MoonStone PEO

Privacy Policy & Legal Notices

Contents

  1. Introduction & Scope
  2. How to Read This Document
  3. Definitions
  4. Our Role & Responsibilities
  5. Information We Collect
  6. Sources of Information
  7. How We Use Information
  8. Disclosures & Service Providers
  9. Cookies & Similar Technologies
  10. California Privacy Rights (CCPA/CPRA)
  11. Your Privacy Rights & Requests
  12. Electronic Communications Consent
  13. International Data Transfers
  14. Data Retention Schedule
  15. Information Security Statement
  16. Detailed Security Practices
  17. MFA & Passkey Policy
  18. Audit Logging Policy
  19. Incident Response & Breach Notification
  20. Acceptable Use Policy
  21. Terms of Use
  22. Employee Self-Service Provisions
  23. Employer & Administrator Responsibilities
  24. Disclaimers & Limitation of Liability
  25. Governing Law & Disputes
  26. DMCA / Copyright Notice
  27. Accessibility Statement
  28. Changes & Revision History
  29. How to Contact Us
  30. Developer Implementation Guidance

Privacy Policy, Terms of Use & Legal Notices

Service: MoonStone Reports — reports.moonstone-peo.com

Operator: MoonStone PEO, Inc. and affiliated entities, incl. Big Pay LLC

Version: 1.0  ·  Effective: 6/24/2026  ·  Last updated: 6/24/2026

1.Introduction & Scope ↑ top

This Privacy Policy, together with the Terms of Use, Acceptable Use Policy, and the other notices set out below (collectively, this “Policy”), governs your access to and use of the MoonStone Reports portal located at reports.moonstone-peo.com and any associated pages, features, downloads, and functionality (the “Service”). The Service is operated by MoonStone PEO, Inc. (“MoonStone,” “we,” “us,” or “our”).

The Service is a secure, business-to-business portal used to generate and distribute payroll-related reports — including check registers, earnings statements and check images, payment registers, period-to-date summaries, and deduction reports — derived from payroll and staffing data that MoonStone processes for its professional-employer-organization (PEO) and staffing clients and their affiliated brands. The Service is intended solely for authorized business users, including MoonStone personnel, authorized client and supplier administrators, and other individuals granted access by MoonStone or its clients. It is not directed to the general public or to consumers acting in a personal capacity.

By accessing or using the Service, you acknowledge that you have read and understood this Policy and agree to be bound by the Terms of Use, the Acceptable Use Policy, and the data practices described here. If you do not agree, do not access or use the Service.

2.How to Read This Document ↑ top

This Policy combines several related instruments in one place for convenience: a privacy notice (including a California-specific notice), a Terms of Use, an Acceptable Use Policy, an Information Security Statement, and operational policies covering authentication, logging, retention, and incident response. Where a specific section is meant to operate as a standalone agreement (such as the Terms of Use or Acceptable Use Policy), it does so in addition to, and not in limitation of, the remainder of this Policy.

Defined terms are capitalized and are explained in the Definitions section. References to “you” mean the individual accessing the Service and, where applicable, the organization on whose behalf that individual is authorized to act.

3.Definitions ↑ top

  • Account Data — information relating to a user’s portal account, such as username, display name, hashed password, multi-factor enrollment data, passkey public keys, role and permission assignments, and authentication logs.
  • Authorized User — an individual to whom MoonStone or a Client has granted credentials to access the Service.
  • Client — an employer, staffing supplier, or other organization for which MoonStone provides PEO, payroll, or reporting services, and on whose behalf payroll data is processed.
  • Payroll Data — personal and business information contained in or derived from payroll processing, including worker identifiers, compensation, tax withholdings, deductions, and payment instrument details (in truncated form), used to generate reports within the Service.
  • Personal Information — information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household, as such term (and equivalent terms such as “personal data”) is defined under applicable privacy law.
  • Sensitive Personal Information — a subset of Personal Information including, where present, government identifiers and financial account information, as defined under applicable law.
  • Process / Processing — any operation performed on Personal Information, including collection, use, storage, disclosure, and deletion.
  • Service Provider / Processor — an entity that Processes Personal Information on behalf of, and at the direction of, another party, for a business purpose and under contractual restrictions.
  • Business / Controller — the entity that determines the purposes and means of Processing Personal Information.
  • Sub-Processor — a third party engaged by MoonStone to Process Personal Information in support of the Service.

