EntityStack

EntityStack Privacy Statement

Effective Date:
September 1, 2026
Last Updated:
September 8, 2026

1. Introduction and Scope

EntityStack, LLC, an Ohio Limited Liability Company with its principal place of business at P.O. Box 61, Powell, Ohio 43065 ("EntityStack," "we," "us," or "our"), provides a software-as-a-service platform that enables law and CPA firms, corporations and other professional service organizations ("Firms") and their authorized personnel ("Users") to capture and create information related corporate entity diagrams displaying corporate and business entities, including corporate names, states filed, tax identification numbers and percent ownership between the various corporate entities (the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard information in connection with the Service and our website located at www.entitystack.us (the "Site," and together with the Service, the "Platform").

This Policy applies to (a) individuals who register for or are authorized to use the Service on behalf of a Firm ("Users"), and (b) visitors to the Site. Section 6 separately addresses how we handle Entity Information (defined below) that Firms and Users submit to the Service, since our role with respect to that information differs from our role with respect to personal information we collect about Users in their own capacity.

This Policy is incorporated into, and should be read together with, our Terms of Service (the "Terms"), which govern access to and use of the Platform and contain additional provisions, including limitations of liability and dispute resolution procedures, that apply to claims arising out of or relating to this Policy. Capitalized terms not defined in this Policy have the meanings given to them in the Terms. By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not access or use the Platform.

2. Definitions

"Entity Information" means information about a corporate or business entity that a Firm or its Users input, upload, import, or otherwise submit to or generate within the Service, which may include an entity's legal and trade names; jurisdiction, type, tax identification or employer identification number (EIN); or other information associated with the entity.

"Personal Information" means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual, as further defined under applicable law.

"User Content" means Entity Information and any other data, files, notes, or materials that a Firm or its Users submit to, upload to, or store within the Service.

"Subprocessor" means a third-party service provider we engage to assist in providing the Platform and that processes Personal Information or Entity Information on our behalf.

3. Information We Collect

3.1 Account and User Information

When a Firm registers for the Service, we collect information about the Users the Firm authorizes to access the Service, including full name, work email address, work telephone number, job title, employing Firm, and role or permission level within the Service. If the Firm enables single sign-on or multi-factor authentication, we may also receive corresponding authentication data from the applicable identity provider.

3.2 Entity Information

In the course of using the Service, Users submit Entity Information as described in Section 2. A substantial portion of Entity Information reflects data that is already a matter of public record (for example, information filed with a secretary of state or other government agency) or is issued by a government authority (such as an EIN). Section 6 describes how we handle Entity Information and the respective responsibilities of EntityStack and the Firm with respect to it.

3.3 Billing Information

If a Firm purchases a paid subscription, we and our third-party payment processor collect billing contact name, business address, and payment method details necessary to process payment. Full payment card and bank account numbers are collected and processed directly by our payment processor and are not stored on EntityStack's own systems.

3.4 Usage, Device, and Log Data

We automatically collect certain technical information when Users and Site visitors interact with the Platform, including IP address, browser and device type, operating system, referring and exit pages, pages viewed, features used, timestamps, and other diagnostic and usage data, typically through server logs and similar technologies described in Section 7.

3.5 Communications

When a User or Firm representative contacts us for support, sales, or other purposes, we collect the content of those communications together with the sender's contact information and any files or information provided to assist in resolving the inquiry.

3.6 Cookies and Similar Technologies

We and our service providers use cookies and similar technologies on the Site and within the Service, as described in Section 7. We do not use tracking pixels.

3.7 Information from Other Sources

We may receive information about a User from the Firm's account administrator (for example, when the administrator creates, modifies, or deactivates a User's account or adjusts permissions), and from Subprocessors that support authentication, communications, or similar functions.

4. How We Use Information

We use the categories of information described in Section 3 for the following business purposes:

  • To provide, operate, maintain, and support the Service, including creating and managing Firm and User accounts and enabling Users to create and manage Entity Information;
  • To process payments and manage billing, invoicing, and subscriptions;
  • To respond to inquiries, provide customer support, and communicate with Users about the Platform, including administrative, transactional, and security-related communications;
  • To send product updates, tips, and marketing communications, where permitted by law and, where required, with the recipient's consent or subject to an opt-out (see Section 10);
  • To monitor, analyze, and understand usage trends in order to maintain, secure, and improve the Platform and to develop new features and functionality;
  • To detect, investigate, and prevent fraud, abuse, security incidents, and other harmful, unauthorized, or illegal activity, and to enforce the Terms and this Policy;
  • To comply with applicable law, regulation, legal process, or governmental request, and to establish, exercise, or defend legal claims; and
  • For any other purpose disclosed to you at the time information is collected or with your consent.

