Now filing 1095-B and 1095-C for ACA reporting.Learn more →
    Privacy Policy

    How Plain Dot collects, uses, and protects your information.

    Last updated: May 2026

    Introduction

    This Privacy Policy explains how Plain Dot, Inc. (Plain Dot, we, us, or our) collects, uses, discloses, and protects personal information when you visit https://www.plaindot.com (the Site), create an account, or use the Plain Dot platform, APIs, MCP server, and related services (together, the Services).

    This Policy applies to (a) visitors to our Site, (b) individuals who create accounts to use the Services on their own behalf or on behalf of a business, and (c) prospective customers who contact us. Section 5 explains how we handle information about your payees, employees, and other third parties whose information you submit to the Services on your own behalf — for that information, you are the controller and we act as your service provider or processor.

    1. Quick Summary

    If you don't want to read the whole thing, here are the basics:

    • We collect account details, the information you submit to use our Services (including tax-related information such as TINs and W-9 data), payment information, and standard technical and usage data.
    • We use it to provide the Services, transmit your filings to the IRS and state agencies, secure our systems, comply with law, and improve and develop our Services.
    • We do not sell your personal information. We do not share it for cross-context behavioral advertising.
    • We do not train foundation models for third parties on your identifiable data.
    • We share data with the service providers we use to run the Services, with the IRS and state agencies when you authorize us to transmit a filing, and where required by law.
    • You have rights to access, correct, delete, and (in some states) limit the use of your personal information. See Section 13.
    • Questions or requests? Email hello@plaindot.com.

    2. What This Policy Covers

    This Policy covers Personal Information, which means any information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. It includes information referred to as "personal information," "personal data," "personally identifiable information," or "sensitive personal information" under applicable privacy laws.

    This Policy does not cover:

    • the practices of third parties we do not own or control, including third-party websites you reach through links on our Site;
    • de-identified, aggregated, or anonymized information that cannot reasonably be linked to you; or
    • personal information that you submit to the Services about your payees, employees, contractors, customers, or other third parties on your own behalf — that information is governed by Section 5 and by your agreement with us (including our Data Processing Addendum, where applicable).

    3. Information We Collect

    We collect the following categories of Personal Information.

    3.1. Information you provide to us.

    • Account information — name, business name, work email, phone number, role/title, password (stored as a hashed value), and account preferences.
    • Tax and compliance information — taxpayer identification numbers (TINs, including SSNs and EINs), W-9 information, employer information, payee and recipient details, payment amounts, withholding information, ACA coverage details, excise-tax data, e-file authorizations (including Form 8879 and 8453 series), and other information you upload or generate in connection with a filing or match.
    • Payment information — billing address and the payment-card or bank-account reference token returned by our payment processor. We do not store full card numbers or bank account numbers on our systems.
    • Support and correspondence — the content of any messages, support tickets, calls, or other communications you send us.
    • Survey, research, and event information — responses you choose to provide.

    3.2. Information collected automatically.

    • Device and connection information — IP address, device identifiers, browser type and version, operating system, language, time zone, and referring URL. We log IP address and timestamps for filings submitted through the Services for IRS e-file authentication, audit-trail, and fraud-detection purposes as required or recommended by IRS authorized e-file Provider rules.
    • Usage information — pages and features you access, actions you take, requests you make to our APIs and MCP server, error logs, and performance metrics.
    • Cookies and similar technologies — described in Section 10.

    3.3. Information from third parties.

    • Identity verification and KYC providers that help us confirm who you are.
    • Government systems (such as the IRS TIN Matching Program) that return results from filings or matches you initiate.
    • Payment processors that confirm transactions or chargebacks.
    • Business contact data providers that help us with sales and marketing outreach.
    • Single sign-on providers if you use one to log in to the Services.

    3.4. Sensitive Personal Information. Some information we handle is treated as sensitive under applicable laws (for example, Social Security numbers and other government identifiers, financial account information, and account log-in credentials). We use Sensitive Personal Information only to provide the Services, to comply with law, and for the limited business purposes permitted by applicable privacy laws. We do not use Sensitive Personal Information to infer characteristics about you and we do not sell or share it for cross-context behavioral advertising.

