Privacy Policy
Last updated: July 26, 2026
This Privacy Policy explains how [Your Company Legal Name] (“we”) handles information in connection with CoverSynx (the “Service”). By using the Service, you agree to this policy.
1. Information we collect
- Account information: name, email, organization, and login details (handled by our authentication provider).
- Customer Data you submit: vendor names and contacts, insurance requirements, and the certificates of insurance (COIs) you or your vendors upload. COIs generally contain business information (insurer, policy numbers, coverage limits, dates) rather than sensitive personal identifiers.
- Payment information: processed entirely by our payment processor. We do not store your card details.
- Usage data: basic, privacy-friendly analytics about how the Service is used.
2. How we use information
- To provide, operate, and secure the Service.
- To extract data from documents and flag potential compliance gaps using AI-assisted features.
- To send reminders and Service-related communications.
- To process payments and manage subscriptions.
- To improve the Service and comply with legal obligations.
3. Third-party processors (subprocessors)
We use reputable third parties to run the Service. Confirm and keep this list current for what you actually deploy:
- Hosting: Vercel (application hosting).
- Database: [your Postgres provider, e.g. Neon].
- Authentication: [Clerk, once enabled].
- Payments: Stripe.
- Email: [Resend, once enabled] for reminders and notices.
- AI processing: Anthropic (Claude) — certificate text is sent to Anthropic’s API to extract fields. Anthropic does not use API data to train its models by default.
4. How we share information
We do not sell your personal information. We share it only with the subprocessors above to operate the Service, when required by law, or to protect our rights. Your organization’s Customer Data is isolated from other customers.
5. Data retention
We retain Customer Data for as long as your account is active and for a reasonable period afterward, then delete or anonymize it, unless a longer period is required by law. You may request deletion (see below).
6. Security
We use industry-standard measures including encryption in transit (HTTPS), access controls, and per-organization data isolation. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your rights
Depending on your location (e.g., GDPR in the EU/UK, CCPA in California), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, contact us at privacy@[yourdomain].com. We will respond within the time required by applicable law.
8. International transfers
Your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy; material changes will be communicated through the Service or by email.
11. Contact
Privacy questions or requests: privacy@[yourdomain].com.