Privacy Policy

Last updated: August 8, 2026

This Privacy Policy describes how and why NeverLapse stores, accesses, collects, uses, and/or shares ("processes") your personal information when you use our services, visit our website, or engage with us in related ways, including marketing or events. It outlines what data is stored, why it is kept, how long it is retained, and what control your organization has over it.

Overview & Scope

Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services.

1. Summary of Key Points

  • What personal information do we process? Depending on how you interact with NeverLapse, we process account credentials, compliance tracking data, uploaded documents, audit records, and billing info.
  • Do we process sensitive personal information? We strictly advise against uploading sensitive personal data beyond what compliance credentials require.
  • Do we share data with third parties? We use a limited set of essential subprocessors (such as hosting, authentication, and Stripe for billing) who process data exclusively to provide their services to us. We do not sell your data.
  • What are your rights? You have choices to view, correct, export, or delete your data.

2. What We Collect

When you visit, use, or navigate our Services, we may collect information depending on your interactions:

  • Account Data: Email address, password (stored securely and hashed by our authentication provider), organization name, industry, and role within the organization.
  • Compliance Data You Enter: Locations and addresses, people (names and role titles), compliance items, issuing authorities, expiration dates, and renewal lead times.
  • Documents You Upload: License, certificate, insurance, and registration files stored in private storage scoped exclusively to your organization and served only through short-lived signed URLs.
  • Audit Records: Automatically written entries describing changes to compliance items and reminders sent, including who acted and when.
  • Billing Data: Subscription tier and a Stripe customer identifier. Note: Card numbers are handled entirely by Stripe and never reach NeverLapse servers.

Important Note on Sensitive Data: Please do not upload records containing sensitive personal data beyond what a compliance credential requires—do not upload government ID scans, medical information, or payment card details.

3. How We Use Your Information

We use your data strictly to operate the service for your organization, including:

  • Authenticating members and managing user sessions.
  • Calculating compliance statuses and sending automated reminder emails to owners and managers.
  • Recording audit trails and rendering shareable snapshots you create.
  • Processing subscription billing.

We do not sell your data, and we do not use your compliance records or documents for advertising or to train artificial intelligence models.

4. Who Else Processes It (Subprocessors)

We rely on a trusted, small set of subprocessors to deliver our services, each processing data solely to provide their respective service to us:

  • Infrastructure & Storage: Managed Postgres and object-storage providers for database management, authentication, and private file storage.
  • Communications: An email delivery provider for transmitting renewal reminders and alerts (recipient addresses and item details appear in those messages).
  • Billing Provider: Stripe, for handling subscription payments securely.
  • Hosting Provider: Application hosting infrastructure.

5. Multi-Tenant Isolation & Security

  • Data Isolation: Every record is strictly scoped to an organization. Access is enforced at the database level using row-level security so that members of one organization cannot read or write another organization's rows or documents.
  • Snapshots Exception: Shareable snapshot links are a deliberate exception, exposing a read-only view to whoever holds the link for as long as that link remains valid.
  • Security Measures: Data is encrypted in transit and at rest by our infrastructure providers. Documents live in private buckets accessible only via expiring signed URLs, and privileged operations run server-side. While no system is completely secure, we will notify affected customers of any data breach without undue delay.

6. Retention and Deletion

  • We retain your data for as long as your organization maintains an active account.
  • Audit entries are append-only and cannot be edited or individually deleted while the account is active.
  • Account Deletion: Deleting your organization's account via Settings permanently removes the organization, its members, locations, people, compliance items, uploaded documents, audit history, and login data. Encrypted system backups may retain residual copies temporarily until routine rotation overwrites them.

7. Your Choices & Regional Rights

  • App Controls: You can view, correct, and export your organization's records directly from within the app at any time, including downloading CSV and PDF exports of your audit history. Organization owners can configure reminder cadences in Settings.
  • Personal Data Requests: To request access, correction, or deletion of personal data held about you, please contact us at our designated legal email address.
  • California Privacy Rights: If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). These include the right to know what personal information we collect, the right to request deletion of your data, the right to opt-out of the "sale" or "sharing" of personal information (including targeted advertising), and the right not to be discriminated against for exercising these rights. To submit a request, please contact us at info@getneverlapse.com.
  • Other U.S. State Privacy Laws: Depending on your state of residence (such as Virginia, Colorado, Utah, Connecticut, or Texas), you may have similar rights to access, correct, or delete your personal data, or to opt out of targeted advertising and profiling. You or your authorized agent may submit a request by visiting the 'Contact/Feedback' form in the sidebar or emailing info@getneverlapse.com.
  • Role as Data Controller vs. Data Processor: When you visit our website or manage your account, NeverLapse acts as a data controller regarding your account profile and billing details. However, when you or your team input, upload, or process customer data within the NeverLapse platform, we act strictly as a data processor (or service provider) on behalf of our corporate customers, who act as the data controllers.

8. Cookies and Analytics

We use cookies and local storage strictly to keep you signed in securely. This policy does not currently incorporate analytics or marketing tracking tools; if such tracking is integrated prior to launch, this section will be updated accordingly.

Questions About This Policy?

If you have any questions or concerns regarding this Privacy Policy, please reach out to us at:

Email: info@getneverlapse.com