Statement privacy in plain language
Your compensation statements, extracted compensation information, forecasts, and planner information are private to your account. Other customers and agents cannot access them through AgentPay.
Automated and service-provider systems handle statements during ordinary processing. AgentPay's authorized support personnel do not routinely open customer statements or monitor individual pay amounts. Limited authorized access may occur only when reasonably necessary to provide support you request, investigate a processing problem, maintain or secure the service, prevent fraud or abuse, comply with law, or respond to a valid legal process.
AgentPay therefore does not make the absolute promise that no human can ever access a statement. Access is limited by role, purpose, and the amount of information reasonably needed.
Information AgentPay collects
- Account and authentication data: name, email address, account identifiers, authentication events, login and recovery records, and account settings.
- Stripe billing identifiers: Stripe customer, checkout, subscription, invoice, payment, and transaction identifiers; subscription status; billing period; assigned price; consent version; and charge status. Stripe processes card details. AgentPay does not receive or store your complete card number or card security code.
- Uploaded compensation statements: PDF files, temporarily while queued and processed; plus filenames, statement dates, file metadata, upload status, processing status, source-deletion audit metadata, and customer corrections or approvals.
- Extracted compensation information: pay categories, compensation codes, pay dates, premiums, commissions, adjustments, deductions, deposits, totals, production information, statement evidence, and extraction-confidence or review information.
- Forecast and planner information: agency and production inputs, forecast results and scenarios, allocation choices, bills, due dates, planning categories, and other values you choose to enter.
- Technical logs: device, browser, IP address, timestamps, request, queue, processing, security, diagnostic, and error records produced by AgentPay and its providers.
- Support communications: the messages and information you provide in service, privacy, billing, security, or legal requests.
Do not upload unrelated sensitive information
Upload only your own authorized compensation statements and information that AgentPay requests for the service. Customers must not upload unrelated sensitive personal information, including customer or employee records, medical or health information, Social Security numbers, dates of birth, full bank or payment-card numbers, passwords, or identity documents.
Review each PDF before uploading and permanently redact unrelated sensitive information when lawful and appropriate. Do not redact statement dates, compensation line items, category labels, totals, deductions, or other information AgentPay needs to process the statement. See the Upload Guide.
How AgentPay uses information
- Create, authenticate, recover, and secure your account.
- Store and process statements, extract compensation information, present results for review, and respond to corrections.
- Generate preliminary and statement-informed forecasts, scenarios, and planner outputs.
- Process subscriptions, document billing authorization, prevent duplicate subscriptions or charges, and control paid access.
- Operate processing queues, diagnose errors, support customers, protect the service, and prevent fraud or abuse.
- Maintain, test, and improve reliability and accuracy using data limited to what is reasonably needed.
- Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
Service providers and disclosures
AgentPay uses vendors acting on its behalf to operate the service. Depending on the feature and configured processing path, these providers may receive, store, transmit, or process the limited information needed for their role:
- Supabase provides account authentication, database services, private file storage, server functions, and related security and technical logs.
- Stripe provides checkout, recurring billing, receipts, payment processing, fraud prevention, and subscription management.
- OpenAI API supports AI-assisted statement extraction and structured processing. Statement files or statement content may be sent to the API when that processing path is used. AgentPay does not use customer statements to train a general-purpose AI model.
- Railway provides background-worker and processing infrastructure that may handle queued statements, extracted information, job status, and technical logs.
- Vercel provides application and web hosting, request handling, deployment infrastructure, and related technical and security logs.
- Resend and/or another email provider may deliver account, recovery, transactional, service, or support email and process the recipient address, message content, and delivery metadata needed to do so.
Providers may also allow exceptional access by their authorized personnel under their security, support, and legal procedures. AgentPay may disclose information to professional advisers, authorities, or transaction participants when reasonably necessary for legal, security, compliance, or corporate-transaction purposes.
AgentPay does not sell personal information or share it for cross-context behavioral advertising. AgentPay does not disclose compensation statements to an insurance carrier merely because you use the service.
Automated and AI-assisted processing
AgentPay uses optical character recognition, AI-assisted extraction, rule-based parsing, validation logic, and forecast calculations. Automated processing can make mistakes. Customers should review extracted information and can correct or report issues through available service and support channels.
AgentPay uses this processing to provide software outputs to the customer. It does not use AgentPay to make decisions about a customer's employment, insurance eligibility, credit, housing, or another legally significant benefit.
Authorized statement access
Statement access is not part of routine human review. A limited number of authorized personnel may access only the information reasonably needed when:
- you request support or ask AgentPay to investigate a result;
- processing flags a format, extraction, reconciliation, or queue issue that requires secure review;
- AgentPay must maintain the service or investigate suspected fraud, abuse, a security incident, or a threat to service integrity; or
- access is required to comply with law or valid legal process.
AgentPay applies access controls and confidentiality and security measures appropriate to compensation information. Access may be logged or reviewed where the supporting systems make that available.
Retention and deletion
Original uploaded compensation-statement files are stored temporarily in private active storage while queued, processing, or undergoing bounded automated retries. After extraction succeeds and the required structured information is securely persisted, AgentPay automatically deletes the original uploaded file from active storage. If processing reaches a terminal failure with no further automated retry, AgentPay deletes the original file and asks the customer to upload it again.
Extracted compensation information, customer corrections and approvals, statement history, forecast inputs and results, planner information, file audit metadata, support records, and technical information remain according to the retention rules applicable to the account and the service. AgentPay does not promise an unsupported fixed retention period for every retained data type. The period depends on the information, account status, service need, security risk, and legal obligations.
You may delete information using available account controls or request deletion by contacting support. Canceling a subscription does not by itself delete the account or saved information. Deletion from active systems may not immediately remove encrypted backups, security logs, or information AgentPay must retain for fraud prevention, billing, disputes, tax, accounting, legal, or compliance purposes.
Billing and subscription-consent records may be kept as reasonably needed to document authorization, resolve disputes, and meet legal obligations. AgentPay will delete or deidentify information when it is no longer reasonably needed, subject to applicable exceptions.
Security
AgentPay uses reasonable administrative, technical, and organizational safeguards designed for the sensitivity of compensation information, including authenticated accounts, private storage, access controls, and server-side authorization. No method of storage or transmission can be guaranteed completely secure.
Protect your password and account access, use only trusted devices and networks, and contact support promptly if you suspect unauthorized access.
Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, or information about disclosures; to appeal a denied request; and to be free from unlawful discrimination for exercising a right. AgentPay may verify your identity and may retain information when an exception applies.
Send privacy questions or requests to support@agentpayforecast.com. Include the email address associated with your account, but do not attach a compensation statement or unrelated sensitive information to an ordinary email.
Children and policy changes
AgentPay is a professional service for adults and is not directed to children under 13. AgentPay does not knowingly collect personal information from children.
AgentPay may update this Policy as its practices or legal obligations change. The last-updated date identifies the current copy. AgentPay will provide additional notice of material changes when required.