1. What we collect
- Account information — your name, email address, company name, and a hashed password (we cannot see the password itself).
- Customer Data you enter — your org structure and the employee information you choose to store: names, employee IDs, positions, compensation records, and uploaded payroll figures, plus the SOP documents you create. You control all of it.
- Billing information — handled by Stripe, our payment processor. Card numbers go directly to Stripe and never touch our servers; we see only the subscription status and invoice history.
- Operational data — standard server logs (IP address, browser type, timestamps) and in-app audit records of changes made in your account, kept for security and support.
We do not use advertising trackers. The only cookie we set is the session cookie that keeps you signed in.
2. How we use it
- To provide, secure, and support the Service.
- To process payments and send transactional email (verification, password resets, billing notices).
- To generate AI drafts you request: the SOP text involved is sent to our AI infrastructure provider — a major U.S. provider under terms that prohibit using your content to train their models — solely to produce your draft.
- To understand aggregate product usage (counts and totals, not the content of your data).
We do not sell your data. We do not share it with advertisers. We do not train AI models on it.
3. Who processes it for us
The Service runs on established infrastructure providers acting on our instructions: Vercel (application hosting), Neon (database hosting), Stripe (payments), Resend (transactional email), and our AI infrastructure provider (AI drafting you request). Each receives only what its role requires.
4. Employee information
Your company decides what employee information to store in PayTree and is responsible for having the right to store it. Within your account, compensation data is visible only to your admin logins and — scoped to their own branch — to the manager logins you invite. If one of your employees asks us directly about their data, we will refer them to you, since you control the account.
5. Security
- All traffic is encrypted in transit (HTTPS/TLS); data is encrypted at rest by our hosting providers.
- Every customer's data is isolated per company and every request is checked server-side against your company and role.
- Passwords are stored only as salted hashes; session tokens are signed and expire.
No system is perfectly secure; if a breach affects your data we will notify you without undue delay.
6. Retention and deletion
We keep your data while your account is active and for at least 60 days after a subscription ends (so you can return or export). You can export a full backup in-app at any time, and you can request deletion of your account and data at info@paytreesolutions.com — we honor such requests within 30 days, after which residual copies age out of routine backups.
7. Children
The Service is for businesses and is not directed at children under 16; we do not knowingly collect their information.
8. Changes
If we materially change this policy we will notify you in-app or by email before the change takes effect.
9. Contact
Privacy questions or requests: info@paytreesolutions.com. See also the Terms of Service.