We keep what we need, for as long as we need it, and then we delete it.
You're giving us your company's papers and your passport name. Here is exactly what happens to them.
- We are not counting visits. Nothing about this visit is recorded.
- No third-party tag is on this page. No Google, Meta or advertising script is loaded, and nothing about your visit is sent to any of them.
This panel is read from the site’s own settings when the page is built, so it says what is true today rather than what was true when the notice was written.
Who is responsible
QOLOR LTD, trading as EIN Route, registered in England & Wales No. [00000000], is the data controller. UK GDPR applies to everything we do with your data. Because our team works from Qatar, Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016) may also apply; we follow the same rules under both. Contact: hello@einroute.com.
What we collect
- About the company: legal name, state and date of formation, addresses, number of members, business description, and your Articles of Organization.
- About you: your name, address, country, email, optional WhatsApp number, your title in the company, and your electronic signature.
- About the order: payment confirmation from Stripe (we never see your full card number), and our record of the correspondence involved in your application.
- On the website: if you use it, your pre-flight answers — stored in your own browser, not on our servers, until you order.
- A record of the visit: which page, in which language, on a phone or a computer, the site you arrived from, roughly which country, and whether you had been here before. No IP address, no cookie, no name. See Cookies and counting, below.
Why we use it
To prepare and submit your EIN application, to communicate with the IRS about it on your behalf, to send you the result, and to keep you updated. The legal basis is performance of our contract with you. We also keep your signed application and the delivery email as evidence of what was ordered and delivered, which is our legitimate interest in defending payment disputes.
We do not sell your data, use it for advertising, or share it with anyone who is not needed to deliver the service.
Who else sees it
- The IRS — the contents of your application. That is the point of the service.
- Stripe — processes your payment.
- Our form, e-signature, communications and email providers — carry the data between you, us and the IRS. Each is bound by its own data-processing terms.
- Resend — sends the emails we write to you, and is told your address and what the email says.
- Supabase — hosts the database and the files, in the EU.
Some of these providers are outside the UK. Where that is the case, transfers rely on the UK's adequacy decisions or standard contractual clauses.
How long we keep it
90 days after we deliver your EIN, we delete your documents, your signature and your personal data from our systems. We keep a minimal record of the order — company name, EIN, date, amount — for as long as UK company and tax law requires us to keep accounting records (currently six years). If you cancel before we file, everything is deleted within 30 days.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it early (we will, unless we are still filing for you or need it for the accounting record), and complain to the UK Information Commissioner's Office if you think we've handled it badly. Email us and we'll respond within 30 days, usually much sooner.
Cookies and counting
This site sets no cookies of its own, beyond remembering which language you chose. Your pre-flight answers are kept in your browser's own storage and stay on your device.
We do count visits, in our own database: which page, in which language, on a phone or a computer, which site you arrived from — the domain only, never the full address, because a web address can carry somebody else's search terms — roughly which country, and whether you had been here before. The country is worked out from your browser's time zone rather than from your IP address, which we never record. There is no cookie and no third party in any of that, and none of it carries your name. If you go on to buy, the payment is tied to the visit that led to it, so that we know which of our own pages actually work.
We may also carry Google Analytics, Google Tag Manager, a Meta pixel or a Google Ads conversion tag. Those are third parties, they do set cookies of their own, and they are switched off unless the panel below says otherwise.
The link in your emails
Every email we send you carries a link to a page showing where your order is, with no password. Anyone holding that link can see the company name, the progress, the number once it is issued, and can download the bank pack — so treat it as you would a receipt. The link contains a long random code, not your order reference: the reference is short enough to guess and the code is not. It stops working once the order's ninety days are up.
Last updated 5 September 2026