Privacy Policy
CivicGuard AI Solutions & Marketing LLC ยท All Product Editions
Last Updated: June 2026
1. Information We Collect
CivicGuard AI Solutions & Marketing LLC ("CivicGuard," "we," "our," or "us") collects the following categories of personal and organizational information when you use our platform:
1.1 Account Information
- Name, email address, and hashed password upon account creation
- Role designation within your organization (Admin, Manager, Viewer)
- Login timestamps and session activity
1.2 Organization Information
- Organization legal name, EIN, and registration numbers
- Mailing address and primary contact details
- City agency contract identifiers and PASSPort vendor numbers
- Subcontractor records and vendor information
1.3 Compliance Documents
- Files uploaded to the document vault, stored with AES-256 server-side encryption
- Grant agreements, contracts, certifications, and insurance documents
- Staff credential and certification records
1.4 Usage & Audit Data
- Actions taken within the platform, logged for immutable audit trail purposes
- Compliance deadline interactions, alert acknowledgments, and report generation
- IP address and device information for security purposes
2. How We Use Your Information
We use collected information solely for the following purposes:
- To provide, maintain, and improve our compliance management services
- To authenticate user identity and manage role-based account access
- To store and secure your compliance documents and organizational records
- To generate compliance deadline alerts and notifications
- To maintain immutable audit logs as required for nonprofit compliance
- To process subscription payments through Stripe
- To respond to support requests and platform inquiries
We do NOT use your information for advertising, data brokering, or any purpose unrelated to providing our compliance services.
3. Zero-Knowledge Principle
CivicGuard operates on a zero-knowledge principle with respect to your financial records, client data, and programmatic information. We monitor compliance status signals only. Specifically:
- We do not access, store, or process your clients' personal information
- We do not have visibility into your organization's financial accounts or banking information
- Billing is processed exclusively through Stripe's PCI-compliant infrastructure โ your payment information never touches our servers
- Document vault contents are encrypted at rest and accessible only by authorized users within your organization
4. Data Security
We implement the following security measures to protect your information:
- AES-256 encryption at rest for all stored documents and sensitive data
- TLS 1.2+ encryption in transit for all data transmissions
- Passwords hashed using bcrypt with minimum cost factor of 12
- JWT session tokens with 30-minute idle timeouts
- AWS enterprise-grade cloud infrastructure (us-east-1)
- Role-based access controls limiting data visibility by user permission level
- Immutable audit logging โ UPDATE and DELETE operations revoked at the database level
5. Data Retention
We retain your organizational data for as long as your account remains active. Upon account termination:
- Compliance documents are retained for 7 years consistent with nonprofit record-keeping requirements
- Audit logs are retained for a minimum of 7 years for legal compliance purposes
- Personal account information is deleted within 90 days of account closure upon written request
You may request deletion of your data subject to applicable legal retention obligations.
6. Third-Party Sharing
We do not sell, rent, or share your personal or organizational information with third parties for their marketing or commercial purposes. Data may be shared only as follows:
- With AWS cloud infrastructure providers solely for the purpose of hosting and delivering the service
- With Stripe for payment processing purposes only
- With Clerk for authentication services
- As required by law, court order, or regulatory requirement
- In connection with a merger, acquisition, or sale of assets, with advance notice
7. California Privacy Rights (CCPA)
Under the California Consumer Privacy Act (CCPA), California residents have the following rights:
- Right to Know: Request disclosure of personal information we collect, use, and disclose
- Right to Delete: Request deletion of your personal information, subject to legal exceptions
- Right to Opt-Out: We do not sell personal information. See our "Do Not Sell My Personal Information" page
- Right to Non-Discrimination: We will not discriminate for exercising CCPA rights
- Right to Correct: Request correction of inaccurate personal information
To exercise these rights, contact us at ebradden@civicguardai.com . We will respond within 45 days as required by law.
8. Contact Information
For privacy inquiries, data requests, or concerns:
Email: ebradden@civicguardai.com
Website: civicguardai.com
Address: CivicGuard AI Solutions & Marketing LLC, New York, NY