This Privacy Policy describes how Steeled Inc. ("we," "us," "our") collects, uses, and protects your personal data in connection with the ComplianceStack service. We comply with applicable privacy laws including the GDPR (EU/UK), CCPA/CPRA (California), and other U.S. state privacy laws. Non-essential cookies are off by default. We do not sell your personal information. You can manage your cookie preferences and exercise your privacy rights at any time by contacting compliancestack@polsia.app.
Steeled Inc., a Delaware Corporation, is the data controller for personal information collected through the ComplianceStack service. As data controller, we determine the purposes and means of processing your personal data in accordance with applicable privacy laws.
Contact for all privacy inquiries: compliancestack@polsia.app
Subject line for privacy requests: "Privacy Request — [Your Request Type]"
Payment transactions are processed by Stripe. We do not store raw credit card numbers, CVV codes, or full payment card data on our systems. We receive and store: subscription status, billing history, last four digits of payment card, and Stripe customer identifiers.
Note: We use anonymized, aggregated AI interaction data to improve our AI models and service quality. We do not use identifiable personal data to train AI models without your explicit consent. See Section 3 for details.
We use cookies and similar tracking technologies. See Section 11 (Cookie Policy) for full details. Analytics cookies (Google Analytics) and marketing cookies (Meta Pixel) are off by default and require your explicit consent.
We may receive information about you from third parties, such as OAuth providers if you sign in through a connected service. We use this information only to provide and improve the Service.
Do not submit Protected Health Information (PHI), Social Security numbers, government-issued ID numbers, classified information, or sensitive personal data to the Service. ComplianceStack is not designed or certified to handle such information. Submitting such information violates our Terms of Service.
We do not sell your personal information. We do not use your data to train AI models in ways that would make your personal information identifiable to third parties.
For users in the EEA, UK, and Switzerland, we process personal data on the following legal bases under the GDPR:
For processing involving special categories of data (which we do not intentionally collect), we would rely on Art. 9(2)(a) explicit consent. If you believe you have inadvertently submitted special category data, contact us immediately at compliancestack@polsia.app.
We share your information only with the following categories of recipients, each subject to data processing agreements and applicable legal protections:
We may disclose your information when required by law, court order, subpoena, or other governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, prevent fraud or crime, or protect the safety of any person.
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred to the acquiring or surviving entity. We will provide reasonable notice to affected users and this Privacy Policy will continue to govern your information unless you are notified otherwise.
We may share your information with third parties when you explicitly consent to such sharing.
We may share aggregated, anonymized data that cannot reasonably identify any individual, for research, benchmarking, or marketing purposes.
We do not sell personal information to data brokers, advertisers, or third parties for monetary consideration. We do not share personal information for cross-context behavioral advertising without your consent.
Steeled Inc. does not sell your personal information to third parties for monetary or other valuable consideration, as defined under the CCPA/CPRA and similar state privacy laws.
We do not share your personal information with third parties for the purpose of cross-context behavioral advertising without your explicit consent. When you provide consent for marketing cookies or advertising tracking (see Section 11), you may withdraw that consent at any time.
For California residents, Virginia residents, and residents of other states with applicable opt-out rights, see Sections 9 and 10 for how to exercise your opt-out rights.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the GDPR (or UK GDPR) regarding your personal data:
We will respond to rights requests within 30 days of receipt. Complex requests may require up to 90 days with prior notice to you.
To exercise any of your privacy rights (GDPR, CCPA, or state-law rights), contact us at:
Email: compliancestack@polsia.app
Subject line: "Privacy Rights Request — [Access / Delete / Correct / Opt-Out / Portability / Object]"
Please include your name, email address associated with your account, and a description of your request. We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.
We will acknowledge receipt of your request within 5 business days and respond substantively within 30 days (or within the timeframe required by applicable law, where shorter).
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the following rights:
We do not sell your personal information to third parties for monetary consideration, and we do not share your personal information with third parties for cross-context behavioral advertising without your explicit consent.
As a California resident, you may submit a formal opt-out request or data rights request using the contact below. Reference "CCPA Privacy Request" in your subject line.
Submit CCPA / Do Not Sell RequestWe do not collect biometric data, geolocation data (beyond approximate country/state), genetic data, or financial account numbers.
To submit a CCPA request, contact compliancestack@polsia.app with subject "CCPA Privacy Request." You may submit up to two data access requests per 12-month period. We will respond within 45 days (extendable to 90 days with notice).
