Privacy Policy

Last updated: June 2026

This Privacy Policy explains how WrapIQ collects, uses, and protects your information.

1. Information We Collect

CategoryExamplesHow it's protected
Account dataYour name, work email, company name, passwordPasswords are hashed with PBKDF2-SHA256 (per-user salt, 100,000 iterations) and are never stored in plaintext or recoverable form
Application dataEmployee names, labor categories, salaries, bill rates, and indirect rate assumptions you enterEncrypted at rest with AES-256-GCM before storage; not visible to WrapIQ employees
Billing dataCard details and payment infoHandled entirely by Stripe (PCI-DSS Level 1); we store only a customer reference and subscription status — never card numbers
Uploaded documentsFinancial documents you upload for rate calculationTransmitted over TLS for analysis and not stored — only the extracted rate percentages are returned

All data is transmitted over encrypted TLS 1.2/1.3 connections. See Data Storage & Security below for full details.

2. How We Use It

We use your data solely to provide and operate the Service: authenticating you, storing your rate model, processing payments, and generating rate calculations. We do not sell your data or use it for advertising.

3. Data Storage & Security

Your application data — including all employee names, salaries, bill rates, and rate assumptions — is encrypted at rest using AES-256-GCM before it is written to storage. The encryption key is held as a protected secret, separate from the data itself.

Your application data is not visible to WrapIQ employees. Because it is encrypted at rest, no member of our team — including engineers and support staff — can read your salary figures, employee information, or rate data. We operate on a zero-visibility basis for your sensitive business data.

All data in transit is protected by TLS 1.2/1.3. Passwords are hashed using PBKDF2 with per-user salts (100,000 iterations) and are never stored in plaintext or recoverable form.

4. Sub-Processors

ProviderPurpose
CloudflareHosting, data storage, content delivery
StripePayment processing
ResendTransactional email (password reset, invites)
AnthropicAI rate calculation from uploaded documents

5. Uploaded Documents

Financial documents you upload for the "Calculate My Rates" feature are transmitted to Anthropic's API for analysis and are not stored by WrapIQ. Only the extracted rate percentages are returned and used.

6. Data Retention & Deletion

We retain your data for as long as your account is active. Upon cancellation and account deletion, your organization's data is permanently removed from our systems. You may request deletion at any time.

7. Your Rights

You may access, correct, export, or delete your data at any time through the app or by contacting us. For organizations subject to specific regulations, see our Data Processing Agreement.

8. Contact

Privacy questions: privacy@wrapai.com

← Back to WrapIQ