4.Our Role & Responsibilities ↑ top

MoonStone’s role under applicable privacy law depends on the category of data:

  • For Payroll Data processed to generate reports for Clients, MoonStone generally acts as a Service Provider / Processor on behalf of the Client, which acts as the Business / Controller. MoonStone Processes such data only to provide the Service and as otherwise permitted by its agreements with Clients and by law, and does not sell it or use it for its own independent commercial purposes.
  • For Account Data relating to the operation, security, and administration of the Service, MoonStone generally acts as a Business / Controller.

Where MoonStone acts as a Service Provider, individuals seeking to exercise privacy rights with respect to their Payroll Data should ordinarily direct their requests to their employer or the relevant Client, and MoonStone will support the Client in responding as required by law and the applicable agreement.

5.Information We Collect ↑ top

The Service is designed around the principle of data minimization. We collect and Process the following categories of information:

CategoryExamplesPrimary purpose
IdentifiersWorker name, employee ID, Client/branch identifiers; for Authorized Users, username and display nameGenerate and route reports; authenticate users
Contact / location dataWorker mailing address where present in source files (e.g., for remittance stubs)Produce earnings statements and check images
Compensation & payroll dataGross and net pay, hours/units, earnings, tax withholdings, deductions, pay-period and check datesProduce payroll reports and registers
Financial account information (truncated)Bank name and the last four digits only of account numbers; check and payment metadataIndicate payment method on statements
Government identifiers (truncated)Last four digits only of Social Security NumbersDisambiguate workers on reports
Authentication & security dataHashed password, multi-factor (TOTP) enrollment secret, passkey public keys and counters, single-use backup codes (hashed), failed-attempt and lockout stateAuthenticate users; protect accounts
Device, log & usage dataIP address, session identifiers, timestamps, authentication and administrative events, and similar technical logsSecurity, auditing, and troubleshooting

Data minimization note: The Service is engineered so that full Social Security Numbers and full bank account numbers are not retained — only the last four digits are stored and displayed. We do not knowingly collect information from individuals under 16, and the Service is not intended for personal or household use.

6.Sources of Information ↑ top

We obtain information from the following sources:

  • From Clients and their payroll systems. Payroll Data is imported from periodic exports generated by the Client’s payroll/staffing software (currently Avionté) and uploaded to the Service by authorized personnel.
  • From Authorized Users. Account Data is provided when accounts are created and when users authenticate, enroll in multi-factor authentication, or register passkeys.
  • Automatically. Device, log, and usage data are generated automatically when the Service is accessed.

7.How We Use Information ↑ top

We Process information for the following business purposes:

  • To provide, maintain, and operate the Service, including generating, formatting, and distributing payroll reports;
  • To authenticate users, enforce role-based access, and secure accounts (including multi-factor authentication and passkeys);
  • To monitor for, investigate, and prevent unauthorized access, fraud, and other security incidents;
  • To maintain audit and activity logs for security, compliance, and accountability;
  • To troubleshoot, debug, and improve the reliability of the Service;
  • To comply with legal obligations and enforce our agreements; and
  • For any additional purpose disclosed to you or directed by the applicable Client.

We do not use Payroll Data for advertising, and we do not sell Personal Information or share it for cross-context behavioral advertising.

8.Disclosures & Third-Party Service Providers ↑ top

We disclose information only as necessary to operate the Service and as permitted by law:

  • To the applicable Client and its authorized administrators and users, who access reports relating to their own organization;
  • To Sub-Processors that provide infrastructure and supporting services under contract, listed below;
  • For legal and safety reasons, such as to comply with law, respond to lawful requests, or protect rights, property, and safety; and
  • In connection with a corporate transaction, such as a merger, acquisition, or asset transfer, subject to appropriate safeguards.

