Legal
Privacy Policy
Effective May 18, 2026 · Last updated July 6, 2026
1. Who we are
“Complidar” (referred to here as we, us, or the Service) is operated as a sole-proprietor product pending entity formation. The Service runs an automated diagnostic scan of public web pages and generates a report describing potential legal-compliance risks. This Privacy Policy describes the personal information we handle when you visit the Service, run a free scan, purchase a paid audit, or contact us.
Data controller. For the purposes of the EU and UK General Data Protection Regulation (GDPR), the controller responsible for your personal information is Complidar, operated as a sole proprietorship based in the United States, reachable at info@complidar.com.
Data Protection Officer. We have not appointed a Data Protection Officer, and are not required to under Article 37 GDPR: our activities do not involve large-scale systematic monitoring of individuals or large-scale processing of special categories of data. Privacy questions can be sent to info@complidar.com.
EU / UK representative. Complidar is established in the United States and not in the EU or UK. Our processing of EU/UK personal data is occasional, does not involve large-scale processing of special-category data, and is unlikely to result in a risk to your rights and freedoms, so we rely on the exemption in Article 27(2) of the GDPR and UK GDPR and have not appointed an EU or UK representative. EU and UK residents may contact us directly at info@complidar.com.
2. The information we collect
Information you provide directly:
- Domain you submit, the URL you enter into the scan form. We treat the domain itself as user-provided input, not personal data, but it is associated with the account that submits it.
- Email address, required at checkout (via Stripe Checkout) and on sign-in (we send a one-time magic link). We never ask for, accept, or store a password.
- Optional report-notification email, if you choose to enter an email on the scan-progress screen, we use it to send you one transactional email with that report’s headline results and a link to view it when the scan completes, and we create a passwordless account tied to that email so you can sign in and return to your report later. The scan is then saved to that account and retained until you delete it or ask us to erase your account (rather than expiring as an anonymous scan). We add your address to our marketing list only if you separately tick the opt-in box (unchecked by default); if you do, we retain it with the date you consented until you unsubscribe, and use it to send occasional product updates, which you can opt out of at any time.
- Optional metadata at quote request, if you request our “Fix It For Me” service, the notes field is stored alongside the request.
Information we collect automatically:
- IP address, recorded on free-scan submissions for rate limiting and abuse prevention; recorded on magic-link requests for the same reason. Retained for thirty (30) days then purged.
- Authentication session cookie, a single first-party cookie issued by our identity provider (Supabase Auth) keeps you signed in across page loads. No third-party advertising or analytics cookies are set unless you opt in (see section 4).
- Anonymous page-view counts, measured with Vercel Web Analytics, a cookieless, first-party service. It sets no cookies, stores nothing on your device, and does not follow you across other sites; visits are counted against a daily-rotating anonymized identifier and we only ever see aggregate numbers. It is on by default and turns off if you click Reject all in the cookie banner or your browser sends a Global Privacy Control signal (see section 4).
- Scan output, when you run a scan, our worker fetches the public pages of the domain you submitted and produces findings, crawl artifacts (HTML, network requests, cookies set by the scanned site, axe accessibility output), and an estimated liability range. This output is associated with your account if you are signed in, or with an anonymous scan record if you are not.
Payment information: we use Stripe to process payments. Stripe collects your card details directly; we never receive or store card numbers or full PAN data. We do store the Stripe customer ID and subscription metadata Stripe returns to us.
We do not collect special categories of personal data (race, religion, biometrics, health, etc.). If you submit any in the “notes” field of the Fix-It-For-Me form, please don’t, we’ll delete it on request.
3. How we use your information
We process the information above only for the purposes described here:
- To run the scan you requested and deliver the report.
- To authenticate you (magic link) and keep you signed in.
- To process payment, issue receipts, and manage your subscription.
- To prevent abuse (IP-based rate limits, fraud signals from Stripe Radar).
- To respond to support requests and Fix-It-For-Me quote requests.
- To improve the diagnostic detectors, but we use aggregated, de-identified findings data for this, not individual user records.
