UR Founders
Back to Home

Privacy Policy

Content reviewed/revised:

Scope of this notice

This Privacy Notice provides factual information about current information practices and is not legal advice. It is reviewed public information, not a certification or a promise beyond the service described. Rights and responsibilities depend on the service used and applicable law.

1. Information the application may collect

The information collected depends on the account, formation, payment, support, and optional feature that you use. It may include the following categories:

  • Account and authentication data: name, email, contact details, credential or password hashes, opaque session-token hashes, session times, IP address, user-agent and related security records.
  • Identity and tax data: identity details and SSN or ITIN information when a requested formation or tax workflow collects it. The application does not claim that every user is asked for every field.
  • Ownership and formation data: company, address, business and formation details, and information about members, directors, officers, shareholders or other owners when the selected workflow requires it.
  • Documents: formation and supporting documents, document metadata, and identity uploads when a requested formation, signature, banking or review path asks for them.
  • Payment and acceptance evidence: Stripe customer, payment, Checkout and webhook identifiers; amount and status; and, when a payment flow records them, the typed name, terms version and hash, acceptance time, IP address, browser information, receipt, and audit or dispute evidence.
  • Messages and assistance: support requests, chat or support messages, and information submitted for an AI review or support feature when that feature is used.
  • Technical and usage data: cookies, session activity, operational logs, error data and, when enabled, analytics data.

2. How information is used

We use information to provide and secure accounts, run requested formation or compliance workflows, prepare or coordinate documents, process and reconcile payments, communicate service status, respond to support, investigate abuse or errors, maintain audit evidence, and meet applicable legal or accounting obligations.

An AI provider receives information only when you use an enabled AI review or support feature. The information handled depends on the feature and your request.

3. Storage and conditional recipients

The application uses a database and, when needed for a service, document or object storage.

Information can be disclosed to the following categories only when the relevant feature or transaction uses the path:

  • Stripe for a payment or payment reconciliation; the application receives transaction identifiers and status, while payment details are entered through Stripe's hosted flow as described by the accepted payment terms.
  • Resend when the application sends an email, and doola when a requested company-formation handoff or related filing path uses it.
  • Google as an identity provider when you choose Google sign-in; this optional sign-in flow uses Google's authentication service.
  • Anthropic, OpenAI or xAI when an enabled AI review or support feature actually invokes that provider.
  • PostHog or Sentry when analytics or error reporting is enabled.
  • A signature provider or banking partner only when you request the corresponding supported signature or banking flow.
  • Government agencies, filing services, professional reviewers or other recipients required by the requested formation or compliance task. The specific recipient depends on the request and its status.

4. Security

Selected sensitive fields are encrypted before storage. This protection applies to those fields only; it does not mean that every database record, backup, uploaded document, or stored file is encrypted in the same way. Access through some service paths is recorded for audit purposes, but audit coverage depends on the access path and not every read is logged in the same way.

Security measures depend on the information and service involved. A requested workflow may involve passports, identity uploads, or banking information; the workflow and its providers determine what is collected and stored.

5. Retention

Information may be retained for the account and requested service, operational needs, security and fraud prevention, payment and accounting records, audit evidence, dispute handling, backups, and legal obligations. Deletion may be limited when a record is needed for one of these purposes or a provider or government process controls it.

Retention depends on the type of information, why it is needed, and applicable requirements.

6. Cookies and similar storage

The application uses necessary cookies or similar browser storage for authentication, session continuity, security and selected preferences. Disabling them can prevent sign-in or other functionality. Analytics or error-reporting storage may be used when the relevant feature is enabled.

7. Privacy requests and statutory rights

Depending on where you live and the applicable law, you may have rights such as access, correction, deletion, portability, objection, restriction, or withdrawal of a consent where consent is the basis. Eligibility, exceptions, response timing, identity verification, and appeal rights depend on the applicable law.

Use the Help Center route below to make a request. We may need enough information to verify the requester and locate the account or record. A request does not automatically erase records that must be kept for security, payment, audit, dispute, government or legal reasons.

8. International processing

Some service providers may process information in countries other than the country where you use the service. This can happen when you use a feature handled by such a provider. The applicable provider terms and laws govern that processing.

9. Contact and requests

Use the UR Founders Help Center for privacy questions or a rights request. The Help Center is the contact route for these requests.

Open the Help Center