    4. How We Use Information

    We use Personal Information to:

    • Provide and operate the Services, including creating and managing your account, processing your filings, performing TIN matches, transmitting authorized filings to the IRS, the SSA, and state agencies, and providing human-expert review where included in your plan;
    • Process payments and prevent fraud, chargebacks, and other abuse;
    • Communicate with you about your account, transactions, security alerts, support requests, product changes, and Service-related notices, and, where you have opted in or where the law permits, to send you marketing about Plain Dot;
    • Secure the Services, monitor for and investigate suspicious activity, identity fraud, and abuse, and enforce our agreements;
    • Comply with law, respond to legal process, and meet our regulatory, audit, and recordkeeping obligations, including those of the IRS, state taxing authorities, and other applicable regulators;
    • Improve, develop, and analyze the Services, including by performing analytics, debugging, internal research, and product development, and by training and evaluating AI models that we own and operate to power the Services (see Section 8); and
    • Conduct corporate transactions such as financings, audits, and mergers or acquisitions, subject to the limits in Section 7.

    We will not collect new categories of Personal Information, or use Personal Information for materially different purposes, without giving you notice and (where required by law) obtaining your consent.

    5. Payee and Third-Party Data

    When you use the Services to file 1099s, send W-9 requests, file ACA forms, run TIN matches, or otherwise transmit information about your payees, employees, contractors, customers, or other third parties, you are the controller or business with respect to that information. We process it as your service provider or processor on your instructions, only as needed to provide the Services to you and to comply with law.

    We will not sell or share that information, use it to build advertising profiles, combine it with information from other customers in a way that would identify the individuals, or use it for our own independent business purposes other than as permitted under applicable privacy laws (for example, to operate, secure, and improve the Services and to comply with law). Our Data Processing Addendum sets out the full processor-side terms, including subprocessor obligations.

    If you are a payee, employee, contractor, or other individual whose information has been submitted to the Services by a Plain Dot customer and you want to exercise privacy rights, please contact that customer first. We will support them in responding to your request.

    6. QuickBooks (Intuit) Data

    If you choose to connect your QuickBooks account, we access the following information through Intuit's API:

    • Vendor and contractor records — names, addresses, and Tax Identification Numbers (TINs);
    • Payment totals — amounts paid to each vendor or contractor during the tax year; and
    • General-ledger categories — account classifications needed to identify 1099-reportable payments.

    This access is read-only. We do not write data back to your QuickBooks account.

    Purpose. We use QuickBooks data solely for the functional purpose of preparing and filing your information returns inside Plain Dot. We do not use it for any other purpose.

    No third-party access and no resale. We do not provide third parties with access to your QuickBooks data, and we do not export, save, or store it for any purpose other than operating the Services for you. This is consistent with our general commitment that we do not sell Personal Information.

    Your consent. Connecting QuickBooks is optional and initiated by you. By connecting, you authorize this access. You can withdraw that authorization at any time.

    Disconnecting. You can disconnect any QuickBooks company inside Plain Dot at any time from the QuickBooks connections screen, which revokes our access to that company's data.

    Retention. Imported QuickBooks-derived data is retained according to our general retention terms (see Section 11) and is removed or de-identified when it is no longer needed to provide the Services or to comply with legal obligations.

    7. How We Disclose Information

    We disclose Personal Information only as described in this Policy.

    • Service providers and subprocessors. We use trusted vendors to host and operate our infrastructure, send emails and notifications, process payments, perform identity verification and fraud screening, provide analytics and error monitoring, and provide customer support and security services. They are bound by contract to handle Personal Information only on our instructions, to keep it confidential and secure, and not to use it for their own purposes.
    • Government agencies. When you authorize us to transmit a filing or perform a match, we send the minimum information required to the relevant authority (for example, the IRS through IRIS or FIRE, the SSA, the IRS Affordable Care Act Information Returns system, or a state taxing authority). We do not share Personal Information with government agencies for any purpose other than to fulfill your compliance request or to comply with law.
    • Professional advisers and auditors such as legal counsel, accountants, and security auditors who are bound by professional or contractual confidentiality obligations.
    • Legal and safety. We may disclose Personal Information to comply with applicable law, regulation, legal process, or government request; to respond to lawful requests by public authorities, including for national security or law enforcement; to protect our rights, property, or safety, or the rights, property, or safety of our customers or others; and to detect, investigate, and prevent fraud, security incidents, or other illegal activity.
    • Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, Personal Information may be transferred to the counterparty, subject to confidentiality protections and continued application of this Policy (or notice of any material change).
    • With your direction or consent. We will share Personal Information with other third parties when you direct or permit us to (for example, when you connect a third-party integration to your account).

