and securing the Service, and consent. You may withdraw consent for future processing where consent is the basis, without affecting prior lawful processing.

Information furnished in connection with preparation of a U.S. income-tax return is also protected by Internal Revenue Code section 7216 and related regulations. We do not use or disclose that information for another purpose unless a legal exception applies or the taxpayer first provides a valid, separate consent in the form federal law requires. Accepting this Notice or the Terms is not such a consent.

5. Professional review and automated checks

Certa uses rules and automated checks to flag common omissions, inconsistencies, or document issues. These tools assist applicants and staff; they do not solely determine ITIN eligibility, document authenticity, tax positions, filing readiness, or an IRS outcome. A qualified professional reviews material case decisions, and you may ask for human review or correction.

6. When we disclose information

We disclose only what is reasonably necessary to the following recipients:

  • Toa Tax Professional and authorized Certa personnel working on your case;
  • the IRS and other authorities when you direct us to file, authorize disclosure, or the law requires it;
  • service providers that host, secure, communicate, process payment for, or support the Service;
  • Stripe or another approved payout provider for hosted recipient onboarding, identity or eligibility checks, bank-detail collection, payout processing, sanctions screening, and reconciliation;
  • postal and delivery carriers for tracked document and package transport;
  • professional advisers, insurers, auditors, or law enforcement when legally permitted and necessary; and
  • a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.

We do not sell personal information, provide it to data brokers, or use it for cross-context behavioral or targeted advertising. We do not share tax-return information for unrelated marketing or use identifiable tax-return information to train general-purpose artificial-intelligence models. A referrer receives aggregated referral and commission status only; we do not disclose the referred customer's name, contact information, application status, documents, or tax information to the referrer.

Service providers receiving tax-return information are limited to the information needed for the contracted tax-preparation or auxiliary service and are subject to confidentiality, security, and tax-information restrictions where required. Access by a person located outside the United States is permitted only when federal tax law allows it, including a valid separate taxpayer consent where required.

7. Key service providers

ProviderPurposeTypical data
RailwayApplication and database hostingAccount, case, audit, and technical data
Cloudflare R2Private file storage and delivery securityUploaded and generated case documents
StripeCheckout, payment and fraud controls; hosted referral-payout onboarding and payouts where availableContact, amount, status, limited card metadata, recipient details, payout credentials, and verification results
ResendTransactional emailEmail address and message content
DailySecure verification interviewsRoom access and attendance metadata
USPS and other carriersTracked transportName, address, shipment, and tracking data

Providers are permitted to use information only for contracted services or their legal obligations. We evaluate providers based on the data they receive, location of processing, security controls, and contractual protections. Their own policies may also apply when you interact with them directly.

8. Cookies and analytics

Certa uses necessary cookies or equivalent browser storage for login, session security, saved progress, support chat, consent preferences, and fraud prevention. These functions remain available when optional cookies are refused.

With permission, Certa uses one first-party referral cookie for up to 30 days to credit the person whose referral link you followed. The referral cookie is disabled by default, is not used for advertising or behavioral tracking, and can be refused or withdrawn through Cookie preferences in the footer. See the Cookie Notice for the current storage list.

9. Security and document handling

We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including encrypted transport, private object storage, access controls, staff multi-factor authentication, malware screening, audit trails, backups, incident procedures, and tracked physical custody. No method is risk-free. Notify us immediately if you suspect account misuse, lost credentials, or a custody problem.

10. Retention

We keep information only as long as needed for the service, professional and legal duties, security, disputes, and accounting. Typical periods are:

RecordTypical retention
Raw identity-document uploadsNormally deleted within 30 days of upload, unless needed for an active incident, legal hold, or professional record
Physical originalsHeld only through receipt, authentication, and tracked return; ordinarily return-dispatched within one business day after authentication
CAA, W-7, tax, signature, and filing evidenceAt least three calendar years following the year the ITIN application is mailed, or longer when tax, due-diligence, or professional rules require
Payment and accounting recordsUp to seven years
Referral, commission, payout, and tax recordsUp to seven years after the related transaction or longer when tax, fraud, dispute, or legal obligations require
Support conversationsPre-application chats normally up to one year; general account chats normally up to two years; case-linked messages follow the case-record retention period
Security and audit logsNormally up to 24 months, longer for an investigation or legal hold
Closed-account operational profileNormally deleted or de-identified within 30 days; regulated case records remain for their required period

These are default periods, not promises to retain every item for the maximum time. We may retain data longer where law, an audit, fraud prevention, litigation, or an unresolved IRS matter requires it, and may delete it sooner where lawful and no longer needed.

11. Your privacy choices and rights

Where applicable, you may ask to access, correct, obtain a copy of, delete, restrict, or object to processing of your information; withdraw consent; or appeal a denied request. You may also close your account and opt out of non-essential communications. We honor these rights worldwide where reasonably possible, subject to identity verification and exceptions for tax, CAA, accounting, security, legal, and filing records.

Send requests to support@certaitin.com. We generally respond within 30 days, or within the period required by your law. You may complain to your local data-protection or consumer-protection authority. We will not discriminate against you for exercising a right.

12. International processing

Certa is based in the United States and the case service is directed from the United States. If you submit information from another country, your information is transferred to and processed in the United States. A provider may also process limited information in another country as described in its service documentation and as permitted by law. Privacy protections and government-access rules may differ from those in your country.

Where applicable law requires a transfer mechanism, representative, or additional contractual safeguard, we will put it in place before intentionally offering the affected processing in that jurisdiction. A cross-border transfer of tax-return information is also subject to the separate restrictions described in section 4; this Notice does not authorize an otherwise restricted foreign disclosure.

Referral payout availability is separate from availability of Certa's applicant services. If you request a payout, your recipient and payout information may be processed in the United States and in countries used by the payout provider and its banking partners. Supported recipient countries, currencies, verification requirements, fees, and transfer times vary and may change. Certa does not represent that referral payouts are available worldwide.

13. U.S. financial privacy and safeguards

Tax-preparation firms may be financial institutions under the Gramm-Leach-Bliley Act and FTC rules. This Notice serves as Certa's initial privacy notice for the nonpublic personal information covered by those rules. We collect the categories described in section 2 and disclose them only for the service-provider, processing, legal, fraud-prevention, and other purposes described in section 6.

We do not currently disclose covered nonpublic personal information to nonaffiliated third parties in a way that gives rise to a federal financial-privacy opt-out right. If that practice changes, we will provide any required notice and opt-out before the disclosure. Federal financial-privacy rules do not relax the stricter restrictions that may apply to tax-return information.

Certa maintains a written information-security program proportionate to its size, systems, and sensitive records. This includes risk assessment, access management, encryption, provider oversight, monitoring, incident response, secure disposal, and periodic review.

14. Changes and contact

We may update this Policy as the Service, providers, or law changes. Material changes will be posted with a new effective date and communicated when appropriate. We will request renewed acknowledgement where required.

CERTA ITIN LLC
3205 Kyle Ave
Upper Marlboro, MD 20774, United States
Email: support@certaitin.com