CompliCore Privacy Policy

Effective Date: [EFFECTIVE DATE] Last Updated: [EFFECTIVE DATE]

This Privacy Policy describes how [COMPLICORE LEGAL ENTITY NAME, e.g. CompliCore LLC] ("CompliCore," "we," "us," or "our") collects, uses, stores, and shares information when you use our building-compliance software platform, websites, mobile/PWA applications, and related services (collectively, the "Service").

CompliCore is a business-to-business service for building owners and property managers in the District of Columbia, Maryland, and Virginia. By using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, do not use the Service.

Contact: [PRIVACY CONTACT EMAIL, e.g. privacy@complicore.app] · [MAILING ADDRESS]


1. Scope

This Policy covers:

  • The CompliCore web application (dashboard, building and asset management, compliance tracking, vendor dispatch, billing).
  • Our public marketing website, including any contact or lead forms.
  • Email, SMS, and push notifications we send in connection with the Service.
  • Live-chat support offered on our website and in the app through a third-party chat provider (tawk.to).

This Policy does not cover the practices of third-party contractors, inspectors, or vendors you engage through or alongside the Service. Those parties are independent businesses with their own privacy practices.


2. Information We Collect

2.1 Information You Provide Directly

Account and profile information. When you register we collect your full name, email address, password (stored by our authentication provider in hashed form — we never store plaintext passwords), a U.S. mobile phone number (required, used for SMS alerts), your company name (optional), and your notification preferences (email, SMS, push).

Google Sign-In. If you register or sign in with Google, we receive your name, email address, and basic profile information from your Google account, as permitted by your Google settings.

Team and invitation information. When an account owner or administrator invites teammates, we collect the invitee's email address, the assigned role (Owner, Admin, Manager, or Viewer), and the identity of the inviting member. Invitation links contain a single-use token; we store only a cryptographic hash of that token.

Building and portfolio information. Building names, street addresses (in DC, MD, or VA), gross floor area, property type, ownership type, and internal identifiers you assign.

Compliance and equipment information. Details about safety-critical equipment (elevators, boilers, fire protection systems, backflow preventers, energy-benchmarking data), including state registration numbers, inspection dates, due dates, and compliance status.

Financial and job records. Inspection and service records you enter or that the Service generates, including estimated, quoted, and final costs, and estimated fine/liability exposure.

Documents you upload. Inspection certificates, invoices, permits, and similar documents. These may contain names, signatures, contact details, and pricing information of you or third parties (e.g., contractors who issued them).

Vendor contact information. Names, email addresses, and phone numbers of contractors and inspectors you enter or select for outreach.

Communications with us. Information you provide in support requests, feedback, or through forms on our marketing site (name, email, company, message content). If you use the live-chat support widget, we and our chat provider (tawk.to) collect the chat transcript and any name, email address, or other information you choose to share in the conversation.

2.2 Information Collected Automatically

Authentication and session data. We use our authentication provider's tokens (stored in your browser) to keep you signed in. These are strictly necessary for the Service to function.

Push notification tokens. If you enable push notifications, we store a device-specific Firebase Cloud Messaging (FCM) token so we can deliver notifications to your device.

Device and log data. Standard technical information such as IP address, browser type, operating system, pages accessed, and timestamps, collected through server logs and our hosting infrastructure for security, debugging, and operations.

Local storage / offline data. As a progressive web app (PWA), the Service caches application assets and stores your display preferences (e.g., light/dark theme) in your browser's local storage.

Live-chat widget data. Our support chat is provided by tawk.to. When a page containing the chat widget loads, tawk.to automatically collects certain technical information about your visit — such as your IP address, approximate location derived from it, browser and device type, and the pages you view on our site — and sets cookies and local-storage entries to keep your chat session continuous across pages (see Section 8). This occurs whether or not you open a chat.

We do not use third-party advertising trackers, advertising cookies, or cross-site tracking. Apart from the visit information collected by the live-chat widget described above, we do not use third-party analytics tools. See Section 8 (Cookies) for details.

