Effective immediatelyWe never sell your data

Our privacy promise

This policy is issued by Hareword LLC, dba Nonresident Tax (“we,” “us,” or “our”) and covers every service we offer — company formation, registered agent service, federal tax filing, and accounting. Four commitments run through everything below: we only collect what we need to serve you, we never sell your data, we protect it with enterprise-grade security, and we stay transparent about what we do with it.

Information we collect

We collect information in three ways.

What you give us

  • Personal details — name, email, phone, residential address, citizenship and nationality
  • Business details — company name, business address, industry, ownership structure, and activities
  • Financial data — bank details for payments, revenue, expenses, and transaction history
  • Government identifiers — EIN, passport number when required, foreign tax IDs
  • Supporting documents — passports, proof of address, contracts, financial statements

What we collect automatically

  • Usage data — pages visited, features used, time spent, interaction patterns
  • Device information — IP address, browser type, operating system, device identifiers
  • Cookies — session cookies for sign-in, preference cookies for settings, analytics cookies with your consent

What third parties give us

  • Identity-verification services, for compliance checks
  • Credit reporting agencies, only when you explicitly authorize it
  • Public records and government databases, for business verification
  • Business partners, when you’re referred to us

How we use your information

Every piece of information we collect serves a specific purpose.

Service delivery

  • Process your company formation in Wyoming or Delaware
  • Prepare and file federal tax returns — Form 5472, Form 1120, Form 1065
  • Maintain your books and produce financial statements
  • Serve as your registered agent and forward legal documents
  • Provide customer support

Legal compliance

  • Verify your identity for Know Your Customer (KYC) checks
  • Report required information to the IRS and state authorities
  • Screen against government watchlists for anti-money-laundering compliance
  • Keep records as required by law — typically 7 years for tax documents

Service improvement

  • Analyze usage patterns to find friction and fix it
  • Read and act on the feedback you send us
  • Build new features around what non-resident founders actually need

Communications

  • Transactional messages — service updates, deadline reminders, account notifications
  • Marketing messages — tax tips and service offerings, only with your consent
  • Legal notices — policy changes or other legally required notices

How we share your information

We never sell your personal information. We only share it when it’s necessary to deliver a service or meet a legal obligation.

Service providers

Everyone we work with is bound by a strict confidentiality agreement:

  • State filing agencies in Wyoming and Delaware
  • The IRS and state tax authorities
  • Xero, for bookkeeping and accounting
  • Stripe, for payment processing
  • Identity-verification services
  • Email service providers
  • AWS, for cloud storage

Legal requirements

We may disclose information when the law requires it: court orders and subpoenas, authorized government agency requests, fraud prevention and investigation, or protecting our rights, property, or safety.

With your consent

We share information whenever you explicitly ask us to — for example, authorizing us to work directly with your accountant, attorney, or business partners.

Business transfers

If Nonresident Tax is acquired or merges with another company, your information may transfer as part of that deal. We’ll notify you before any transfer happens, and the new entity has to honor this policy.

International data transfers

Because our clients are based outside the US, cross-border data protection matters to us. Your data is primarily processed in the United States, where our services operate. For EEA and UK residents, we rely on Standard Contractual Clauses for international transfers, and we maintain GDPR-aligned safeguards so your data gets equivalent protection no matter where it’s processed.

Data security

We implement enterprise-grade security measures to protect your information.

Technical safeguards

  • 256-bit SSL encryption for all data in transit
  • AES-256 encryption for data at rest
  • Multi-factor authentication for system access
  • 24/7 security monitoring and intrusion detection
  • Regular encrypted backups with disaster recovery

Organizational safeguards

  • Regular security training for every employee
  • Role-based access on a strict need-to-know basis
  • Confidentiality agreements with all staff
  • Regular security audits and vulnerability assessments
  • An incident-response plan with breach-notification procedures
No system is completely impenetrable, and we won’t pretend otherwise. We continuously update our security practices, and if a breach ever affects your personal information, we’ll notify you promptly.

Data retention

We keep information only as long as it’s useful or legally required, then securely delete or anonymize it.

Data categoryRetention period
Tax records7 years after filing (IRS requirement)
Company formation documentsLife of the company, plus 7 years
Accounting records7 years from creation
Email communications2 years, unless the law requires longer
Marketing preferencesUntil you opt out or request deletion

Some information may be kept longer than the periods above if the law requires it, or for legitimate purposes like fraud prevention.

Cookies and tracking technologies

Essential

Required for the site to function — sign-in and security. These can’t be disabled.

Functional

Remember your preferences, language, and recent searches.

Analytics

Google Analytics and Mixpanel, only activated once you consent.

Marketing

Facebook Pixel and Google Ads, used only with your explicit consent.

Manage your preferences through our consent banner or your browser settings. Disabling certain cookies may limit some functionality.

Your privacy rights

Wherever you’re based, you have real control over your information:

  • Access a copy of everything we hold about you
  • Correct information that’s inaccurate
  • Delete your personal data, subject to legal retention requirements
  • Receive your data in a portable, machine-readable format
  • Object to certain processing activities
  • Restrict how we process your data
  • Withdraw consent for marketing or optional processing, at any time

California residents (CCPA/CPRA)

You can ask what we collect, sell, or share, request deletion, and opt out of sales — though there’s nothing to opt out of, since we don’t sell data. Exercising any of these rights never changes how we treat you.

EEA, UK, and Swiss residents (GDPR)

Every right above applies, plus the right to lodge a complaint with your supervisory authority. We process data under four lawful bases: consent, contract fulfillment, legal obligation, and legitimate interest.

Children’s privacy

Our services are built for businesses and for people 18 or older. We don’t knowingly collect information from anyone under 13, and if we ever discover that we have, we delete it immediately. If you believe we’ve collected information about your child, contact us and we’ll act right away.

Third-party links

Our site links to third-party sites, including government resources like the IRS and state filing agencies, and partner services. We aren’t responsible for their privacy practices, so we’d encourage you to read their policies before sharing any information with them.

Marketing and communications

We try to keep you informed without overwhelming your inbox.

  • Transactional emails — deadline reminders, account updates, receipts — are always sent
  • Marketing emails — tax tips, service updates, educational content — go out only with your consent
  • SMS is reserved for urgent matters or explicit opt-in
  • Phone calls are service-related, unless you’ve requested a consultation

Unsubscribe from marketing emails anytime, using the link in any email or by contacting us directly. Transactional emails stay on while you’re an active client — they’re how we tell you about deadlines and account changes.

Dispute resolution

If a privacy dispute comes up, we’ll start with good-faith negotiation. If that doesn’t resolve it, disputes go to binding arbitration in Delaware. You’re also always free to file a complaint with the relevant data protection authority in your jurisdiction.

Contact us

Questions or concerns about your privacy? Reach us any of these ways:

Mailing address

604 Carson Dr, Bear, DE 19701

We typically respond to privacy inquiries within 24–48 hours. For anything urgent, call us directly.

Changes to this policy

Your consent

Ready to start your US business?

Join international entrepreneurs who trust us for US company formation and ongoing compliance.

Get started