Privacy Policy
How Handler Labs LLC ("we") collects, uses, shares, and protects information when you use Certiwage. This policy is anchored to the laws cited throughout.
Last updated July 18, 2026
Effective date: July 18, 2026. This Privacy Policy explains how Handler Labs LLC ("Certiwage," "we," "us") handles information in connection with the Certiwage website and application (the "Service"). It forms part of, and is governed by, our Terms of Service.
Overview & our two roles
Certiwage helps small subcontractors prepare the federal Form WH-347 (Certified Payroll Report) and its Statement of Compliance. Because of how the Service works, we handle information in two distinct roles:
- As a business (controller) for the account information we collect for ourselves — your email, name, and billing relationship.
- As a service provider / processorfor the payroll information you enter about your company and workers. That data belongs to you (or your employer-client); we process it on your behalf and under your instructions to generate your reports, and we do not use it for our own purposes. (See Cal. Civ. Code § 1798.140(ag); GDPR Art. 28.)
Information we collect
| Category | Examples | Our role |
|---|---|---|
| Identifiers / account data | Email address, name, password (hashed), account ID | Controller |
| Company & project data | Company name, address, project name/location, contract and wage-determination numbers | Processor |
| Worker & payroll data | Worker names, the last four digits of each worker's SSN, work classifications, hours, wage and fringe rates, deductions, net pay | Processor |
| Billing data | Stripe customer and subscription identifiers, plan, billing status (card numbers are handled by Stripe, not stored by us) | Controller |
| Technical / usage data | IP address, device/browser type, pages viewed, and similar log data used for security and reliability | Controller |
We collect only what is reasonably necessary and proportionate to provide the Service (Cal. Civ. Code § 1798.100(c)).
Where it comes from
We collect information from:
- You — when you create an account, set up your company/projects/employees, enter weekly payroll, and contact support.
- Your devices — technical and usage data collected automatically when you use the Service.
- Our service providers — for example, billing status from Stripe.
How we use information
We use information for these purposes (and, where a legal basis is required, on the bases noted):
- To provide the Service — generate your WH-347 and Statement of Compliance, run the fringe check, and store your history (basis: performance of a contract, GDPR Art. 6(1)(b)).
- To process billing through Stripe and manage your subscription (basis: contract).
- To send transactional messages — sign-in links, confirmations, and receipts (basis: contract).
- To send product messages such as missing-week reminders, which you can opt out of at any time (basis: legitimate interests, GDPR Art. 6(1)(f)).
- To secure, maintain, and improve the Service and prevent abuse (basis: legitimate interests / legal obligation).
How we share information
We share information only as described here. We engage the following service providers / subprocessorsunder written contracts that limit their use of the information to providing services to us and require them to protect it (Cal. Civ. Code § 1798.100(d)):
- Supabase — database, authentication, and hosting. Your data is isolated per account with row-level security.
- Stripe — payment processing. Stripe collects and handles your payment-card details directly; we do not receive or store full card numbers.
- Hosting / content delivery (Vercel, Cloudflare) — to serve the site and app.
- Vercel Analytics — privacy-friendly, cookieless page analytics (aggregate page views and country-level location; no cross-site tracking and no advertising use).
We may also disclose information: to comply with law or valid legal process; to protect our rights, users, or the public; and in connection with a merger, acquisition, or sale of assets (with notice as required).
We do not sell your information or share it for advertising
We do not sell personal information for money or other valuable consideration, and we do not shareit for cross-context behavioral advertising, as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah). Our disclosures to the service providers above are not "sales" or "shares."
Cookies & Do Not Track
We use strictly necessary cookies and similar technologies to keep you signed in, remember your theme preference, and secure the Service. We do not use third-party advertising cookies. We measure site usage with Vercel Analytics, which is cookieless — it reports aggregate page views without setting cookies, storing device identifiers, or tracking you across other websites.
Do Not Track (Cal. Bus. & Prof. Code § 22575(b)(5)): Because there is no common industry standard for Do Not Track signals, the Service does not currently respond differently to them. We also do not permit third parties to collect personal information about your online activities over time and across different websites when you use the Service.
Worker Social Security numbers
Consistent with U.S. Department of Labor guidance for Form WH-347, we collect and store only the last four digitsof a worker's Social Security number — the "individual identifying number" that appears on the form. We never ask for or store full Social Security numbers. We transmit and store this data over encrypted connections, consistent with California Civil Code § 1798.85, which restricts the public display, insecure transmission, and sale of SSNs.
