Sandbox HiringSandbox Hiringby Winslow Back to sign in
Legal

Privacy Policy

Effective Date: [INSERT DATE] Last Updated: [INSERT DATE]

Template notice. This document is a starting draft prepared as a template for NFTCo, Inc. It is not legal advice. Engage privacy counsel to review and adapt this policy to your actual data practices, jurisdictions of operation, and applicable laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, GLBA, HIPAA where applicable, and others) before publishing. Yellow highlights mark sections that need especially careful counsel review or factual updates.


1. Introduction

This Privacy Policy explains how NFTCo, Inc. ("NFTCo," "we," "us," or "our") collects, uses, discloses, and protects information about you when you visit our websites, use our products and services (including the Winslow platform), or otherwise interact with us (collectively, the "Services").

We are a US-based company headquartered at [INSERT ADDRESS]. The Services are offered to and intended for users located in the United States.

If you do not agree with this Privacy Policy, please do not use the Services.

2. Scope

This Privacy Policy applies to:

  • Visitors to nftco.com, usewinslow.com, and any related NFTCo websites.
  • Account holders, administrators, and authorized users of the Winslow platform ("Customers").
  • Individuals whose information our Customers process through the Services, including their employees, contractors, applicants, and trial workers ("End Users").
  • Prospective customers, investors, partners, and other persons who interact with us through marketing channels, events, or sales conversations.

When a Customer uses the Services to manage information about their own employees, contractors, or trial workers, NFTCo acts as a service provider or processor on behalf of that Customer. The Customer is the controller of that information and is responsible for its own privacy notices and practices. End Users with questions about how their employer or principal handles their information should contact that Customer directly.

3. Information We Collect

We collect information in three ways: information you provide to us, information we collect automatically, and information we receive from third parties.

3.1 Information you provide

  • Account information: name, business email, phone number, job title, employer name, password (hashed).
  • Billing information: billing address, payment card details (processed by our payment processor; we do not store full card numbers).
  • Communications: messages, support tickets, survey responses, and feedback.
  • Customer data and End User data: information our Customers upload, input, or generate through the Services about their workforce, including names, addresses, dates of birth, Social Security Numbers and other government identifiers, work authorization documents, compensation, payroll history, tax withholding elections, direct deposit details, benefits enrollment, time and attendance records, performance evaluations, and other employment-related information necessary to operate the Services.

3.2 Information we collect automatically

  • Usage information: pages viewed, features used, click paths, session duration, referring URLs, search terms within the Services.
  • Device information: IP address, device identifiers, browser type and version, operating system, language settings, time zone.
  • Cookies and similar technologies: see Section 8.

3.3 Information from third parties

  • Identity verification and background check vendors: when a Customer initiates a background check on a job applicant or trial worker through the Services, we receive the resulting reports from the consumer reporting agency.
  • Payroll and tax authorities: confirmation receipts, filing acknowledgments, and notices related to tax remittances.
  • Benefits carriers and brokers: enrollment confirmations, eligibility files, claim status (where applicable).
  • Banking and payments partners: ACH confirmation, return notices, KYC/KYB results.
  • Authentication providers: single sign-on identity information (e.g., Google, Microsoft).
  • Public sources: business directories, regulatory filings, professional social networks (for sales and partnership outreach).

4. Sensitive Information

We collect categories of information that are considered sensitive under federal and state law, including: Social Security Numbers, financial account information, precise geolocation (in limited cases), and information about race, ethnicity, or disability status where collected for legally required equal employment opportunity reporting.

We use sensitive information only for the purposes described in this Policy, including providing the Services, complying with tax and labor laws, and where required by law. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about an individual.

5. How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, and improve the Services.
  • Process payroll, remit taxes, file required government forms, and provide other employer-of-record and HR functions on behalf of our Customers.
  • Authenticate users, secure accounts, prevent fraud, and investigate suspected misuse.
  • Communicate with Customers and authorized users about the Services, including service announcements, support, and billing.
  • Send marketing communications to prospective and current Customers (subject to opt-out).
  • Comply with legal obligations, respond to lawful requests by public authorities, and protect our rights and the rights of others.
  • Conduct analytics, research, and product development to improve the Services.
  • Aggregate or de-identify information for analytical and benchmarking purposes; de-identified information is no longer associated with any identifiable individual.

We do not use Customer data or End User data to train generally available AI models. Where the Services include AI features, those features operate on Customer data only for the benefit of the relevant Customer and in accordance with our Data Processing Agreement.

