Privacy Policy
Effective September 13, 2026
ComplyCue (“ComplyCue,” “we,” “us,” or “our”) provides compliance tracking software that helps businesses monitor licenses, permits, insurance policies, and other regulatory obligations. This Privacy Policy explains what information we collect through our website and application at complycue.com (the “Service”), how we use it, and the choices you have.
1. Information we collect
We collect information in three ways:
- Account and organization data. Name, work email, password (hashed by our authentication provider, never stored in plain text), business name, entity type, industry, employee count, and business location details you provide during signup and onboarding.
- Compliance documents and extracted data. Licenses, permits, insurance certificates, bonds, and related documents you upload to your Compliance Vault, plus the fields our AI extraction pipeline reads from them (license numbers, issue and expiration dates, issuing agency) and a confidence score per field.
- Usage and device data. Log data, IP address, browser type, pages visited, and interactions with the free License & Permit Checker, collected via first-party analytics events to improve the Service.
2. How we use your information
- To operate your compliance dashboard: matching regulatory requirements to your business, generating obligations, and scheduling renewal reminders.
- To process documents you upload, including AI-assisted field extraction, so you don't have to enter data manually.
- To send transactional email — renewal reminders, account notifications, and (if you use the free checker) your results and relevant product updates.
- To maintain an audit log of account and compliance-record activity for security and accountability.
- To improve our regulatory knowledge base, product, and free tools such as the License & Permit Checker.
We do not sell your personal information or your organization's compliance data to third parties.
3. The free License & Permit Checker
If you use the free checker without creating an account, we store the business details you enter (business type, city, county, state, employee count), the email address you provide, and a snapshot of the generated report, so we can send you your results, follow up about relevant coverage, and improve the accuracy of our regulatory matching. This data is not visible to other users and is handled with the same security controls described below.
4. Data security
ComplyCue is built around a defense-in-depth model appropriate for sensitive business compliance data:
- Encryption in transit and at rest. All traffic to the Service is encrypted via TLS. Documents and database records are encrypted at rest by our infrastructure provider.
- Row-level security (RLS). Every database table containing customer data enforces PostgreSQL row-level security policies scoped to your organization, so one customer's data is never queryable by another's session credentials.
- Private document storage. Uploaded files live in a private storage bucket, organized under your organization's unique ID, accessible only to authenticated members of your organization with the appropriate role.
- Audit logging. Meaningful changes to compliance records — status changes, document uploads, team membership changes — are written to an append-only activity log visible to your organization's admins.
- Role-based access control. Access to documents and obligations is gated by organization role (owner, admin, manager, viewer), enforced at the database layer, not just in the UI.
See our Security page for more detail on our technical and organizational safeguards.
5. Data retention
We retain account and compliance data for as long as your account is active. If you close your account, we delete or anonymize personal information and organization data within a reasonable period, except where retention is required for legal, tax, or fraud-prevention purposes. Free checker submissions that never convert to an account are retained for product improvement and may be deleted upon request.
6. Your choices and rights
- Access, correct, or export your account and compliance data at any time from your dashboard settings.
- Request deletion of your account and associated data by contacting us at privacy@complycue.com.
- Opt out of non-essential email communications via the unsubscribe link in any marketing email; transactional renewal alerts tied to obligations you've created cannot be disabled without disabling the underlying reminder.
- Depending on your jurisdiction (e.g. California under the CCPA, or the EU/UK under the GDPR), you may have additional rights to access, delete, or restrict processing of your personal information. Contact us to exercise these rights.
7. Sub-processors
We use a limited set of infrastructure providers to operate the Service, including our database and authentication provider (Supabase), hosting provider (Vercel), transactional email provider (Resend), and payment processor (Stripe). Each is bound by contractual data protection obligations and processes data only as necessary to provide their service to us.
8. Children's privacy
The Service is intended for business use by adults and is not directed to individuals under 18. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to account owners or via a notice within the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
10. Contact us
Questions about this policy or your data can be sent to privacy@complycue.com.
11. Not legal advice
ComplyCue provides compliance tracking assistance and general information about regulatory requirements. It is not a substitute for legal, tax, or professional advice. Requirements marked "Needs Verification" or "Likely Applicable" have not been confirmed against an authoritative source and should be independently verified with the relevant agency before you rely on them.