2.3 Information from Public Records and Government Sources

A core function of the Service is monitoring public government compliance records, including the Maryland Division of Labor and Industry elevator registry, District of Columbia government datasets, and DC BEPS (Building Energy Performance Standards) data. We collect and refresh registration numbers, certificate expiration dates, and inspection statuses associated with buildings from these public sources and match them to buildings in your portfolio.

These records are created and maintained by government agencies, which may disclaim their accuracy. See Section 12.

2.4 Information from Third-Party Directories

When you use the vendor-suggestion feature, we retrieve publicly listed business information (business name, phone, website, rating, review count, address) about local contractors from the Google Places API. We cache these results temporarily (approximately 30 days) to reduce repeat lookups. This is business-directory data, not consumer data.


3. How We Use Information

We use the information we collect to:

  • Create and administer your account, portfolio, and team;
  • Track compliance deadlines and generate the compliance calendar for your buildings;
  • Send you compliance alerts and reminders by email, SMS, and push notification, according to your preferences;
  • Suggest local vendors and, at your direction, send service-request emails to vendors you select;
  • Generate AI-assisted content (see Section 4);
  • Process subscription payments and manage billing through Stripe;
  • Provide customer support and respond to your inquiries;
  • Secure the Service, prevent fraud and abuse, enforce rate limits, and debug problems;
  • Comply with legal obligations; and
  • Improve and develop the Service, including through aggregated or de-identified data that does not identify you.

We do not sell your personal data, and we do not process personal data for targeted advertising.


4. Artificial Intelligence Features

Certain features use large language models provided by Google (Gemini API):

  • Vendor outreach drafting. When you ask the Service to draft a request-for-quote email, we send the relevant building name and address, equipment details, service type, and summarized inspection history (dates, costs, overdue status) to the Gemini API to generate a draft. You review and can edit every draft before anything is sent.
  • Invoice and document extraction (OCR). When you upload an invoice or inspection document and request parsing, the document file itself is transmitted to the Gemini API to extract fields such as vendor name, amount, service date, and invoice number.
  • Building health profiles (Pro plan). Equipment and inspection-history data for a building is sent to the Gemini API to generate health scores and budgeting recommendations.

We send only the data needed for the specific feature. We do not send your account credentials or payment information to AI providers. We do not use Customer Data to train our own models. We transmit this data to Google's Gemini API on a paid basis; under Google's terms for the paid API, Google does not use data submitted through the API to train or improve its models. AI-generated output may contain errors; it is provided as a convenience and is not professional, engineering, or legal advice. Consult Google's applicable privacy documentation for its practices.


5. How We Share Information

We share personal information only as described below. We do not sell personal information to anyone, and we do not share it with third parties for their own marketing.

5.1 Service Providers (Processors)

We use the following categories of service providers, which process data on our behalf under contractual restrictions:

ProviderPurposeData Involved
Google Firebase / Google CloudAuthentication, database (Firestore), file storage, push notificationsAccount data, all application data, uploaded documents, push tokens
StripeSubscription billing and payment processingName, email, subscription details. Payment card numbers are collected directly by Stripe and never touch our servers.
Twilio SendGridTransactional email delivery (alerts, invitations, vendor outreach)Recipient email addresses and message content
TwilioSMS alert deliveryYour mobile phone number and alert message content
Google (Gemini API)AI drafting, document extraction, health profiles (Section 4)Building/equipment data and uploaded documents you submit for these features
Google (Places / Maps APIs)Address autocomplete; vendor directory lookupAddress text you type; building city/state/ZIP for vendor searches
tawk.toLive-chat customer support and support ticketingChat transcripts; name, email, and other details you provide in chat; technical visit data collected by the widget (IP address, browser/device type, pages viewed)
Hosting and infrastructure providers (e.g., Vercel)Application hosting, logsTechnical/log data; data in transit
Workflow automation (self-hosted n8n)Scheduled compliance checks and government-registry synchronizationBuilding registration identifiers; alert dispatch triggers

We may add, replace, or remove service providers as the Service evolves. When we make a material change to the providers that process personal data, we will update this list and, for material changes, provide notice by updating this Policy's "Last Updated" date or by other reasonable means before the change takes effect.

