Privacy Policy

CivicGuard AI Solutions & Marketing LLC ยท All Product Editions

Last Updated: June 2026

1. Information We Collect

CivicGuard AI Solutions & Marketing LLC ("CivicGuard," "we," "our," or "us") collects the following categories of personal and organizational information when you use our platform:

1.1 Account Information

  • Name, email address, and hashed password upon account creation
  • Role designation within your organization (Admin, Manager, Viewer)
  • Login timestamps and session activity

1.2 Organization Information

  • Organization legal name, EIN, and registration numbers
  • Mailing address and primary contact details
  • City agency contract identifiers and PASSPort vendor numbers
  • Subcontractor records and vendor information

1.3 Compliance Documents

  • Files uploaded to the document vault, stored with AES-256 server-side encryption
  • Grant agreements, contracts, certifications, and insurance documents
  • Staff credential and certification records

1.4 Usage & Audit Data

  • Actions taken within the platform, logged for immutable audit trail purposes
  • Compliance deadline interactions, alert acknowledgments, and report generation
  • IP address and device information for security purposes

2. How We Use Your Information

We use collected information solely for the following purposes:

  • To provide, maintain, and improve our compliance management services
  • To authenticate user identity and manage role-based account access
  • To store and secure your compliance documents and organizational records
  • To generate compliance deadline alerts and notifications
  • To maintain immutable audit logs as required for nonprofit compliance
  • To process subscription payments through Stripe
  • To respond to support requests and platform inquiries

We do NOT use your information for advertising, data brokering, or any purpose unrelated to providing our compliance services.

3. Zero-Knowledge Principle

CivicGuard operates on a zero-knowledge principle with respect to your financial records, client data, and programmatic information. We monitor compliance status signals only. Specifically:

  • We do not access, store, or process your clients' personal information
  • We do not have visibility into your organization's financial accounts or banking information
  • Billing is processed exclusively through Stripe's PCI-compliant infrastructure โ€” your payment information never touches our servers
  • Document vault contents are encrypted at rest and accessible only by authorized users within your organization

4. Data Security

We implement the following security measures to protect your information:

  • AES-256 encryption at rest for all stored documents and sensitive data
  • TLS 1.2+ encryption in transit for all data transmissions
  • Passwords hashed using bcrypt with minimum cost factor of 12
  • JWT session tokens with 30-minute idle timeouts
  • AWS enterprise-grade cloud infrastructure (us-east-1)
  • Role-based access controls limiting data visibility by user permission level
  • Immutable audit logging โ€” UPDATE and DELETE operations revoked at the database level

5. Data Retention

We retain your organizational data for as long as your account remains active. Upon account termination:

  • Compliance documents are retained for 7 years consistent with nonprofit record-keeping requirements
  • Audit logs are retained for a minimum of 7 years for legal compliance purposes
  • Personal account information is deleted within 90 days of account closure upon written request

You may request deletion of your data subject to applicable legal retention obligations.

6. Third-Party Sharing

We do not sell, rent, or share your personal or organizational information with third parties for their marketing or commercial purposes. Data may be shared only as follows:

  • With AWS cloud infrastructure providers solely for the purpose of hosting and delivering the service
  • With Stripe for payment processing purposes only
  • With Clerk for authentication services
  • As required by law, court order, or regulatory requirement
  • In connection with a merger, acquisition, or sale of assets, with advance notice

7. California Privacy Rights (CCPA)

Under the California Consumer Privacy Act (CCPA), California residents have the following rights:

  • Right to Know: Request disclosure of personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information, subject to legal exceptions
  • Right to Opt-Out: We do not sell personal information. See our "Do Not Sell My Personal Information" page
  • Right to Non-Discrimination: We will not discriminate for exercising CCPA rights
  • Right to Correct: Request correction of inaccurate personal information

To exercise these rights, contact us at ebradden@civicguardai.com . We will respond within 45 days as required by law.

8. Contact Information

For privacy inquiries, data requests, or concerns:

Email: ebradden@civicguardai.com

Website: civicguardai.com

Address: CivicGuard AI Solutions & Marketing LLC, New York, NY