Privacy Policy
What we collect
- Account data: name, email, password (stored only as a salted hash), time zone, notification preferences.
- Subscription data: the states and license types your plan covers, and your alert settings (categories, mutes, snoozes).
- Billing data: handled by Stripe. We store your Stripe customer reference — never your card number.
- Usage data: which alerts you open (so "new" badges work), login timestamps, and standard server logs.
What we deliberately do NOT collect
The regulatory content we monitor is public government information. We do not collect data about your business operations, inventory, customers, or sales. We do not sell or share personal information for advertising.
How we use it
To operate the service: matching public regulatory items to your covered states and license types, sending the alerts you've opted into, billing, and support. That's it.
Security
Data is encrypted in transit and at rest. Customer data is isolated per organization at the database layer, enforced and machine-verified on every schema change. Alert and evidence history is append-only. Access to production systems uses short-lived credentials; no shared passwords.
Retention
Account and alert history are retained while your account is active and for [90 days ⚖] after closure, then deleted, except records we must keep for tax/accounting. Archived copies of public government pages (our evidence record) are retained per our document-retention policy as business records — they contain public information, not your personal data.
Your choices
You can update or delete profile details, change notification settings, and cancel anytime from your dashboard. Email support@cann.dev to request account deletion or a copy of your data.
Third parties we rely on
Amazon Web Services (hosting, in the United States), Stripe (payments), and email delivery infrastructure. Each processes data only to provide their service to us.
Contact
[COMPANY], [ADDRESS] — support@cann.dev