Privacy policy
Draft, pending review by counsel
Last updated 2026-09-15
What this covers
This policy describes the information the Churro service collects from the people who use it and about the employees of the companies it tracks, why it is collected, how long it is kept, and who can see it.
Information about you
- Your work email address, used to sign you in by emailed link and to send the notices you choose.
- Your display name and time zone, if you set them.
- A record of what you did in the service: an audit event for each change you make, kept so your organisation can show who did what.
Information about a company and its employees
The service holds only what is needed to decide which compliance obligations apply and when: the states and cities where a company has employees, headcounts, benefit plan details, federal contract status, and for each employee the work location, hire and termination dates, scheduled hours, worker classification and benefits eligibility. Legal names are stored encrypted with a key held by the application.
The service does not collect Social Security numbers, dates of birth, home addresses, bank details or pay rates.
Where it comes from
- Answers you give in the onboarding questionnaire.
- Rosters you import from a spreadsheet.
- A payroll system you connect, through an integration you authorise and can disconnect at any time.
Who processes it
The service runs on hosting, database, background-job, email and payment providers acting on our instructions. A current list of these subprocessors and what each handles is on the security page. A model used to read public legal sources never receives customer data.
How long it is kept
Obligations, evidence and the audit trail are kept for as long as the account exists, because they are the record the account exists to keep. Operational logs of background jobs and notification deliveries are removed after two years; processed queue entries and expired invitations after ninety days.
Your choices
- Change which notices you receive, or unsubscribe from a digest by the link in the email, without signing in.
- Disconnect a payroll integration; the stored access token is deleted.
- Ask your account owner to remove your membership; your audit events remain as part of the account’s record.
- Ask us to delete an account by writing to support@usechurro.com; deletion is a manual procedure with a thirty-day grace period while the self-serve flow is built.
Not legal advice
Information the service shows about compliance obligations is provided for general informational purposes only and does not constitute legal advice. Consult qualified counsel about your specific circumstances.
Contact
Questions about this policy, or a request about your data, go to support@usechurro.com.