Residents of the following states have additional privacy rights under their respective state privacy laws:
| State | Law | Rights Available |
|---|---|---|
| Virginia | VCDPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal |
| Colorado | CPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal |
| Connecticut | CTDPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal |
| Utah | UCPA | Access, deletion, portability, opt-out of sale/targeted advertising |
| Texas | TDPSA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling |
| Montana, Oregon, Delaware, Iowa, Indiana, Tennessee | Respective state laws | Access, correction (some), deletion, portability, opt-out of sale/targeted advertising |
How to exercise state rights: Contact compliancestack@polsia.app and specify your state, the right you wish to exercise, and your contact information. We will respond within the timeframe required by your state's applicable law (typically 45–60 days).
Appeals: If we decline to act on your request, you may appeal by responding to our decision notice and requesting review. If your appeal is denied, you may submit a complaint to your state's attorney general or designated privacy authority.
We apply these rights to all residents of applicable states regardless of whether the state-specific threshold conditions are technically met, as a matter of good practice.
We use cookies and similar technologies (pixels, local storage) on our Service. Non-essential cookies are off by default and require your explicit consent before activation.
You can withdraw consent for non-essential cookies at any time using the preference manager below.
Steeled Inc. is based in the United States. If you are accessing the Service from the EEA, UK, Switzerland, or other jurisdictions with data transfer restrictions, your personal data will be transferred to and processed in the United States.
We ensure that international transfers are made with appropriate safeguards in place, including:
By using the Service from these jurisdictions, you acknowledge that your data will be transferred internationally under these safeguards. You may request a copy of applicable SCCs by contacting compliancestack@polsia.app.
We retain personal data for as long as necessary for the purposes described in this Policy, or as required by law. The following table summarizes our standard retention periods:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account & profile data | 12 months after account deletion | Dispute resolution, legal obligations |
| AI outputs & deliverables | 30 days after account deletion | User access during wind-down period |
| Payment & billing records | 7 years | Tax law and financial compliance requirements |
| Anonymized usage data | Indefinite | Service improvement; no longer personal data |
| Analytics cookies | 12–26 months | Standard analytics retention |
| Customer support records | 3 years | Quality assurance, dispute resolution |
| Server and access logs | 90 days | Security monitoring and debugging |
| Waitlist data | Until you unsubscribe + 30 days | Communication purposes |
Upon account deletion, we will delete or irreversibly anonymize your personal data within the periods specified above, except where retention is required by applicable law (e.g., financial records, legal holds). You may request deletion of your data at any time, subject to these retention requirements, by contacting compliancestack@polsia.app.
We implement industry-standard technical and organizational security measures designed to protect your personal data against unauthorized access, disclosure, alteration, and destruction. These measures include:
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
Sensitive data stored in our databases is encrypted using AES-256 encryption.
Passwords are hashed using bcrypt with sufficient work factors; plaintext passwords are never stored.
MFA is available and encouraged for all user accounts; required for administrative access.
Internal access to personal data is restricted to personnel who need it to perform their job functions.
Continuous monitoring for unauthorized access attempts, anomalous activity, and security incidents.
Despite these measures, no security system is impenetrable. If you suspect a security breach affecting your account, contact us immediately at compliancestack@polsia.app. In the event of a data breach affecting your rights and freedoms, we will notify you and applicable regulatory authorities as required by law.
ComplianceStack is not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13 as covered by the Children's Online Privacy Protection Act (COPPA) or children under 16 as covered by the GDPR.
If we become aware that we have inadvertently collected personal information from a child under the applicable age threshold without verifiable parental consent, we will take steps to delete such information promptly.
If you are a parent or guardian and believe that your child has provided personal information to us without your consent, please contact us at compliancestack@polsia.app with the subject line "Child Data — COPPA Request."
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will provide notice of material changes by:
Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree to the revised Policy, you must stop using the Service and may request deletion of your account.
We encourage you to review this Policy periodically to stay informed about our data practices.
Privacy Contact
For all privacy inquiries, rights requests, and data protection questions:
Email: compliancestack@polsia.app
Subject line: "Privacy Request — [Your Request Type]"
Entity: Steeled Inc., a Delaware Corporation
CCPA requests: Subject "CCPA Privacy Request"
GDPR requests: Subject "GDPR Rights Request"
Response time: within 30 days for GDPR requests; within 45 days for CCPA requests; within 30 days for state law requests (unless extended as permitted by law).