Audit Shield

Privacy Policy

How Audit Shield collects, uses, secures, and retains account and audit-preparation information.

Updated August 29, 2026

Scope

This policy applies to the Audit Shield website, customer workspace, public demo, and related support communications. It does not govern an insurer, auditor, payment processor, or other third party you choose to use.

Information we collect

We collect account identity and contact information, business profile details, policy and audit records, employee and subcontractor information, payment amounts, insurance certificate details, uploaded documents, team membership, product activity, support messages, device and security information, and subscription status.

How information is used

Information is used to operate and secure the service; organize audits; calculate transparent readiness and estimated exposure; generate requested reports and packages; send configured reminders; provide support; administer subscriptions; detect abuse; maintain activity records; and comply with lawful obligations.

Service providers and disclosure

We may use infrastructure, authentication, storage, email, analytics, and payment providers to deliver the service. They receive only the information reasonably needed for their role. We do not sell customer documents or personal information. We may disclose information when required by law, to protect the service or its users, or as part of a properly managed business transaction.

Private documents

Customer files are stored in private object storage. They are not published through public bucket URLs. Application download routes check authenticated business membership before returning a file. The public demo uses separate sample data and does not expose customer records.

Retention and deletion

Account and audit data is retained while the account is active and for a limited period afterward when needed for recovery, security, billing, dispute resolution, or legal obligations. You may request export or deletion through the contact page. Some records may be retained when legally required or when deletion would compromise security and audit logs.

Security

We use encrypted connections, private file storage, server-side authorization, role-based permissions, validated uploads, rate controls, and activity logging. No online service can guarantee absolute security. Report a concern through the security contact option.

Your choices

You may correct workspace information, configure notifications, download generated packages, and request access, export, or deletion. Marketing communications, if introduced, will include an opt-out. Required security, billing, and account notices may still be sent.

International processing

Service providers may process information in countries different from yours. We use contractual and technical safeguards appropriate to the service and information involved.

Children

The service is intended for businesses and is not directed to children under 18.

Changes and contact

Material changes will be posted here with an updated date. Privacy questions and rights requests can be submitted through the contact page.