Privacy Policy
How YourStanding collects, uses, shares, and retains account, billing, document, and product-usage data.
Information We Collect
We collect information you provide directly, including:
- Account information: name, email address, password, and sign-in details
- Organization and compliance data: business name, locations, tracked compliance items, dates, and related notes
- Documents you upload: files, filenames, metadata, and extraction results
- Billing information: subscription and customer records needed to manage paid plans. Payment card details are processed by Stripe and are not stored directly in our app database.
- Communications and subscriptions: messages you send to support and email subscription records when you ask to receive updates
We also collect limited technical and usage information automatically, including:
- IP address, user agent, and request metadata for security, fraud prevention, and rate limiting
- Browser, device, and page activity information such as pages viewed and features used
- Product analytics and session diagnostics collected through PostHog to understand usage, triage issues, and improve the service
How We Use Your Information
We use personal information to operate the product and support the people using it. That includes:
- Creating and securing accounts, organizations, and sign-in sessions
- Providing tracking, reminders, document storage, and related compliance workflows
- Processing uploaded document content with automated extraction tools, including AI models running on our infrastructure providers, when you use document auto-fill or extraction features
- Processing subscriptions and billing events through Stripe
- Sending transactional and relationship emails such as verification, password reset, invitation, and reminder emails
- Responding to support requests and service issues
- Measuring product usage, understanding where users struggle, and investigating bugs, abuse, or security events
- Complying with legal, tax, accounting, and record-keeping obligations
Data Storage and Security
Your data is stored on Cloudflare infrastructure. Documents are stored in Cloudflare R2. Database records are stored in Cloudflare D1. All connections use HTTPS encryption, and we apply access controls, security headers, and rate limiting to protect your data.
Third-Party Services
We use the following service providers to run the product:
- PostHog: product analytics and session diagnostics
- Stripe: subscription and payment processing (Stripe Privacy Policy)
- Resend: email delivery
- Cloudflare: hosting, database, object storage, edge delivery, and related infrastructure
We may also receive basic account details from an identity provider if you choose to sign in with a supported social login method.
Data Sharing
We do not sell, rent, or trade your personal information. We share data only with the services listed above, as needed to provide the Service or when required by law.
Retention
We retain information for as long as it is needed to operate the service, maintain security and accounting records, resolve disputes, and meet legal obligations. Because the product is still evolving, some retention periods are based on operational need rather than a single fixed timeline for every category.
- Account and profile data: generally kept while your account is active and for a limited period afterward as needed for security, fraud prevention, support, and legal recordkeeping
- Billing and subscription records: retained as needed for accounting, tax, fraud, and reconciliation purposes even after a paid subscription ends
- Uploaded documents and related extraction data: kept until you delete them, your organization deletes them, or the underlying account or organization is deleted, subject to temporary backup or recovery copies
- Analytics, security logs, and session diagnostics: retained for operational analysis, troubleshooting, and abuse prevention, then trimmed, aggregated, or removed under our internal operational limits and vendor retention settings
- Email-subscriber records: kept until you unsubscribe or we decide the subscription list is no longer needed, and we may keep limited suppression history to honor future unsubscribe requests
Your Choices and Privacy Requests
You can:
- Access and update some account information from within the product
- Delete documents or other records you no longer want to keep in the service
- Manage or stop subscriber emails through the unsubscribe or preferences links we include where relevant
- Contact us at support@yourstanding.com to request access, correction, deletion, or other privacy help
If you contact us about a privacy request, please use the email address associated with your account when possible or tell us which account or organization the request is about.
We may ask you to verify control of that email address or complete the request from an authenticated account before we disclose account-specific information or act on the request.
California Notice
California residents can contact us at support@yourstanding.com to ask for access, correction, deletion, or other privacy help. This is the same manual support path we use for privacy requests generally today.
We do not currently provide a separate self-service privacy-rights portal, automated identity workflow, or formal statutory privacy program on this page. If our legal obligations or live request-handling process materially change, we will update this page to reflect the current process.
Changes to This Policy
We may update this policy from time to time to reflect product, operational, or legal changes. If we make a material update, we will revise the date on this page and may notify registered users through the product or by email when appropriate.
Contact
Privacy questions? Contact us at support@yourstanding.com.