- To comply with legal obligations and respond to lawful requests.
We do not use your information to train any general-purpose machine-learning model and we do not allow our subprocessors to do so either.
4. Cookies and similar technologies
One cookie is strictly necessary: a first-party HTTP-only session cookie issued by Supabase Auth to keep you signed in. It is always on because the site cannot function without it.
We measure traffic with Vercel Web Analytics, a cookieless, first-party service. It sets no cookies and stores nothing on your device, so there is no stored identifier to consent to; it counts page views against a daily-rotating anonymized hash and cannot follow you across other sites. It runs by default, and we turn it off entirely when you click Reject all in the cookie banner (or its preferences panel) or your browser sends a Global Privacy Control signal (see section 15).
We also use the Meta (Facebook) Pixel, a third-party analytics-and-advertising technology that measures traffic and ad performance. It is strictly optional and off by default: the pixel does not load and sets no cookies unless you allow it through the cookie banner or its preferences panel. Decline, or ignore the banner, and it never runs. You can change or withdraw your choice any time from the Cookie preferences or Do Not Sell or Share My Personal Information links in the footer, and if your browser sends a Global Privacy Control signal we treat it as a standing decline and never load the pixel (see section 15).
Local storage is used by Stripe Checkout while you are on the payment page; that data is governed by Stripe’s privacy policy.
5. The subprocessors we rely on
We share personal data with the following service providers, each contractually bound to use it only to provide services to us:
- Stripe, Inc., payment processing and billing portal. Receives your name, email, and card details. Privacy: stripe.com/privacy.
- Supabase Inc., managed Postgres, authentication, file storage. Hosts the database where account and scan records live. Privacy: supabase.com/privacy.
- Vercel Inc., web application hosting and edge networking. Receives HTTP request metadata (IP, user agent) and operates the cookieless Web Analytics described in section 4. Privacy: vercel.com/legal/privacy-policy.
- Railway Corporation, runs our background scanner worker. Receives the domains being scanned and the operational logs. Privacy: railway.com/legal/privacy.
- Inngest, Inc., durable job orchestration. Receives scan IDs and job payloads. Privacy: inngest.com/privacy.
- Anthropic PBC, large-language-model API used by our detectors and the optional Fix-It-For-Me service to analyze the scan artifacts. By Anthropic’s commercial-API terms, prompt and completion data is not used to train their models. Privacy: anthropic.com/legal/privacy.
- Resend Inc. (or the email provider in use at the time), delivers magic-link sign-in emails and receipts.
6. International transfers
Our subprocessors are primarily based in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US under appropriate safeguards (Standard Contractual Clauses where applicable).
7. How long we keep your data
- IP logs (rate limiting): 30 days, then purged.
- Scan results and crawl artifacts: retained while your account exists. You can delete an individual scan from your dashboard at any time; the record and its artifacts are removed within seven days. For scans run without an account, we keep the raw crawl artifacts (captured page HTML and screenshots) for 7 days and then delete them; the scan report itself stays available at its link.
- Account records: retained while your account is active. If you ask us to delete your account, we remove your data within 30 days, except records we are required to keep for tax or accounting purposes (typically seven years for receipts/invoices).
- Stripe billing records: governed by Stripe’s retention rules; typically seven years.
8. Your rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access, request a copy of the personal data we hold about you.
- Correction, ask us to fix anything inaccurate.
- Deletion, ask us to delete your data (subject to legal-retention carve-outs).
- Portability, receive your data in a machine-readable format.
- Objection / restriction, under GDPR, object to certain processing or ask us to restrict it.
- Opt out of sale or sharing, under the CCPA / CPRA. We do not sell personal information. The only sharing for cross-context behavioral advertising is the optional Meta Pixel (section 4), which stays off unless you expressly opt in; declining, the Do Not Sell or Share link in the footer, or a Global Privacy Control signal keeps it off.
- Non-discrimination, we will not deny you service, charge you a different price, or provide a different level of quality for exercising any of the above.