Current Sub-Processors

ProviderFunctionLocation
Hosting provider — HostGator / AWSApplication and database hosting (shared web hosting)United States

The Client’s upstream payroll/staffing system (currently Avionté) is the source of Payroll Data and operates under the Client’s own agreements and privacy practices; it is not a Sub-Processor engaged by MoonStone for the Service.

9.Cookies & Similar Technologies ↑ top

The Service uses only the minimum cookies necessary to function. Specifically, it sets a single strictly necessary session cookie that maintains your authenticated session and protects against cross-site request forgery. This cookie is essential to the Service and cannot be disabled without preventing sign-in.

The Service does not use advertising cookies, third-party analytics, tracking pixels, or cross-context behavioral advertising technologies. Because only strictly necessary cookies are used, a cookie consent banner is generally not required under United States privacy law; however, your browser settings allow you to manage cookies, and blocking the session cookie will prevent the Service from operating.

CookiePurposeTypeDuration
Session cookieAuthenticated session & CSRF protectionStrictly necessarySession / on sign-out

10.California Privacy Rights (CCPA/CPRA) ↑ top

This section provides information required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), for California residents. Where MoonStone acts as a Service Provider for a Client, it Processes Personal Information on the Client’s behalf and subject to contractual restrictions; California residents should generally direct rights requests concerning their Payroll Data to their employer or the relevant Client.

Categories of Personal Information collected

In the preceding 12 months, we have collected the categories described in the Information We Collect section, which correspond to the following CCPA categories: identifiers; personal records (e.g., financial information in truncated form, employment and compensation information); characteristics that may be protected under law (only insofar as incidentally present in payroll records); commercial-type information (payment metadata); internet or network activity (logs); and professional or employment-related information. We collect Sensitive Personal Information only in truncated form (last four digits of government and financial account identifiers) and authentication credentials.

Sources, purposes, and disclosures

The sources of this information are described in Sources of Information, the purposes in How We Use Information, and the categories of recipients in Disclosures & Third-Party Service Providers. We disclose Personal Information to Sub-Processors and to the applicable Client for business purposes.

No sale or sharing of Personal Information

MoonStone does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the preceding 12 months.

Use of Sensitive Personal Information

We use Sensitive Personal Information (in the limited, truncated forms described above, plus authentication credentials) only as necessary to provide and secure the Service. We do not use it to infer characteristics about an individual. Under the CCPA, this limited use does not trigger the right to limit further use.

Your California rights

Subject to verification and to MoonStone’s role as Service Provider where applicable, California residents may have the rights to: know and access the Personal Information collected about them; correct inaccurate Personal Information; delete Personal Information; and not receive discriminatory treatment for exercising these rights. To exercise these rights, see Your Privacy Rights & Requests. We will not discriminate against you for exercising your rights.

11.Your Privacy Rights & Requests ↑ top

Depending on your jurisdiction and your relationship to the data, you may have rights to access, correct, delete, restrict, or obtain a portable copy of Personal Information, and to object to certain Processing.

How to submit a request

Submit requests to info@moonstone-peo.com. If your request concerns Payroll Data held on behalf of your employer, we will direct you to, or coordinate with, the relevant Client.

Verification

To protect your information, we will take reasonable steps to verify your identity before acting on a request, which may include confirming information already in our records. We will not use information provided for verification for any unrelated purpose.

Authorized agents

You may use an authorized agent to submit a request, provided the agent furnishes proof of authorization and we can verify your identity.

Timing

We will acknowledge and respond to verifiable requests within the time required by applicable law (for example, generally within 45 days under the CCPA, with the possibility of an extension).

12.Electronic Communications Consent ↑ top

By using the Service, you consent to receive communications from us electronically, including notices, disclosures, and records relating to the Service, delivered through the Service, by email, or by other electronic means. You agree that electronic communications satisfy any legal requirement that such communications be in writing. You may withdraw consent to receive non-essential electronic communications by emailing your administrator at ops@moonstone-peo.com; however, certain communications are integral to the Service and cannot be waived while you maintain an account. To access and retain electronic records, you need a device with internet access, a current web browser, and the ability to view and save HTML and PDF files.

