Privacy Policy
Last updated: August 19, 2026
1. Controller
Paircat UG (haftungsbeschränkt), Kolonnenstr. 8, 10827 Berlin, Germany, represented by Pëllumb Dalipi. Email: [email protected]. We have not appointed a data protection officer because we are not legally required to.
2. What data we process and why
2.1 Visiting the website
Our website is delivered through Cloudflare, which sits in front of our server as a content delivery network and security layer. Every request therefore passes through Cloudflare before it reaches us, and Cloudflare processes the IP address, the requested URL, and browser information in order to route the request, filter attacks, and terminate the encrypted connection. Our own server additionally records the IP address, date and time, requested URL, referrer, and browser information in server logs, which we use to deliver the site, keep it secure, and investigate abuse. Legal basis for both: Art. 6(1)(f) GDPR (legitimate interest in operating a secure and available website). Our server logs are deleted after 14 days. See section 3 for details on Cloudflare.
2.2 Necessary cookies
We set technically necessary cookies without asking: a short-lived token that protects forms against cross-site request forgery, a setting that remembers your cookie choice, and, for our staff only, an administration session cookie. Cloudflare may additionally set a short-lived security cookie (for example __cf_bm) to tell human visitors from automated traffic. These are all strictly necessary to provide the service you requested. Legal basis: Section 25(2) TTDSG and Art. 6(1)(f) GDPR.
2.3 Advertising measurement and analytics (only with your consent)
If you click "Accept" in the cookie notice, we use Google Ads conversion tracking and Google Analytics 4, services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to measure which advertisements and pages lead to orders and how the site is used. Google sets cookies (for example _gcl_au, _ga) and processes your IP address, device and browser information, the pages you visit, and, after an order, the order value and an identifier of the order. For conversion measurement we may transmit your email address in hashed form to Google ("enhanced conversions") so that Google can match the order to an ad click. Google may transfer data to Google LLC in the USA; Google LLC is certified under the EU-US Data Privacy Framework. Legal basis: your consent, Art. 6(1)(a) GDPR and Section 25(1) TTDSG. You can withdraw consent at any time under "Cookie settings" in the footer. If you click "Reject" or make no choice, no advertising or analytics cookies are set; in that case the Google tag sends only cookieless, non-identifying signals so that Google can estimate conversion counts (Consent Mode). We use IP anonymization in Google Analytics and have concluded Google's data processing terms.
On the same consent we use the ChatGPT Ads measurement pixel of OpenAI, OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, USA, to measure which advertisements shown in ChatGPT lead to orders. The pixel loads from OpenAI's servers only after you click "Accept" and reports that a page was viewed and that a checkout was started, together with your IP address and browser information. When you start a checkout we additionally report the same event from our own server to OpenAI's conversions interface, using an identifier derived from your order number so that the two reports are recognised as one event; that server-side report is likewise only sent if you have accepted. We do not transmit your name, address, email address or the details of your LLC to OpenAI, and no order value is transmitted. OpenAI processes this data in the USA on the basis of the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR. Legal basis: your consent, Art. 6(1)(a) GDPR and Section 25(1) TTDSG, withdrawable at any time under "Cookie settings" in the footer. If you click "Reject" or make no choice, the pixel is not loaded and nothing is sent to OpenAI, from your browser or from our server.
If you arrive through an advertisement, the click identifier (gclid) and campaign parameters in the link are stored together with your order so we can see which campaigns work. This does not involve cookies.
2.4 Placing an order
To perform the service we process the data you enter in the order form: your email address and phone number, the LLC's name, address, state and date of formation, number of members and business description, the name and address of the owner, and, if you upload it, the Form SS-4 you previously filed. We use this data to prepare and submit Form SS-4 to the IRS, to communicate with you about the order, and to deliver the 147c letter. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). We also store the resulting 147c letter, which contains the EIN, to be able to resend it to you on request.
2.5 Payment
Payment is processed by Stripe Payments Europe, Ltd., Dublin, Ireland, and its affiliates. Card details are entered on Stripe's pages and never reach our servers. We receive a payment reference, the amount, and the payment status. Stripe is an independent controller for its own processing; see stripe.com/privacy. Legal basis: Art. 6(1)(b) GDPR.
2.6 Email
Order confirmations, status updates, and the 147c letter are sent by email through Resend (Resend, Inc., USA), acting as our processor under a data processing agreement including EU standard contractual clauses. Legal basis: Art. 6(1)(b) GDPR.
2.7 Status check
To show your order status we match the order number and the owner's last name you enter against our records. Repeated failed attempts are rate limited by IP address to prevent guessing. Legal basis: Art. 6(1)(b) and (f) GDPR.
2.8 Affiliate partner program
If you apply to our affiliate partner program we process the name, email address, website and description you submit, and the password you choose (stored only as a scrypt hash), in order to assess the application and operate the account. Legal basis: Art. 6(1)(b) GDPR (steps prior to and performance of a contract). Where a customer reaches us through a partner link, we store a reference to that partner on the order so that commission can be calculated. Partners can see only the order reference, date and commission amount; they never see customer names, addresses, email addresses or company details. Rejected applications are deleted after [6] months.
2.9 Contact by email
If you email us, we process the content of your message to answer it. Legal basis: Art. 6(1)(b) or (f) GDPR.
3. Recipients and transfers outside the EU
- Internal Revenue Service (IRS), USA. We transmit the order data to the IRS to obtain the EIN. This transfer is necessary for the performance of the contract you have with us (Art. 49(1)(b) GDPR). The IRS is a US government authority and processes the data under US law.
- Freelance specialists working on our instructions. We engage self-employed specialists to prepare EIN applications, submit them to the IRS, and receive the IRS reply. They process the order data solely on our behalf as processors, under written data processing agreements with confidentiality obligations, and only for as long as they work on your order. Because we work with different specialists over time, we do not name them individually here; the current list is held in our record of processing activities and we will tell you who processes your data on request. These specialists are located in the United States and in other countries, some inside and some outside the EU. Where a specialist is outside the EU in a country without an EU adequacy decision, the transfer is protected by the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR. You can request a copy of these safeguards at [email protected].
- Cloudflare, Inc., USA. Content delivery, DNS, and protection against attacks. Because Cloudflare terminates the encrypted connection at its edge, it processes all request data, including your IP address, on our behalf as our processor. Cloudflare is certified under the EU-US Data Privacy Framework, so transfers to the USA rest on the European Commission's adequacy decision; Cloudflare additionally offers the standard contractual clauses. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and available website).
- Hetzner Online GmbH, Germany. Hosting of the website and database in the EU, as our processor.
- Stripe (payment), Resend (email), and, only with your consent, Google (advertising measurement and analytics) and OpenAI (ChatGPT Ads measurement), as described above.
We do not sell personal data and do not use it for advertising.
4. Retention
Order data, including the 147c letter, is kept for as long as needed to perform the service and handle follow-up questions, and thereafter as required by German commercial and tax retention rules (generally 6 to 10 years for business records, Sections 257 HGB and 147 AO). Unpaid draft orders are deleted after 30 days. Server logs are deleted after 14 days.
5. Your rights
Under the GDPR you have the right to access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Contact us at [email protected]. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
6. Security
The site is served over HTTPS only. Data is stored on servers in the EU with access restricted to authorized staff using strong authentication. Payment data is handled exclusively by Stripe.
7. Changes
We update this policy when our processing changes. The current version is always available at this address.