AUDIT_ENGINE

Legal

Privacy Policy

Effective date: 2026-04-29.

Audit Engine is operated by Venture Panda LLC. This policy describes what we collect, how we use it, and your rights.

1. Information we collect

2. How we use it

3. How we share it

We do not sell your information. We share it only with subprocessors required to deliver the service (Stripe for payments, Resend for transactional email, Supabase for storage, Vercel for hosting). Subprocessors are bound by their own privacy policies.

4. Retention

Audit reports and intake submissions are retained for 24 months unless you request earlier deletion. Aggregate methodology improvements (with no identifying information) are retained indefinitely.

5. Your rights

You may request access to, correction of, or deletion of your data by emailing audits@auditenginehq.com. We respond within 30 days. EU and California residents have additional rights under GDPR and CCPA respectively; we honor those rights for all users.

6. Security

We use encrypted transport (TLS) for all data in transit. Data at rest is encrypted by our subprocessors. We have not had a breach. If one occurs, we will notify affected users within 72 hours.

7. Cookies

We use the minimum cookies required to operate the site (auth session if you log in). We do not use advertising cookies.

8. Contact

Privacy questions: audits@auditenginehq.com. Venture Panda LLC.

Note for Jon: v0 placeholder. A lawyer should harden this before live revenue, particularly for GDPR and CCPA exact language. Update once Stripe is live and Supabase region is locked.