5.2 Vendors and Contractors — At Your Direction

When you use the dispatch feature to request quotes, we send the email you approved to the vendors you selected. That email typically includes the building name and address, the equipment and service needed, relevant inspection history, and your reply contact information. Once delivered, that information is in the vendor's hands and subject to the vendor's own practices.

5.3 Within Your Organization

Members of your portfolio team can see portfolio data (buildings, assets, logs, alerts) and basic teammate profile information (name, email, role) consistent with their assigned role. The portfolio Owner controls membership.

5.4 Legal, Safety, and Corporate Events

We may disclose information: (a) to comply with law, regulation, subpoena, or lawful government request; (b) to enforce our Terms of Service; (c) to protect the rights, safety, or property of CompliCore, our users, or others; or (d) in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy will continue to apply to previously collected data until a successor policy takes effect with notice to you.

5.5 Aggregated and De-Identified Data

We may use and share aggregated or de-identified information (e.g., regional compliance-lapse statistics) that cannot reasonably be used to identify you or any individual.


6. SMS / Text Messaging Terms

By providing your mobile number at registration and enabling SMS notifications, you consent to receive transactional and account-related text messages from CompliCore (compliance alerts, deadline warnings, and service notifications). Consent to receive texts is not a condition of purchasing any good or service, and you can use the Service with SMS disabled.

  • Message frequency varies based on your buildings' compliance activity.
  • Message and data rates may apply, per your carrier plan.
  • Reply STOP to cancel at any time, or disable SMS notifications in Settings. Reply HELP or contact [SUPPORT EMAIL] for help.
  • Carriers are not liable for delayed or undelivered messages.
  • No mobile telephone numbers or SMS opt-in data will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging opt-in data is shared only with our SMS delivery provider (Twilio) as necessary to deliver the messages you requested.

7. Push Notifications

If you opt in to push notifications, your browser or device generates a delivery token that we store with your account. You can revoke push permission at any time through your browser/device settings or in the app's notification settings, and we deactivate stored tokens that become invalid.


8. Cookies and Local Storage

We use strictly necessary and functional browser storage only — no advertising or cross-site-tracking cookies:

  • Authentication: tokens from Firebase Authentication to keep you signed in.
  • Preferences: your theme choice (light/dark), stored locally.
  • PWA caching: application files cached by a service worker so the app loads quickly and functions offline.
  • Stripe: when you enter checkout or the billing portal, Stripe sets cookies on its own pages for payment security and fraud prevention.
  • Support chat (tawk.to): the live-chat widget sets cookies and local-storage entries to maintain your chat session as you move between pages and to remember the widget's state. These are functional cookies used solely to operate the chat; see tawk.to's privacy policy for its practices.

We do not use advertising cookies, social-media pixels, or cross-site tracking, and we do not respond differently to browser "Do Not Track" signals because we do not track users across third-party sites. Because we do not sell personal data or engage in targeted advertising, universal opt-out signals (such as Global Privacy Control) do not change how we process your data, though we honor them where required by law.


9. Data Retention

We retain personal information for as long as your account is active and as needed to provide the Service. Thereafter we retain information only as necessary to:

  • Comply with legal, tax, and accounting obligations (e.g., billing records);
  • Resolve disputes and enforce agreements;
  • Maintain security and audit logs for a limited period.

Compliance records, inspection logs, and uploaded documents belong to your portfolio and are retained until you delete them or your account is deleted. Upon verified account deletion, we delete or de-identify personal information within a commercially reasonable period (generally within 90 days), except where retention is required by law. Support chat transcripts are retained in our support tools for as long as reasonably needed to provide support and keep records of your requests; you may request their deletion at [PRIVACY CONTACT EMAIL]. Cached vendor-directory data expires automatically (approximately 30 days). Backup copies are purged on a rolling basis.


10. Security

We use commercially reasonable technical and organizational safeguards, including:

  • Encryption in transit (TLS) for all connections and encryption at rest provided by our cloud infrastructure;
  • Password hashing and authentication managed by Firebase Authentication;
  • Tenant isolation: database security rules restrict every read to members of the owning portfolio, and all writes flow through authenticated server-side APIs that verify portfolio ownership;
  • Role-based access controls within each portfolio;
  • Secrets management for API credentials; signed webhooks and shared-secret authentication between internal systems;
  • Recipient caps and validation on outbound email features to prevent abuse.

