Legal
How ComplianceOS collects, uses, and protects your data and vendor information.
Last updated: July 13, 2026
ComplianceOS (“we”, “us”, or “our”) is a vendor compliance management platform that helps operations teams onboard vendors, verify documents, track expirations, and route payments. We take your privacy and the security of your vendor data seriously.
This Privacy Policy explains what information we collect, how we use it, how we store and protect it, and the choices you have. By using the Service, you consent to the practices described in this policy.
When you create an account, we collect your full name, work email address, phone number (if provided), job title, company name, industry type, company size, and country. This information is used to set up and administer your workspace.
When you use the Service to manage vendors, you and your vendors may upload documents such as insurance certificates, business licenses, certifications, tax forms (W-9s), and other compliance documentation. This data is stored securely and is accessible only to authorized users within your workspace.
We automatically collect certain usage information when you interact with the Service, including IP address, browser type, device information, pages visited, timestamps, and interaction data. This information is used to operate, maintain, and improve the Service.
When you use payment features, payment data is processed by Stripe. ComplianceOS does not store full credit card numbers or bank account details. We may store limited payment metadata (such as transaction status and vendor connection status) for record-keeping purposes.
We use the information we collect to:
We do not sell your personal information or vendor data to third parties.
All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Documents and files uploaded to the Service are stored in encrypted private storage buckets. Access to storage is restricted to authenticated sessions.
Our database enforces row-level security (RLS), which means that each workspace can only access its own data. Users in one workspace cannot see or interact with data belonging to another workspace. Access is scoped per tenant and per user role.
Access to the Service is controlled through authenticated sessions and role-based permissions (admin, compliance reviewer, finance). Internal access to production systems is restricted to authorized personnel and is logged and monitored.
We regularly review our security practices and infrastructure. However, no system is perfectly secure, and we cannot guarantee the absolute security of your data. You are responsible for maintaining strong passwords and limiting access to authorized personnel within your organization.
We retain your vendor data and documents for as long as your account is active or as needed to provide the Service. When you cancel your account, we provide a reasonable period during which you can export your data. After this period, your data may be permanently deleted from our systems.
Certain documents may be subject to legal or regulatory retention requirements (for example, tax-related documents may need to be retained for several years). You are responsible for understanding and complying with any retention obligations specific to your industry and jurisdiction. We will retain data only as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.
The Service integrates with the following third-party providers. Each provider has its own privacy policy governing how it handles data:
We do not share your data with third parties for marketing or advertising purposes.
The Service uses cookies and browser local storage to maintain authentication sessions, remember user preferences, and analyze usage patterns. We use the following types:
You can control cookies through your browser settings. Disabling authentication cookies will prevent you from signing in to the Service.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at info@complianceos.us. We will respond within 30 days. We may need to verify your identity before processing your request.
If you use the Service in a healthcare context, you are responsible for ensuring that your use complies with the Health Insurance Portability and Accountability Act (HIPAA) and any other applicable health privacy laws. ComplianceOS is not a HIPAA Business Associate and does not knowingly store Protected Health Information (PHI). If you believe your use requires a Business Associate Agreement (BAA), please contact us before uploading any health-related data.
For logistics users, the Service may store DOT-related compliance documents such as operating authority records, safety ratings, and insurance certificates. You are responsible for ensuring that your use of the Service complies with Federal Motor Carrier Safety Administration (FMCSA) regulations and any other applicable transportation laws.
Regardless of your industry, you are responsible for ensuring that you have the legal right to collect, store, and process any vendor data you upload to the Service, and that your use complies with all applicable privacy and data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional regulations.
Your data may be stored and processed in the United States or other countries where our infrastructure providers operate. If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to these transfers. We take reasonable measures to ensure that your data is protected in accordance with this Privacy Policy regardless of where it is processed.
The Service is intended for business use and is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will take steps to delete such information.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and, where appropriate, sending an email or in-app notification. We encourage you to review this policy periodically. Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or our data practices, please contact us at: