Sefro — Privacy Policy

Last updated: July 4, 2026
Draft template intended to reflect how the Service actually handles data. It is not legal advice — have a licensed attorney review and adapt it for your jurisdiction and obligations (including CCPA/CPRA and GDPR where applicable) before publishing.

This Privacy Policy explains how Call The IT Dude LLC, doing business as Sefro ("Sefro", "we", "us"), collects, uses, and shares information in connection with the Sefro sales tax rate and calculation API and website (the "Service").

1. Information we collect

CategoryExamplesWhy
Account & billingEmail address; subscription and payment status. Card details are entered directly with Stripe and are never received or stored by Sefro.Create your account, issue API keys, manage billing.
API usageAPI key identifier, request counts, timestamps, request ID, IP address, endpoint and status.Authentication, rate limiting, security, and support/troubleshooting.
Calculation inputsAddresses/ZIP codes, amounts, and line items you send to /calculate, retained as a calculation history for your account.Return results and give you an auditable history of your own calculations.
Exemption certificatesBuyer name, buyer email, buyer EIN, exempt states/categories that you choose to store.Apply exemptions you configure. This data is provided and controlled by you.

We do not sell personal information, and we do not use your calculation inputs or stored certificates to build a competing dataset.

2. How we use information

To provide and secure the Service, authenticate requests, enforce plan limits, process payments, respond to support requests, comply with law, and detect or prevent fraud and abuse. We do not use your data for advertising.

3. Subprocessors

We share information with a small set of service providers who process it on our behalf under contract:

ProviderPurposeData
RailwayApplication hosting and managed PostgreSQL database (US region).All Service data at rest.
StripePayment processing and subscription billing.Billing email, payment method (held by Stripe), subscription status.

A current subprocessor list is available on request; we will update this page when it changes.

4. Data location and retention

Service data is stored in the United States. We retain data as follows, and prune on a schedule: calculation history for approximately 24 months; billing records for as long as required for tax and accounting purposes; API usage/audit logs for a limited period for security. Exemption certificates persist until you delete them. You may request deletion of your account data as described below.

5. Security

API keys are stored only as salted hashes, never in plaintext. Traffic is served over HTTPS/TLS. Access to production systems is restricted. Payment card data is handled entirely by Stripe. See our security disclosure policy for reporting vulnerabilities. No method of transmission or storage is 100% secure.

6. Your rights

Depending on your location, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. Because much of the data in the Service (certificates, calculation inputs) is data you control as the business customer, you can view, update, and delete most of it through the API. For other requests, contact us at the address below and we will respond within the time required by applicable law.

7. Data processing for business customers

Where you use the Service to process personal information of your own customers (for example, buyer details on exemption certificates), you are the controller and Sefro is a processor acting on your instructions. A Data Processing Addendum is available on request.

8. Children

The Service is a business product and is not directed to children under 16, and we do not knowingly collect their personal information.

9. Changes

We may update this Policy; material changes will be posted here with a new date.

10. Contact

Privacy questions or requests: [email protected].

← Back to Sefro