13.International Data Transfers ↑ top

The Service and its data are hosted and Processed in the United States. The Service is intended for use by authorized business users in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and Processed in the United States, where data-protection laws may differ from those in your location.

14.Data Retention Schedule ↑ top

We retain Personal Information for as long as necessary to provide the Service, to comply with legal, tax, and payroll-recordkeeping obligations, to resolve disputes, and to enforce our agreements. Retention of Payroll Data is also governed by our agreements with Clients and by the Client’s own retention obligations. Indicative periods are set out below and must be confirmed.

Data categoryIndicative retentionBasis
Payroll Data & generated reports3 years minimum, or as required by lawService provision; legal/payroll recordkeeping
Account Data3 years minimum, or as required by lawService provision; security
Authentication & audit logs3 years minimum, or as required by lawSecurity, accountability
Backups3 years minimum, or as required by lawResilience / disaster recovery

When information is no longer required, we delete or de-identify it using reasonable measures.

15.Information Security Statement ↑ top

MoonStone maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information Processed through the Service, appropriate to the nature of the data. These safeguards include encryption of data in transit, strong authentication, role-based access controls, data minimization, and logging and monitoring, as further described below. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; however, we work to protect information using reasonable and appropriate measures and to continuously improve them.

16.Detailed Security Practices ↑ top

  • Encryption in transit. All access to the Service occurs over HTTPS/TLS.
  • Credential protection. Passwords are stored only as salted one-way hashes (bcrypt). Plaintext passwords are never stored.
  • Multi-factor authentication. MFA is required for accounts, using time-based one-time passcodes (TOTP) and/or passkeys, with single-use backup codes for recovery. See the MFA & Passkey Policy.
  • Passkeys (WebAuthn/FIDO2). Passkeys use public-key cryptography; only public keys are stored by the Service, and private keys never leave the user’s device.
  • Brute-force protection. Repeated failed verification attempts trigger temporary account lockout.
  • Session security. Session identifiers are regenerated upon authentication, scoped with secure cookie attributes, and invalidated on sign-out.
  • Least-privilege access. Access is governed by defined roles (internal staff, delegated administrators, and Client users) so that users see only the data within their authorized scope.
  • Data minimization. Sensitive identifiers are truncated (last four digits of Social Security and bank account numbers); full values are not retained.
  • Application protections. The Service uses parameterized database queries and anti-CSRF tokens, and validates uploaded files.
  • Logging & monitoring. Authentication and administrative events are logged for security and accountability; see the Audit Logging Policy.

17.Multi-Factor Authentication & Passkey Policy ↑ top

To protect access to payroll information, the Service requires multi-factor authentication for accounts.

  • Enrollment. On first sign-in, users enroll an authenticator app (TOTP) and are issued single-use backup recovery codes, which must be stored securely.
  • Passkeys. Users may additionally register one or more passkeys (WebAuthn) tied to their device’s biometric or screen-lock. A verified passkey satisfies multi-factor authentication on its own and may be used to sign in without a password. Passkeys are optional; the authenticator app and backup codes remain available as fallbacks.
  • Recovery. A user who loses access to their authenticator may use a backup code or have an administrator reset their MFA enrollment. Administrators must verify identity before performing a reset.
  • User responsibilities. Users are responsible for safeguarding their credentials, authenticator devices, passkeys, and backup codes, and for not sharing them. Suspected compromise must be reported promptly (see How to Contact Us).
  • Administration. MoonStone may set, adjust, or enforce authentication requirements, including lockout thresholds and session limits, to maintain security.