    We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising, in each case as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and similar state laws.

    8. AI Features

    The Services use artificial intelligence to assist with classifying, extracting, validating, drafting, and routing compliance work.

    • No training of foundation models for third parties. We do not use identifiable Customer Data or Personal Information you submit to the Services to train foundation models for any third party.
    • Our own models. We may use Personal Information to train, evaluate, and improve AI models that we own and operate to power the Services. Where feasible, we de-identify or aggregate data before using it to train or evaluate models. You can ask us not to use your data for these purposes by contacting hello@plaindot.com.
    • Human review available. AI Outputs may be incomplete, incorrect, or non-deterministic. You can request human review of any AI-driven decision that has a significant effect on you or your filings by contacting hello@plaindot.com. In jurisdictions where the law gives you a right not to be subject to solely automated decision-making with legal or similarly significant effects (such as under the GDPR or the California ADMT regulations), we will honor that right as required.
    • Subprocessor AI providers. Where we use third-party AI infrastructure providers to operate the Services, we contractually prohibit them from using your data to train their own models or for any purpose other than providing services to us.

    9. How We Protect Information

    We maintain administrative, technical, and physical safeguards designed to protect Personal Information from loss, misuse, unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption of Personal Information in transit and at rest, role-based access controls, least-privilege provisioning, logging and monitoring, secure software-development practices, regular vulnerability testing, vendor risk management, and an incident-response program.

    Where we handle Federal Tax Information (FTI) or other information subject to additional regulatory safeguards (for example, under IRS Publication 1075, IRS Publication 1345 for authorized e-file Providers, or the FTC Safeguards Rule under the Gramm-Leach-Bliley Act, in each case as applicable), we maintain controls aligned with those requirements.

    No system is perfectly secure. You play an important role in protecting your information — choose a strong, unique password, enable multi-factor authentication where available, and tell us right away if you suspect unauthorized access to your account.

    In the event of a data breach involving your Personal Information, we will notify you and applicable regulators where and as required by law (including state breach-notification statutes and, where applicable to FTI, the notification requirements of IRS Publication 1075).

    10. Cookies and Tracking

    We use cookies and similar technologies (pixels, tags, local storage) for purposes that include:

    • Strictly necessary — keeping you signed in, maintaining session state, and providing core Site features.
    • Functional — remembering your preferences (language, region, layout).
    • Analytics — understanding how the Site and Services are used so we can improve them.
    • Security — detecting and preventing fraud and abuse.

    We do not use cookies for cross-context behavioral advertising.

    You can control cookies through your browser settings and through any cookie preference center we make available on the Site. Because cookie standards continue to evolve, our Services may not currently respond to all browser Do Not Track signals; we do, however, recognize Global Privacy Control (GPC) signals as an opt-out of "sale" and "sharing" where required by state law.

    11. Data Retention

    We keep Personal Information for as long as we need it for the purposes described in this Policy. In general:

    • Account information — for the life of your account, plus a reasonable period after closure to handle billing, support, and legal matters.
    • Tax filing records (filed forms, transmittal receipts, e-file authorizations) — generally at least four (4) years from the date the filing was made or the tax was due, whichever is later, consistent with IRS recordkeeping rules under Treasury Regulation § 1.6001-1 and § 1.6107-1 and applicable state-law requirements.
    • TIN matching results — retained only as long as needed to deliver the match to you and to support audit and dispute resolution, consistent with the IRS TIN Matching Program rules. We do not use TIN match results for any secondary purpose.
    • Payment records — for the period required by tax, accounting, and audit obligations (typically seven (7) years).
    • Support and correspondence — for a reasonable period to support ongoing service and dispute resolution.
    • Logs and security data — for the period needed to maintain the integrity and security of the Services, typically not more than two (2) years in active systems.

    We may retain Personal Information for longer where required by law, regulation, court order, or legal process, or where reasonably necessary to establish, exercise, or defend legal claims. We may retain de-identified or aggregated data indefinitely.