Data retention
We retain account and payroll data for as long as your account is active and as needed to provide the Service, and afterward as required to comply with legal obligations, resolve disputes, and enforce our agreements (Cal. Civ. Code § 1798.100(a)(3)). Certified-payroll records often must be kept for several years under Davis-Bacon recordkeeping rules; you are responsible for your own retention obligations. You may delete your data at any time in the app, or request account deletion (see Your privacy rights).
How we protect data
We use reasonable administrative, technical, and organizational safeguards (Cal. Civ. Code § 1798.100(e)), including encrypted transport (TLS), row-level security isolating each account's data, scoped access, and data minimization (for example, last-4 SSNs only). Payment-card data is handled by Stripe under the PCI-DSS standard (Stripe hosts the card-entry fields, so card numbers never reach our servers). No method of transmission or storage is perfectly secure, but we design the Service to store the minimum necessary and to isolate customer data.
Your privacy rights
Depending on where you live, you may have some or all of the following rights. We honor these requests regardless of your state where practicable, and we will not discriminate against you for exercising them (Cal. Civ. Code § 1798.125).
| Right | What it means |
|---|---|
| Know / access | Ask what personal information we have collected, the sources, purposes, and third parties, and the specific pieces (Cal. Civ. Code §§ 1798.110, 1798.115; Va. Code § 59.1-577). |
| Delete | Ask us to delete personal information we collected from you (§ 1798.105), subject to legal exceptions. |
| Correct | Ask us to correct inaccurate personal information (§ 1798.106). |
| Portability | Obtain a portable copy of data you provided (state privacy laws). |
| Opt out of sale/sharing | Direct us not to sell or share your personal information (§ 1798.120) — though we do neither. |
| Limit sensitive PI | Limit use of sensitive personal information to what is necessary to provide the Service (§ 1798.121). |
| Appeal | Appeal a denied request where your state provides for it (e.g., Va. Code § 59.1-578; C.R.S. § 6-1-1306). |
How to exercise your rights (at least two methods): email us at privacy@certiwage.com, or contact support@certiwage.com. You may use an authorized agent to submit a request on your behalf; we may need to verify your identity and the agent's authority. We aim to respond within the time your state law requires (typically 45 days).
Because much of the payroll data in the Service belongs to a business customer (the employer), if your information appears in a customer's account, we will refer your request to that customer as the controller and assist them as their service provider.
California disclosures (CCPA/CPRA)
This section provides the specific disclosures required by Cal. Civ. Code § 1798.130(a)(5). In the preceding 12 months:
- Categories collected: identifiers, customer records/commercial information (billing), internet/network activity (usage), and the company/worker/payroll data described above.
- Sources: you, your devices, and our service providers.
- Business/commercial purposes: to provide, secure, bill for, and support the Service (as described in How we use information).
- Categories disclosed for a business purpose: account and billing identifiers disclosed to the service providers listed above.
- Categories sold or shared: none. We do not sell or share personal information.
- Sensitive personal information: we do not collect full SSNs; we use any information we hold only as necessary to provide the Service and do not use or disclose it for purposes requiring a "limit" right.
We review and update this policy at least once every 12 months, as required by § 1798.130(a)(5). If we act as a business subject to the CCPA thresholds in Cal. Civ. Code § 1798.140(d), these rights apply in full; we honor them as a matter of practice regardless.
Data breach notification
If a breach of the security of the system affecting personal information occurs, we will notify affected individuals and our business customers (as data owner) without undue delay and consistent with applicable law. For California residents, we will provide notice within the timeframe required by Cal. Civ. Code § 1798.82 (currently 30 calendar days of discovery or notification). Every U.S. state has its own breach-notification law; we comply with those that apply.
Children's privacy
The Service is a business tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13 (see the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506). If we learn that we have collected such information, we will delete it. Contact us if you believe a child has provided us information.
International users
The Service is intended for use in the United States. If you access it from the European Economic Area or the United Kingdom, note that we process personal data on the lawful bases of contract and legitimate interests (GDPR Art. 6(1)(b), (f)); you have the rights in GDPR Arts. 15–22; and any transfer of EEA/UK personal data would be made under appropriate safeguards such as the European Commission's Standard Contractual Clauses (GDPR Art. 46). We will use processors bound by GDPR Art. 28 terms for any such data.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Effective date" above and notify you by a notice on the Service or by email before the changes take effect (Cal. Bus. & Prof. Code § 22575(b)(3)). Your continued use after the effective date means you accept the updated policy.
Contact us
Questions or privacy requests? Email privacy@certiwage.com or support@certiwage.com, or write to Handler Labs LLC, 5510 NW 38th Terrace, Coconut Creek, FL 33073.