18.Audit Logging Policy ↑ top

The Service maintains logs of security-relevant and administrative events, which may include sign-in attempts (successful and failed), multi-factor verification, account lockouts, passkey registration and use, administrative actions on user accounts, and report-generation and download activity, together with associated timestamps and technical metadata such as IP address. These logs are used to secure the Service, investigate suspected misuse, support compliance, and provide accountability. Access to logs is restricted to authorized personnel. Logs are retained for the period stated in the Data Retention Schedule and are protected by the same safeguards as other data.

19.Incident Response & Breach Notification ↑ top

MoonStone maintains procedures to detect, respond to, and remediate security incidents. In the event of a security incident affecting Personal Information, we will investigate, take steps to contain and mitigate the incident, and assess applicable notification obligations. Where MoonStone acts as a Service Provider, we will notify the affected Client(s) without undue delay so that they may meet their own obligations, and we will reasonably cooperate in their response. Where required by law, affected individuals and/or authorities will be notified within the timeframes mandated by applicable law.

20.Acceptable Use Policy ↑ top

The Service is for authorized business use only. By accessing it, you agree that you will not, and will not attempt to:

  • Access the Service or any data without authorization, or beyond the scope of your authorization;
  • Share, transfer, or expose your credentials, passkeys, or backup codes, or allow another person to use your account;
  • Access, download, or use payroll or personal information except as necessary for your legitimate, authorized business purpose;
  • Probe, scan, or test the vulnerability of the Service, or breach or circumvent security or authentication measures, without express written authorization;
  • Introduce malware, interfere with or disrupt the Service, or impose an unreasonable load on it;
  • Copy, scrape, reverse engineer, or create derivative works from the Service except as permitted by law or with written consent;
  • Use the Service to violate any law or the rights of any person, or for any unlawful, fraudulent, or harmful purpose; or
  • Remove, obscure, or alter any notice or security feature.

Activity on the Service may be monitored and logged. Violations may result in suspension or termination of access, and may be reported to the relevant Client and to law enforcement, and may give rise to civil or criminal liability.

21.Terms of Use ↑ top

License to access

Subject to your compliance with this Policy, MoonStone grants you a limited, revocable, non-exclusive, non-transferable right to access and use the Service for authorized business purposes. All rights not expressly granted are reserved.

Accounts & responsibility

You are responsible for all activity under your account, for maintaining the confidentiality of your credentials, and for the accuracy of information you submit. You must promptly notify us of any unauthorized use.

Intellectual property

The Service, including its software, design, and content (excluding Client data), is owned by MoonStone or its licensors and is protected by intellectual-property laws. Reports generated for a Client contain that Client’s data and are made available for the Client’s use.

Feedback

If you provide suggestions or feedback, you grant MoonStone a perpetual, royalty-free license to use it without restriction or obligation to you.

Suspension & termination

We may suspend or terminate access at any time, including for violation of this Policy or to protect the Service. Provisions that by their nature should survive termination will survive.

Third-party & source systems

The Service relies on data exported from third-party systems (such as the Client’s payroll software). MoonStone is not responsible for the accuracy or availability of third-party systems or for data as originally recorded in them.

22.Employee Self-Service Provisions ↑ top

Where the Service makes reports or statements available to workers, such access is provided on behalf of, and as configured by, the worker’s employer or the relevant Client. If you are a worker whose Payroll Data appears in the Service:

  • Your access (if any) and the scope of information available to you are determined by your employer/Client;
  • Requests to access, correct, or obtain copies of your payroll records should ordinarily be directed to your employer/Client, who is the appropriate party to act on such records; and
  • MoonStone will support your employer/Client in responding to such requests as required by law and the applicable agreement.

This Policy does not alter the rights and obligations between you and your employer.

23.Employer & Administrator Responsibilities ↑ top

Clients and their administrators who use the Service agree that they:

  • Are responsible for establishing a lawful basis for providing worker Personal Information to the Service and for the accuracy and lawfulness of the data they upload;
  • Will provide any notices to, and obtain any consents from, their workers as required by law;
  • Are responsible for administering their own users’ access on a least-privilege basis, promptly disabling access when no longer appropriate, and conducting periodic access reviews;
  • Will instruct MoonStone only to Process Personal Information consistent with applicable law and the parties’ agreement; and
  • Will respond, with MoonStone’s reasonable support, to data-subject requests concerning data for which the Client is the Business/Controller.