Aggregated and De-Identified Data. We may create, use, and disclose information that has been aggregated or de-identified such that it does not identify a particular individual, Firm, or entity, for any lawful business purpose, including to develop, train, test, and improve our products, features, and analytics, and any machine-learning or artificial-intelligence models, without restriction. We will not use Entity Information or Personal Information that identifies a particular Firm, entity, or individual to train models made generally available to other customers or third parties, except in de-identified or aggregated form as described above.

5. How We Share Information

We do not sell Personal Information for monetary consideration, and we do not share Personal Information for cross-context behavioral or targeted advertising purposes. We may disclose information in the following circumstances:

  • Subprocessors and Service Providers. With vendors that perform services on our behalf, such as cloud hosting and infrastructure, data storage and backup, customer support and communications tools, analytics, security monitoring, and payment processing, bound by written obligations to protect the information and use it only to provide services to us.
  • Within a Firm's Account. Information about a User (such as name, role, and activity within the Service) may be visible to other authorized Users or administrators within the same Firm account as necessary for the Firm to administer its own account and personnel.
  • Professional and Legal Advisors. With our auditors, insurers, and legal, financial, and other professional advisors, subject to confidentiality obligations.
  • Business Transfers. In connection with, or during negotiations of, a merger, acquisition, financing, reorganization, bankruptcy, or sale or transfer of some or all of our assets or business, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information and Entity Information held by us may be among the assets transferred.
  • Legal Obligations and Protection of Rights. Where we believe disclosure is necessary or appropriate to comply with applicable law, regulation, legal process, or governmental request; to enforce the Terms and this Policy; to protect the security, rights, property, or safety of EntityStack, our Users, or others; or to detect, prevent, or address fraud, security, or technical issues.
  • With Consent or at Your Direction. Where a Firm or User directs us to share information with a third party (for example, through an integration the Firm elects to enable), or otherwise consents to disclosure.

6. Our Role Regarding Entity Information; Firm and User Responsibilities

With respect to Entity Information and other User Content, EntityStack acts solely as a service provider, processor, or similar designation under applicable law, on behalf of the Firm, which remains the business responsible for determining the purposes and means of processing such information. We process Entity Information only (a) to provide, maintain, support, and secure the Service, (b) as necessary to comply with applicable law, or (c) as otherwise instructed in writing by the Firm, in each case consistent with any data processing terms incorporated into the Terms.

Firm and User Responsibilities. The Firm and its Users are solely responsible for (i) the accuracy, quality, and lawfulness of Entity Information they submit to the Service; (ii) having all rights, permissions, and legal bases necessary to submit any Personal Information contained within Entity Information, including information about officers, directors, managers, members, beneficial owners, or other individuals; and (iii) complying with all applicable data protection, professional conduct, and confidentiality obligations applicable to the Firm's own clients, matters, and practice.

Professional Responsibility. EntityStack is a technology provider. We are not a law firm, do not provide legal advice, and are not a party to, and assume no responsibility for, any attorney-client relationship between a Firm and its clients. Each Firm is solely responsible for evaluating whether, and on what terms, its use of the Service is consistent with its obligations under applicable rules of professional conduct, including rules concerning client confidentiality and the retention of third-party service providers, and for obtaining any client consent required before storing client-related Entity Information within the Service.

Publicly Available and Government-Source Information. Certain data elements within Entity Information (such as an entity's registered legal name, formation jurisdiction, or an EIN issued by a taxing authority) commonly originate from, duplicate, or are otherwise available through public government records. Regardless of the public availability of any such data element, we apply the administrative, technical, and physical safeguards described in Section 9.

7. Cookies and Tracking Technologies

We and our service providers use the following categories of cookies and similar technologies on the Site and within the Service:

  • Strictly Necessary. Required for core functionality, such as authentication, session management, and security; these cannot be disabled without impairing the Platform.
  • Functional. Remember preferences and settings to enhance usability, such as your saved color schemes and table display options. These are held in your browser's local storage rather than in cookies, and are never sent to us.
  • Analytics and Performance. Help us understand how the Platform is used so we can maintain and improve it. We use Vercel Web Analytics, which counts page views without cookies and without storing any identifier that would let us recognize you across visits or across other websites.

We do not currently use advertising or cross-site tracking cookies on the Platform. Where required by applicable law, we honor opt-out preference signals, including the Global Privacy Control ("GPC"), as a valid request to opt out of any sale or sharing of Personal Information, to the extent such practices apply. Most browsers allow you to control cookies through their settings; disabling certain cookies may affect the functionality of the Platform.

