Privacy Policy for einforllc.co
einforllc.co is a private LLC EIN filing service operated at 1209 Orange Street, Wilmington, DE 19801. This policy describes the personal data we collect on Form SS-4 to obtain your EIN, how it is stored, and the 3 vendors (Stripe for payments, Postmark for mail, and a US-based tax preparer of record) who see it. The policy was last updated on 2026-07-28 and applies to every visitor and every buyer of a $97 EIN order or$127 EIN Fast order.
What data do we collect from you?
We collect only the fields the IRS requires on Form SS-4 lines 1 through 18: legal LLC name, mailing address, responsible party name and SSN or ITIN (or ITIN application data for non-US owners), number of members, and the tax classification you elect. We also store your email, order total, and the 4 last digits of your card, which Stripe returns. We do not collect a Social Security number for anyone other than the responsible party.
How long do we keep your data?
We retain your Form SS-4 image and CP-575 letter for 7 years, matching the IRS record-retention rule at IRM 25.7.4. Payment metadata (last 4 digits, order ID, amount) is retained for 10 years to satisfy PCI-DSS 3.2.1 section 3.1 and Delaware corporate tax records. After the retention window expires we shred the SS-4 image and delete the record from our database within 30 days.
Who has access to your SS-4?
Exactly 3 external processors see the SS-4: (1) Stripe, which sees only card and email, never the SSN; (2) Postmark, our transactional email vendor, which sees only the confirmation email body; (3) our US-based Enrolled Agent of record, who sees the full SS-4 to file it with the IRS. Internally, only the 2-person filing team can read a full SS-4, and all access is logged for 24 months.
Do we share your data with the IRS?
Yes, that is the point of the service. We fax, mail, or (for eligible responsible parties with an SSN) file your SS-4 electronically to the IRS Cincinnati service center at PO Box 145600, which issues the EIN and returns the CP-575 confirmation letter within 16 to 19 business days on Standard, or 6 to 8 on Fast. We do not share your data with any other government agency and do not sell any personal data.
How do we secure the data?
All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Servers are hosted in AWS us-east-1 under a signed BAA-equivalent DPA. Access requires 2-factor authentication and a hardware security key for the 2 principals. We run an annual SOC 2 Type II readiness review and patch dependencies within 14 days of a published CVE with a CVSS score of 7.0 or higher.
What rights do you have?
You may request access, correction, or deletion of your data by emailing privacy@einforllc.co. We respond within 30 days as required by CCPA section 1798.130 and, for EU residents, GDPR Article 15. Deletion requests during the 7-year IRS retention window are honored to the extent US federal record-keeping law allows; we will delete non-required fields (marketing email, phone) immediately.
Do we use cookies?
We use 3 cookies: a session cookie (30-minute expiry) for checkout, a Stripe payment cookie for fraud scoring (session only), and a first-party analytics cookie that expires after 400 days. We do not run Facebook, TikTok, or Google Ads retargeting pixels. Blocking cookies will not prevent your order from completing.
Do we serve children under 18?
No. An LLC responsible party must be at least 18 years old under IRS Publication 1635 and every US state's LLC act. We do not knowingly collect data from anyone under 18. If we learn we have collected such data we will delete it within 7 days.
How do you contact us?
Email privacy@einforllc.co for privacy questions, or write to Privacy Office, einforllc.co, 1209 Orange Street, Wilmington, DE 19801. For the general contact channel see the contact page. This policy was last revised on 2026-07-28 and supersedes all prior versions.