No system is perfectly secure. You are responsible for maintaining the confidentiality of your credentials and for the access you grant to team members.


11. Your Privacy Rights

11.1 Rights for All Users

Regardless of where you live, you may: access the personal information in your account (most of it is visible directly in Settings and your dashboard); correct your profile information; export your compliance data; adjust notification preferences; and request deletion of your account by contacting [PRIVACY CONTACT EMAIL]. These baseline rights are extended to all users, including those who reside outside the District of Columbia, Maryland, and Virginia, even where no state privacy statute requires it.

11.2 Maryland Residents (Maryland Online Data Privacy Act)

If the Maryland Online Data Privacy Act (MODPA) applies to our processing of your personal data, you have the right to: (a) confirm whether we process your personal data and access it; (b) correct inaccuracies; (c) delete personal data provided by or obtained about you; (d) obtain a portable copy; and (e) opt out of targeted advertising, the sale of personal data, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. We do not sell personal data, do not engage in targeted advertising, and do not perform such profiling of individuals. We collect personal data consistent with MODPA's data-minimization standard — only what is reasonably necessary to provide the Service you request.

11.3 Virginia Residents (Virginia Consumer Data Protection Act)

If the VCDPA applies to our processing of your personal data, you have equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and significant-effect profiling. Note that the VCDPA's definition of "consumer" excludes individuals acting in a commercial or employment context; because CompliCore is a business service, much of the data we process may fall outside the VCDPA, but we extend the rights in Section 11.1 to all users regardless.

11.4 District of Columbia Residents

D.C. law does not currently provide a comprehensive consumer privacy statute, but we extend the rights in Section 11.1 to D.C. residents, and we comply with D.C.'s data-security and breach-notification requirements (see Section 13) and the D.C. Consumer Protection Procedures Act.

11.5 Exercising Rights and Appeals

Submit requests to [PRIVACY CONTACT EMAIL] with the subject "Privacy Request." We will verify your identity (typically by confirming control of the account email) and respond within 45 days, extendable once by 45 days where reasonably necessary, with notice. Authorized agents may submit opt-out requests on your behalf with proof of authorization. We will not discriminate against you for exercising your rights.

If we decline a request, you may appeal by replying to our decision or emailing [PRIVACY CONTACT EMAIL] with the subject "Privacy Appeal." We will respond to appeals within 60 days. If your appeal is denied, you may contact your state Attorney General: Maryland (www.marylandattorneygeneral.gov), Virginia (www.oag.state.va.us), or the D.C. Office of the Attorney General (oag.dc.gov).


12. Public Records Accuracy

Compliance statuses shown in the Service are derived in part from government registries that the issuing agencies may update on a delay and for which they disclaim accuracy. Information about your buildings appearing in those public records is not created by CompliCore. If you believe a government record is inaccurate, contact the issuing agency; we will re-synchronize on our regular schedule or upon your request.


13. Data Breach Notification

If we discover a breach of security affecting your personal information, we will notify affected users and, where required, regulators and consumer-reporting agencies, in accordance with the D.C. Security Breach Protection Amendment Act, the Maryland Personal Information Protection Act, and Virginia's breach-notification statute (Va. Code § 18.2-186.6), in the most expedient time possible and without unreasonable delay.


14. Children's Privacy

The Service is a business tool intended for users 18 years of age or older. We do not knowingly collect personal information from children under 13 (or any minor). If you believe a child has provided us personal information, contact us and we will delete it.


15. Data Location

We store and process data in the United States, in cloud regions operated by our infrastructure providers. If you access the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S.


16. Changes to This Policy

We may update this Policy from time to time. We will post the revised version with a new "Last Updated" date and, for material changes, notify you by email or in-app notice before the changes take effect. Continued use of the Service after the effective date constitutes acceptance.


17. Contact Us

[COMPLICORE LEGAL ENTITY NAME] [MAILING ADDRESS] Email: [PRIVACY CONTACT EMAIL] Support: [SUPPORT EMAIL]