whatsapp
5.0
Based on 44 reviews
This Privacy Policy was last updated September 1, 2026. Changes take effect when they're posted here.
← Security & Trust
Last updated September 1, 2026

Privacy Policy

This policy outlines the privacy practices of National Software, Inc. ("NSI"), which operates 1099FIRE, and explains how we collect, use, and protect personal data.

Introduction

When you use our services, we're collecting your personal data to support those services. Data privacy is important to us at NSI. This Privacy Policy details our use of personal data and your privacy rights and choices available to you.

How We Use Personal Data

NSI collects personal data to:

  • Personalize and improve user experience.
  • Provide customer support and troubleshooting.
  • Process and fulfill service requests.

Personal Data We May Collect

NSI may collect one or more of the following types of data as a requirement for using our services:

Name
Contact information
Home address
Date of birth
SSN
Credit card number
Taxpayer identification numbers
Business contact information
IP address
Cookie ID
Login and password
Usage data

When We Share Your Personal Data

NSI shares personal data with third parties only under lawful circumstances, including:

  • Compliance with legal or regulatory requirements.
  • Secure processing by sub-processors (as outlined below).

Sub-Processors and Locations

To deliver our services, NSI engages third-party providers (sub-processors) who meet stringent security standards. See the complete list and their respective roles detailed below.

Cloud Service Providers

Webhost/DatabaseHosts and processes application data.Location: United States (primary hosting regions).
Google WorkspaceProvides email, document management, and shared drive functionality and cloud functions.Location: Global (specific locations depend on Google's data center allocations).

Data Backup and Disaster Recovery Services

CloudAllyBacks up Google Workspace data, including email, Google Drive, and shared drives.Location: United States and other regions as per their service architecture.
SupabaseData processing and workflow records.Location: United States and other regions as per their service architecture.

Customer Support Platforms

CrexendoVOIP phone provider used for customer communication.Location: United States.
Direct Digital DivisionManages mail house operations for sending 1099 and ACA form data to employees of our customers.Location: United States.
DocuSignProvides digital signature solutions and acts as a backup for signed agreements.Location: United States and other regions depending on their global operations.
ShareFileBackup storage for application data and other critical files.Location: United States.

Payment Processors

Authorize.netProcesses payment transactions securely.Location: United States.
StripeProcesses payment transactions securely.Location: United States and other global locations as per their operational model.

We remain committed to maintaining transparency about our sub-processors and their roles in processing customer data. If any changes occur to our list of sub-processors, we will update this Privacy Policy accordingly.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies We use include beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:

  • Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service. Unless you have adjusted Your browser setting so that it will refuse Cookies, our Service may use Cookies.
  • Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).

Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.

We use both Session and Persistent Cookies for the purposes set out below:

Retention of Your Personal Data

We retain personal data only for as long as it is needed for the purposes set out in this Privacy Policy, and to meet our legal, tax and regulatory obligations. We collect only the personal information that is directly relevant and necessary for those purposes.

For filing services specifically:

  • Client data files are not retained. The file you send is used to prepare and transmit your returns and is removed shortly after processing is complete.
  • Filing records are retained for 7 years, including the record of what was filed and the related submission receipts and confirmations, in line with IRS requirements.
  • System log data is retained for 12 months.
  • Vendor agreements are retained for 5 years after the contract ends.
  • Marketing contact data is retained until the person unsubscribes or asks us to delete it.

When data reaches the end of its retention period, it is securely disposed of.

Security of Your Personal Data

We apply technical and organizational security measures to protect the personal data we collect. That includes AES-256 encryption for stored data, TLS 1.2 or higher for data in transit, multi-factor authentication, access limited to authorized personnel on a least-privilege basis, and periodic security audits.

You can read more on our Security & Trust page. No method of transmission over the Internet or method of electronic storage is 100% secure, and while we use commercially reasonable means to protect your personal data, we cannot guarantee its absolute security.

Your Privacy Rights

You have the following rights:

  • Right to be Informed: Learn how and why your data is collected.
  • Right to Access: Request copies of your personal data and details about its use.
  • Right to Rectify: Correct inaccuracies in your personal data.
  • Right to Erasure: Request deletion of your personal data (subject to legal or operational requirements).
  • Right to Restrict Processing: Limit how your data is used.
  • Right to Data Portability: Transfer your data to another provider.
  • Right to Opt-In for Sensitive Data: Provide explicit consent for processing sensitive data.

These rights are subject to the clauses of the relevant privacy regulations, legal requirements, public interest, and where the above rights may conflict with your use of our services. For any privacy concerns or to request further details of your rights, please see the Privacy Requests and Contacts section below.

Breach Notification

Breaches of personal data will be reported to supervisory authorities, as required under applicable law and typically within 72 hours of becoming aware of the breach, and to the data subjects whose data was part of the breach.

Our Privacy Program

This policy sits on top of an internal privacy program that assigns ownership to our Senior Leadership Team, requires every employee to read and acknowledge it, and sets our obligations for notice and transparency, legal basis for processing, purpose limitation, data minimization, security, record keeping, breach notification, and the appointment of a Data Protection Officer.

The program accounts for the privacy regulations and standards that apply to our business, including CCPA, GDPR, PIPEDA, HIPAA, IRS guidelines for safeguarding taxpayer data, PCI DSS and SOX. This list is non-exhaustive and is updated as laws evolve.

Children's Privacy

Our Service is intended for business use and is not directed to anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 18, We take steps to remove that information from Our servers.

If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.

When we do, we update the "Last updated" date at the top of this page.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Privacy Requests and Contacts

For inquiries, complaints, or exercising your privacy rights, contact us:

Attention: Privacy Officer

privacy@1099fire.com

(480) 706-6474

Mailing address: PO Box 93001, Phoenix, Arizona 85070

Contact page

We attempt to respond to inquiries within 30 days.

National Software, Inc. | PO Box 93001 | Phoenix, Arizona 85070 | (480) 706-6474 | info@1099fire.com

Security & Trust  ·  Data Services Terms and Conditions

Scroll to Top