6. How We Share Information

We share information only as described below:

  • With service providers and subprocessors who help us deliver the Services, including cloud hosting providers, payroll and tax filing partners, identity verification vendors, background check vendors, benefits administrators, payment processors, customer support tooling, analytics providers, and security vendors. These parties are contractually required to protect the information and use it only as instructed.
  • Within the customer relationship: information uploaded by a Customer is accessible to that Customer's authorized administrators. End User information is generally accessible to the End User's employer (our Customer) consistent with the Customer's role.
  • For legal and safety reasons: when required by law, court order, or other legal process; to protect the rights, property, or safety of NFTCo, our Customers, End Users, or others; to enforce our agreements; or to detect, prevent, or address fraud or security issues.
  • In corporate transactions: in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar event, information may be transferred as part of the transaction, subject to the recipient agreeing to comparable protections.
  • With consent or at your direction: when you direct us to share with a specific third party (for example, by integrating a third-party application with the Services).

We do not sell personal information for money. We do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act. If our practices change, we will update this Policy and provide any opt-out rights required by law.

7. Data Retention

We retain personal information for as long as needed to provide the Services, comply with our legal obligations (including tax, payroll, and employment recordkeeping requirements, which may extend several years), resolve disputes, and enforce our agreements. Specific retention periods vary by record type and applicable law; for example, payroll records are typically retained for at least four years from the date of filing of the relevant return, and I-9 employment eligibility records are retained for the longer of three years after hire or one year after termination.

When personal information is no longer needed for the purposes for which it was collected, we will delete, anonymize, or aggregate it. Customers may request earlier deletion subject to our legal retention obligations.

8. Cookies and Tracking Technologies

We and our service providers use cookies, pixels, local storage, and similar technologies to:

  • Maintain login sessions and remember preferences.
  • Measure traffic and usage patterns.
  • Detect and prevent fraud and security incidents.
  • Provide analytics that help us improve the Services.

You can control cookies through your browser settings and through any cookie consent banner we display. Disabling certain cookies may affect the functionality of the Services. We do not use cookies to deliver third-party advertising.

We honor Global Privacy Control ("GPC") signals where required by law.

9. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, and destruction. These include encryption in transit and at rest, role-based access control, logging and monitoring, vulnerability management, vendor risk management, and incident response procedures. We pursue and maintain independent attestations of our security program, including SOC 2.

No security measures are perfect. Please use strong, unique passwords; enable multi-factor authentication; and contact us promptly at [security@nftco.com] if you suspect any unauthorized access to your account.

10. Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If we learn we have collected personal information from a child under 16, we will delete it. Contact us at [privacy@nftco.com] if you believe a child has provided information to us.

11. Your Rights and Choices

Depending on where you live and your relationship with us, you may have the following rights:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request that we correct inaccurate personal information.
  • Deletion: request that we delete personal information about you, subject to legal exceptions.
  • Portability: request a copy of certain information in a portable format.
  • Opt-out: opt out of certain processing, including marketing communications.
  • Limit use of sensitive personal information: where applicable under California law.
  • Non-discrimination: we will not discriminate against you for exercising your rights.

To exercise these rights, contact us at [privacy@nftco.com]. We will verify your identity before responding and will respond within the timeframes required by applicable law. If we deny your request, we will explain why, and you may have the right to appeal.

For End Users whose information is processed through the Services on behalf of a Customer (for example, employees of a company that uses Winslow): direct your request to your employer or principal, who is the controller of that data. We will assist our Customer in responding to your request as required by applicable law and our agreement with the Customer.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We will require proof of the agent's authorization and may require you to verify your identity directly.

12. State-Specific Disclosures

12.1 California (CCPA/CPRA)

California residents have additional rights, including the right to know what personal information we collect, use, disclose, and sell or share; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit use of sensitive personal information; and the right to non-discrimination.

Categories of personal information we collect (CCPA categories): identifiers; California Customer Records information; characteristics of protected classifications (where collected for compliance reporting); commercial information; internet or other electronic network activity; geolocation; professional or employment-related information; education information; inferences drawn to create profiles about consumer preferences (limited); and sensitive personal information (SSNs, financial account information, precise geolocation in limited cases, and contents of communications where applicable).

Sources, purposes, and disclosures are described in Sections 3, 5, and 6.

Sale or sharing. We do not sell personal information for money and we do not share personal information for cross-context behavioral advertising as defined under the CCPA.

Retention is described in Section 7.

12.2 Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and others)

Residents of these states may have rights similar to those described above, subject to state-specific exceptions and processes. To exercise your rights, contact us at [privacy@nftco.com].

13. International Users

The Services are intended for use in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Services, you consent to this transfer.

14. Third-Party Sites and Services

The Services may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated Policy with a new "Last Updated" date. If we make material changes, we will provide additional notice (such as email or an in-product notice) as required by law.

16. How to Contact Us

If you have questions or concerns about this Privacy Policy or our privacy practices, contact us at:

NFTCo, Inc. Attn: Privacy [INSERT ADDRESS] Email: [privacy@nftco.com]

Data Protection Officer / Privacy Lead: [INSERT NAME OR TITLE]

If you are not satisfied with our response, you may have the right to contact the privacy regulator in your state.


This Privacy Policy is provided as a template by NFTCo, Inc. Please consult qualified privacy counsel before adopting it for live use.

Privacy Policy·Terms of Service·Contact us