24.Disclaimers & Limitation of Liability ↑ top

Disclaimer. Except as expressly stated in a written agreement, the Service is provided “as is” and “as available,” without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, accuracy, and non-infringement. MoonStone does not warrant that the Service will be uninterrupted, error-free, or secure.

Limitation of liability. To the maximum extent permitted by law, MoonStone and its affiliates will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenues, data, or goodwill, arising out of or relating to the Service. To the maximum extent permitted by law, MoonStone’s total aggregate liability arising out of or relating to the Service will not exceed $100,000.00.

Allocation of risk. The disclaimers and limitations in this section are an essential basis of the parties’ agreement.

25.Governing Law & Dispute Resolution ↑ top

This Policy and any dispute arising out of or relating to it or the Service are governed by the laws of the State of California, without regard to its conflict-of-laws rules. The exclusive venue for disputes will be the state and federal courts located in Orange County, California, and you consent to their jurisdiction. Where MoonStone and a Client have a separate written agreement, that agreement’s governing-law and dispute-resolution terms control as to that Client.

26.DMCA / Copyright Notice ↑ top

MoonStone respects intellectual-property rights. The Service is a private, access-controlled portal and does not host publicly posted, user-generated content; the DMCA notice-and-takedown framework therefore has limited applicability.

27.Accessibility Statement ↑ top

MoonStone is committed to making the Service usable by as many people as possible and aims to conform to the Web Content Accessibility Guidelines (WCAG) 2.1, Level AA, as a target standard. We continue to work to improve accessibility. If you encounter an accessibility barrier or need an accommodation, please contact us at access@moonstone-peo.com and we will work with you to provide the information or functionality you need.

28.Changes & Revision History ↑ top

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, provide notice through the Service. Your continued use after the effective date of a change constitutes acceptance of the updated Policy, except where additional consent is required by law.

VersionDateSummary of changes
1.06/24/2026Initial publication.

29.How to Contact Us ↑ top

For questions about this Policy, to exercise privacy rights, or to report a security concern, contact:

MoonStone PEO, Inc.
760 N Euclid St Ste 207
Anaheim, CA 92801
Email: info@moonstone-peo.com

If your inquiry concerns Payroll Data held on behalf of your employer, we may direct you to the relevant Client.

30.Developer Implementation Guidance ↑ top

This section is operational guidance for whoever deploys and maintains the Service. It is not part of the published legal terms and can be removed from the public page if preferred.

  • Placement. This page lives at /privacy.php and is already linked from the login screen and the Authorized-Access acknowledgment screen. Add a footer link on authenticated pages as well.
  • Acceptance & acknowledgment. The portal already records a per-user, timestamped acknowledgment of the Authorized-Access terms (users.acceptable_use_ack) on first sign-in. To bind acceptance of these Terms of Use and Acceptable Use Policy, reference this page from that acknowledgment screen.
  • Versioning & re-consent. On material updates, bump $LEGAL_VERSION and the effective/updated dates at the top of this file. To force re-acknowledgment, add a users.legal_ack_version column and compare it to $LEGAL_VERSION at login, clearing the acknowledgment when it differs.
  • Cookies. The app sets only one strictly necessary session cookie, so a consent banner is generally not required under U.S. law. If analytics or any non-essential technology is added later, revisit Section 9 and implement consent.
  • Sub-processors & DPAs. Keep Section 8 current. Execute a data-processing agreement with the hosting provider; no ad-network DPAs are needed because no third-party trackers are loaded.
  • Logging & retention. Ensure the audit-log table and retention windows match Sections 14 and 18. Avoid logging full sensitive values; the app already truncates Social Security and account numbers to the last four digits.
  • Legal review. Company-specific values have been completed. Have counsel give a final review before go-live, paying particular attention to Sections 10, 14, 19, 24, and 25.
← Back to sign in