Legal
Privacy Policy
Last updated August 6, 2026
Information We Collect
We may collect contact details, company information, usage data, device and browser data, support communications, billing-related information, cookie preferences, and documents or data submitted through the platform by customers and vendors. For visitors who allow analytics cookies on the marketing site, we may also collect first-party marketing activity data such as pages viewed, buttons and links clicked, scroll-depth milestones, approximate timestamps, referrer information, and an anonymous visitor identifier stored in a first-party cookie.
How We Use Information
We use information to operate the site and platform, provide support, process billing, secure accounts, deliver onboarding and renewal workflows, send requested communications, measure and improve the performance of the marketing site, understand which pages and calls to action are effective, prevent fraud, and comply with legal obligations.
Partner Program Applications
If you apply to the OnComply Partner Program, we collect the contact, business, website, audience, promotion-channel, expected-referral, and other information you choose to submit. We use it to evaluate program fit, detect duplicate or abusive applications, contact you about the application, and, if accepted, prepare a separate secure partner onboarding workflow. The public application does not request taxpayer identification numbers, bank details, customer documents, or passwords. Applying does not guarantee acceptance into the program.
Cookies and Consent Choices
The marketing site uses first-party cookies and local storage. Necessary storage supports core site behavior, remembers your cookie preference, and may retain an opaque partner referral code and, for branded campaign links, a public campaign identifier for up to 90 days so they can accompany a trial signup. The code and campaign identifier expire together and do not enable broader analytics tracking or contain contact details. If you choose `Allow All Cookies`, we also use first-party analytics cookies and related storage to measure visitor journeys across the marketing site. If you choose `Necessary Only`, we do not enable those non-essential analytics events. You can change or clear cookies in your browser settings, although doing so may remove your saved preference and other site settings.
Marketing Site Analytics
When analytics cookies are allowed, we record first-party marketing-site events such as page views, click targets, and scroll-depth milestones so we can understand engagement and improve conversion performance. We do not use this feature as session-replay or raw mouse-coordinate surveillance. The analytics data is linked to an anonymous first-party visitor identifier rather than a logged-in product account unless you separately submit information such as a demo request or trial signup.
Email Communications
If you request a demo, start a trial, submit a partner application, contact us, or use the platform, we may send application, account, onboarding, billing, security, support, legal, and product-operational emails. We may also send promotional emails where permitted by law. You can unsubscribe from promotional emails at any time using the unsubscribe link. Transactional or operational emails may still be sent when necessary to provide the service or administer your account.
Customer Responsibility for Vendor Notices and Consent
Customers using OnComply to contact vendors are responsible for providing required notices and obtaining any required consent, opt-in, or other lawful basis before sending emails, reminders, or alerts through the platform. Customers are also responsible for honoring communication preferences and applicable legal requirements for those vendor communications.
Sharing
We may share data with service providers that support hosting, storage, payments, analytics, email delivery, document extraction and validation, and support operations. Automated document processing uses Microsoft Azure and can involve source documents containing tax identifiers, bank details, and other sensitive vendor data. The Data Processing Agreement overview and published subprocessor schedule explain that processing, Microsoft's training and retention commitments, and available customer choices. For marketing-site analytics, this may include infrastructure providers that store or process first-party event data on our behalf. We may also disclose information where required by law, subpoena, court order, regulatory request, or where reasonably necessary to investigate fraud, abuse, or security incidents.
Retention and Security
We retain demo requests for up to two years, marketing analytics and consent records for up to 395 days, delivered notification records for 90 days, and abuse-prevention counters for 48 hours by default. Partner applications and their review history are retained while they are under consideration and afterward as reasonably necessary to administer the program, prevent duplicate or abusive applications, document decisions, and meet legal obligations. We may apply a shorter period to declined applications under our retention procedures. Automated deletion applies where configured. Legal holds or a documented legal obligation may require specific records to be retained longer. We use administrative, technical, and organizational safeguards appropriate to the nature of the data we process, but no method of transmission or storage is completely risk-free.
Requests and Contact
Privacy questions, access requests, cookie-related questions, and legal requests can be sent to admin@oncomply.biz.
AI Processing and Subprocessors
Review our DPA and Azure AI disclosure and the current subprocessor schedule.
Erase Browser Analytics
You can delete analytics events and the consent record associated with this browser at any time.