This Privacy Policy explains how Call The IT Dude LLC, doing business as Sefro ("Sefro", "we", "us"), collects, uses, and shares information in connection with the Sefro sales tax rate and calculation API and website (the "Service").
| Category | Examples | Why |
|---|---|---|
| Account & billing | Email address; subscription and payment status. Card details are entered directly with Stripe and are never received or stored by Sefro. | Create your account, issue API keys, manage billing. |
| API usage | API key identifier, request counts, timestamps, request ID, IP address, endpoint and status. | Authentication, rate limiting, security, and support/troubleshooting. |
| Calculation inputs | Addresses/ZIP codes, amounts, and line items you send to /calculate, retained as a calculation history for your account. | Return results and give you an auditable history of your own calculations. |
| Exemption certificates | Buyer name, buyer email, buyer EIN, exempt states/categories that you choose to store. | Apply exemptions you configure. This data is provided and controlled by you. |
We do not sell personal information, and we do not use your calculation inputs or stored certificates to build a competing dataset.
To provide and secure the Service, authenticate requests, enforce plan limits, process payments, respond to support requests, comply with law, and detect or prevent fraud and abuse. We do not use your data for advertising.
We share information with a small set of service providers who process it on our behalf under contract:
| Provider | Purpose | Data |
|---|---|---|
| Railway | Application hosting and managed PostgreSQL database (US region). | All Service data at rest. |
| Stripe | Payment processing and subscription billing. | Billing email, payment method (held by Stripe), subscription status. |
A current subprocessor list is available on request; we will update this page when it changes.
Service data is stored in the United States. We retain data as follows, and prune on a schedule: calculation history for approximately 24 months; billing records for as long as required for tax and accounting purposes; API usage/audit logs for a limited period for security. Exemption certificates persist until you delete them. You may request deletion of your account data as described below.
API keys are stored only as salted hashes, never in plaintext. Traffic is served over HTTPS/TLS. Access to production systems is restricted. Payment card data is handled entirely by Stripe. See our security disclosure policy for reporting vulnerabilities. No method of transmission or storage is 100% secure.
Depending on your location, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. Because much of the data in the Service (certificates, calculation inputs) is data you control as the business customer, you can view, update, and delete most of it through the API. For other requests, contact us at the address below and we will respond within the time required by applicable law.
Where you use the Service to process personal information of your own customers (for example, buyer details on exemption certificates), you are the controller and Sefro is a processor acting on your instructions. A Data Processing Addendum is available on request.
The Service is a business product and is not directed to children under 16, and we do not knowingly collect their personal information.
We may update this Policy; material changes will be posted here with a new date.
Privacy questions or requests: [email protected].
← Back to Sefro