Privacy Policy for ComplianceKit
This policy explains what we collect, why we collect it, how we use it, and how public legal pages stay separate from private workspace data.
At a glance
Private workspace data stays private
ComplianceKit is built around a clear split between private audits, drafts, billing records, and the public legal pages a user chooses to publish.
Product scope
Website audits, document drafts, hosted legal pages, billing, and support.
Public boundary
Only published legal pages are public. Private audits and drafts stay in the workspace.
Contact
Support channel in the app footer
Table of contents
Jump to the section you need
Section
Introduction
ComplianceKit is a software product that helps users scan public websites, review launch-readiness signals, generate document drafts, and publish selected legal pages. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the service.
It applies to the ComplianceKit website, app, and related services operated by the ComplianceKit team. It is meant to be clear enough for launch review and later legal review, but it is not a substitute for counsel.
Section
Information we collect
We collect information that users provide directly, information generated by product use, and technical information needed to run the service.
Account information
- Email address and account profile details.
- Authentication and session information.
- Workspace membership and role information.
- Settings, preferences, and product configuration choices.
Website and audit information
- Submitted website URLs and normalized URLs.
- Public crawl results, crawl status, and lifecycle metadata.
- Pages checked, failed page status, and safe evidence snippets.
- Findings, recommendations, and generated report data.
Document and workspace information
- Generated document drafts and document edits.
- Version history and published document content.
- Legal center settings and project or workspace names.
Billing information
- Stripe checkout session IDs and related payment references.
- Payment status, price, amount, currency, and entitlement state.
- ComplianceKit does not store full payment card numbers. Stripe processes payment details on our behalf.
Technical and usage information
- IP address where available through hosting, authentication, or security logs.
- Device and browser information.
- Log data, analytics events, product usage events, and error or performance data.
Cookies and local storage
- Authentication and session cookies.
- App preference storage.
- Analytics cookies if PostHog is configured.
- Stripe and Supabase related session behavior where applicable.
Support and contact information
- Messages you send to us.
- Email and support communications.
Section
Information we do not intentionally collect
We do not intentionally collect the following unless a user includes it in workspace content or support communications:
- Raw full website HTML by default.
- Payment card numbers.
- Government ID numbers.
- Sensitive personal information.
- Children's data knowingly.
If a user enters sensitive data into a document, support message, or published page, that content may be processed as part of the service.
Section
How we use information
We use information to provide the product and keep it safe and reliable.
- Run audits, previews, reports, and crawl summaries.
- Generate document drafts and save workspace state.
- Publish the legal pages users choose to make public.
- Authenticate users and manage workspace access.
- Process payments and entitlement unlocks through Stripe.
- Prevent fraud, abuse, and security issues.
- Improve the product using analytics and usage signals.
- Respond to support requests and fulfill legal obligations.
Section
Legal bases and business purposes
Depending on where you and we are located, we may rely on one or more of the following bases or purposes:
- Contract and service delivery, because the product has to process data to provide the requested features.
- Legitimate interests and product security, such as protecting the service, preventing abuse, and improving reliability.
- Consent where required, such as for optional analytics or marketing in jurisdictions that require it.
- Legal obligations, such as tax, accounting, recordkeeping, or lawful requests.
We do not claim that one legal basis applies in every situation or jurisdiction.
Section
Public legal pages
Private audit data stays private. Only selected and published documents are exposed on public legal pages. Those pages may be visible to anyone with the URL, so users should review content carefully before publishing it.
Public legal center pages are separate from workspace data and should not be treated as a dump of the full private audit or document history.
Section
Data retention
We keep information for as long as needed to provide the service, satisfy legal requirements, and support security and operations.
- Account and workspace data are retained while the account is active or as needed for service delivery.
- Audit, report, and document data are retained while needed for the product and workspace history.
- Billing records are retained as required for tax, accounting, fraud prevention, or dispute handling.
- Logs may be retained for a limited time for security, debugging, and reliability.
- Some data may remain in backups or system logs for a limited period after deletion requests are processed.
Where exact retention periods are not yet finalized, this policy uses general language that can be updated later.
Section
Security
We use access controls, server-side authorization, workspace boundaries, and encryption in transit to protect the service. Private audit data and public legal pages are handled through separate boundaries so that published content does not expose workspace-only details.
For more detail about operational security practices, see our Security page.
No system is perfectly secure, and we cannot guarantee absolute security.
Section
International transfers
Because our providers and infrastructure may operate in different countries, your information may be processed in countries other than the one where you live.
Section
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to some processing.
- You can contact us to ask about the information we hold.
- You can ask us to correct or delete information, subject to legal and operational limits.
- You can ask questions about cookies or analytics if those features are enabled.
- If marketing features are added later, you can opt out of marketing messages.
We may need to verify requests before taking action, and some data may still be kept when the law allows or requires it.
Section
Children
The service is not intended for children under 13, or under 16 where local law uses a higher age threshold for online services.
Section
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and change the "Last updated" date above.