8. Data Retention

We retain Account and User Information for as long as the applicable Firm account remains active, and for a reasonable period thereafter (not to exceed 90 days, absent a legal hold or ongoing dispute) to permit account recovery, resolve disputes, enforce the Terms, and comply with legal, tax, and accounting obligations.

We retain Entity Information for the duration of the Firm's subscription, in accordance with the Firm's instructions and any retention or export settings available within the Service. Upon termination or expiration of a Firm's subscription, we will make Entity Information available for export for 30 days, after which it may be deleted, returned, or de-identified in accordance with our standard data-retention schedule and the Terms. We may retain aggregated or de-identified information described in Section 4 indefinitely, and we may retain copies of information as required by law or as necessary to establish, exercise, or defend legal claims.

9. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information within the Platform against unauthorized access, disclosure, alteration, and destruction, including encryption of data in transit, access controls and authentication requirements, network and application monitoring, and periodic review of our security practices and those of our Subprocessors. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting Personal Information, we will notify affected parties and applicable authorities as and to the extent required by applicable law and the Terms.

10. Your Privacy Rights

Depending on your state of residence, you may have certain rights under applicable U.S. state privacy laws (which, as of the Last Updated date above, include comprehensive consumer privacy statutes enacted in California and a growing number of other states) with respect to your Personal Information. These rights commonly include the right to:

  • Confirm whether we process your Personal Information and access a copy of it;
  • Correct inaccurate Personal Information;
  • Delete your Personal Information, subject to certain exceptions;
  • Obtain your Personal Information in a portable format;
  • Opt out of the sale or sharing of your Personal Information, or of profiling in furtherance of decisions that produce legal or similarly significant effects;
  • Limit the use or disclosure of sensitive Personal Information; and
  • Not receive discriminatory treatment for exercising any of these rights, and to appeal a decision we make regarding your request (see below).

As noted in Section 5, we do not sell Personal Information and do not use it for cross-context behavioral or targeted advertising; accordingly, opt-out requests directed at those practices are not applicable to our current data practices, but we will honor any such request we receive, including through recognized opt-out preference signals where required by law.

How to Exercise Your Rights. You may submit a request by emailing support@entitystack.us. We will need to verify your identity before processing certain requests, which may require you to provide additional information. If you are an authorized agent submitting a request on behalf of another individual, we may require proof of your authorization and may also require the individual to verify their own identity directly with us.

Our Response. We will respond to a verified request within the time period required by applicable law (generally 45 days, which may be extended by an additional 45 days when reasonably necessary, with notice to you). If we decline to act on your request, we will explain the basis for that decision and, where required by law, describe how you may appeal by emailing support@entitystack.us. We will respond to an appeal within the time period required by applicable law and, if we deny the appeal, will provide information about how to submit a complaint to your state's Attorney General or other applicable regulator.

Because Users generally interact with the Platform as representatives of their employer in a business-to-business context, this Section applies to Personal Information about Users to the same extent it would apply to any other individual, except as otherwise permitted by applicable law.

11. International Users

The Platform is designed for use within the United States, and information we collect is processed and stored in the United States. If you access the Platform from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, a jurisdiction whose data protection laws may differ from those of your home jurisdiction. Where applicable law requires a specific legal mechanism for such transfer, we will implement an appropriate safeguard (such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum) prior to transfer.

12. Third-Party Links and Integrations

The Platform may contain links to third-party websites (such as secretary of state filing portals) or offer optional integrations with third-party services (such as e-signature or accounting software) that a Firm elects to enable. We do not control, and are not responsible for, the privacy practices of any third party. We encourage you to review the privacy policy of any third-party website or service before providing information to it.

13. Data Storage

We use reputable third-party cloud infrastructure providers located in the United States to host the Platform and store information. Our Subprocessors may process information in other locations solely to the extent necessary to provide the applicable service to us, subject to contractual confidentiality and security obligations.

14. Changes to This Privacy Policy

We may revise this Policy from time to time. When we do, we will update the "Last Updated" date below and post the revised Policy on the Site. If we make a material change that reduces your rights under this Policy, we will provide additional notice as required by applicable law (for example, by email to the Firm's account administrator or a notice within the Service) before the change takes effect. Your continued access to or use of the Platform after the effective date of any revision constitutes your acceptance of the revised Policy.

15. Contact Us

If you have questions about this Privacy Policy or our privacy practices, or would like to exercise a right described in Section 10, please contact us at:

EntityStack, LLC
P.O. Box 61
Powell, Ohio 43065
Attn: Privacy Officer
Email: support@entitystack.us