Legal

Privacy policy

Last updated September 5, 2026

The short version. We built this so we never receive your consumers' personal information. Records are normalized and hashed inside your browser before anything is transmitted. We hold one-way hashes, work-item identifiers, status codes, and timestamps — not names, emails, phone numbers, or addresses.

Information we collect

From you, our customer: company name, your name and work email, your data broker registration identifiers, billing information (processed by our payment processor — we never store card numbers), and support communications.

From your use of the service: SHA-256 hashes of consumer identifiers derived in your browser; DROP work-item identifiers, list types, match results, status codes, exemption notes you write, and timestamps; your suppression list, held as hashes; and operational logs covering requests, errors, and performance.

From the design-partner form on this site: the company name, email address, and any note you submit.

Information we do not collect

There is no upload path in the product for raw consumer records, because the product does not need one.

How we use information

To provide the service — run the matching cycle, track deadlines, generate filings, and maintain your evidence log — and to support you, bill you, secure and improve the service, and meet our own legal obligations. We do not sell or share personal information, we do not use your data to train models, and we do not use your data to benefit other customers.

Our role under privacy law

Where you are a business or data broker and we process information on your behalf, we act as a service provider under the CCPA and as a processor under comparable laws. We process that information only on your documented instructions and only to provide the service. Separate contractual terms govern this relationship.

Sub-processors

ProviderPurposeLocation
Vercel Inc.Application hosting and loggingUnited States

We keep this list current and will give notice before adding a sub-processor that processes customer data.

Retention

Account and billing records are retained while your account is active and afterward as required for tax and legal purposes. Compliance records — your evidence log, cycle history, and suppression list — are retained for the life of the account, because you need them for audits beginning in 2028. On termination you may export everything; we then delete it within 30 days unless you ask us to retain it or law requires otherwise.

Security

Data in transit is encrypted with TLS. The hash-only architecture is our primary control: a breach of our systems does not expose consumer identities, because we do not hold them. Production access is limited to personnel who need it. No system is perfectly secure, and we do not claim otherwise.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to withdraw consent. Contact us and we will respond within the period the applicable law requires. Note that for hashed consumer identifiers we generally cannot determine whose data is whose — that is by design — so requests about consumer records should be directed to the data broker who holds them.

Children

The service is sold to businesses and is not directed to children.

Changes

We post changes here and update the date above. Material changes are notified to account holders by email.

Contact

Questions about this policy: privacy@privacyclock.com