    12. International Data Transfers

    Our primary operations are in the United States, and we process Personal Information in the United States.

    If we transfer Personal Information from the European Economic Area, the United Kingdom, or Switzerland to the United States or another country, we rely on appropriate transfer mechanisms recognized under applicable law — for example, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss-U.S. Data Privacy Framework, or the equivalent — together with supplementary measures where needed. By using the Services from outside the United States, you acknowledge that your information may be processed in the United States and other jurisdictions whose data-protection laws may differ from those in your country.

    13. Your Privacy Rights

    Depending on where you live, you may have some or all of the following rights with respect to your Personal Information:

    • Access — request a copy of the Personal Information we hold about you.
    • Correction — ask us to correct inaccurate Personal Information.
    • Deletion — ask us to delete your Personal Information, subject to legal exceptions (including our obligation to retain certain tax filings under Section 11).
    • Portability — request a copy in a portable format.
    • Restriction or objection — ask us to limit or object to certain processing.
    • Withdraw consent — withdraw any consent you have given (without affecting prior lawful processing).
    • Opt out of sale/sharing or targeted advertising — although we do not engage in these activities.
    • Opt out of profiling or automated decision-making producing legal or similarly significant effects, where applicable.
    • Limit the use of Sensitive Personal Information — where applicable.
    • Non-discrimination — we will not deny services, charge different prices, or provide a different level or quality of service because you exercised a privacy right.

    To exercise any of these rights, email hello@plaindot.com. We will respond within the time required by applicable law (generally 45 days under US state privacy laws and one month under the GDPR, subject to extension). We may need to verify your identity before fulfilling your request and may decline a request where the law allows.

    You may also designate an authorized agent to make a request on your behalf where state law permits. We may require written authorization from you and verification of your identity before acting on the agent's request.

    12.1. California (CCPA/CPRA). In addition to the rights above, California residents may request the categories and specific pieces of Personal Information we have collected; the categories of sources; the business or commercial purposes for collecting or sharing it; and the categories of third parties to whom we disclose it. Categories collected in the past 12 months are described in Section 3; purposes are described in Section 4; recipients are described in Section 7. We do not knowingly sell or share for cross-context behavioral advertising the Personal Information of any consumer, including any consumer under 16.

    You may also request a list of third parties to whom we have disclosed Personal Information for their direct marketing purposes under California Civil Code §§ 1798.83–1798.84 ("Shine the Light"). Note that we do not engage in such disclosures.

    12.2. Other US states. If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, Indiana, Kentucky, Maryland, Minnesota, Rhode Island, Nebraska, or another state with a comprehensive privacy law, you have the rights described above as provided by your state's law. Submit requests to hello@plaindot.com. If we deny your request, you may appeal by replying to our response; we will respond within the time required by your state's law.

    12.3. Nevada. Nevada residents may direct us not to "sell" certain Personal Information as defined under NRS 603A. We do not currently sell Personal Information as defined under that statute.

    12.4. EEA/UK/Switzerland. If you are in the EEA, the UK, or Switzerland and the GDPR or equivalent law applies, you have the rights described above. Our lawful bases for processing include performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the Services, and (where applicable) your consent. You may lodge a complaint with your local supervisory authority.

    13. Children

    The Services are not directed to children and we do not knowingly collect Personal Information from anyone under 16. If you believe a child has provided us with Personal Information, contact us at hello@plaindot.com and we will delete it.

    14. Third-Party Sites and Integrations

    The Site and Services may contain links to third-party websites, or you may connect third-party integrations, AI agents, or MCP clients to your account. We are not responsible for the privacy practices or content of those third parties, and this Policy does not apply to them. Review their privacy policies before providing them with Personal Information.

    15. Changes to This Policy

    We may update this Policy from time to time. If we make a material change, we will give you reasonable advance notice (for example, by email, an in-product notice, or a prominent notice on the Site). The "Last updated" date at the top tells you when this Policy was last revised. Your continued use of the Services after the effective date of the change means you accept the updated Policy.

    16. Contact Us

    If you have questions about this Policy or our privacy practices, or to exercise any privacy rights, contact us at:

    If you are not satisfied with our response, you may have the right to lodge a complaint with the data-protection authority where you live or work.