To exercise any of these rights, email info@complidar.com. We will respond within 45 days. We will verify the request by replying to the email on file for your account; for unauthenticated requests we may ask for additional information to confirm identity. You may also designate an authorized agent.
If you believe we have mishandled your data, you can lodge a complaint with your local supervisory authority (e.g. the California Privacy Protection Agency or your EU data-protection authority), though we’d appreciate the chance to fix it first.
9. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, email info@complidar.com and we will delete it.
10. Security
We use industry-standard safeguards: TLS for all traffic, encrypted-at-rest databases, short-lived signed magic-link tokens, role-based access controls, principle-of-least- privilege on internal accounts, and review of every code change before it ships. We never store passwords or payment-card numbers. No system is perfectly secure; if we ever experience a breach affecting your data we will notify you within the timeframe required by applicable law.
11. Changes to this policy
We will update the “Last updated” date at the top of this page when we revise this Privacy Policy. For material changes (changes to the categories of data we collect or the purposes for which we use it), we will email account holders at least 14 days before the change takes effect.
12. Contact
For privacy questions, requests, or complaints: info@complidar.com.
13. Legal bases for processing (GDPR and UK GDPR)
Where the GDPR or UK GDPR applies, we rely on these legal bases under Article 6:
- Running the scan you request, delivering your report, authenticating you, and managing a paid subscription — performance of a contract with you (Art. 6(1)(b)). For a free scan run before any contract exists, our legitimate interest in providing the diagnostic you asked for (Art. 6(1)(f)).
- Processing payments and keeping the tax/accounting records the law requires — performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c)).
- Preventing abuse and fraud (IP rate limiting, Stripe Radar) and keeping the Service secure — our legitimate interest in protecting the Service and its users (Art. 6(1)(f)).
- Answering support and Fix-It-For-Me requests — performance of a contract or our legitimate interest in responding to you (Art. 6(1)(b)/(f)).
- Improving our detectors using aggregated, de-identified data — our legitimate interest in improving the Service (Art. 6(1)(f)).
- Complying with the law and responding to lawful requests — compliance with a legal obligation (Art. 6(1)(c)).
- Where we ask for it (e.g. the optional report-notification email) — your consent (Art. 6(1)(a)), which you can withdraw at any time.
14. Your U.S. state privacy rights
If you are a resident of California, Colorado, Connecticut, Texas, Utah, Virginia, or another U.S. state with a comprehensive privacy law, you have the right to:
- Know and access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete personal information we hold about you.
- Obtain a portable copy of your data.
- Opt out of the sale of personal information, of sharing or processing for targeted (cross-context behavioral) advertising, and of profiling that produces legal or similarly significant effects.
- Appeal a denied request. If we deny a request, you may appeal by emailing info@complidar.com with “Appeal” in the subject. We respond to appeals within the period your state law allows (generally 45–60 days); if we deny the appeal, you may contact your state attorney general.
We do not sell your personal information or use it for profiling that has legal or similarly significant effects. The only sharing for targeted (cross-context behavioral) advertising is the optional Meta Pixel described in section 4: it runs only if you expressly opt in through the cookie banner, and you can withdraw that choice at any time with the Cookie preferences or Do Not Sell or Share links in the footer, or automatically with a Global Privacy Control signal. To exercise any right, email info@complidar.com; we verify requests against the email on file and respond within the time your state law requires. You may use an authorized agent, and we will not discriminate against you for exercising a right.
15. Opt-out preference signals (Global Privacy Control)
Some state laws (including California, Colorado, and Connecticut) require us to treat a browser-level universal opt-out signal such as Global Privacy Control (GPC) as a valid request to opt out of the sale or sharing of personal information and of targeted advertising. We honor GPC and other recognized opt-out preference signals, and on this site the signal goes further than the legal minimum: we treat it as a standing decline, so the optional Meta Pixel never loads and the cookieless page-view counter described in section 4 is turned off.
This Privacy Policy is provided in good faith and is intended to accurately describe our practices. It is not legal advice. If you have a legal question about your rights, consult a licensed attorney in your jurisdiction.