Privacy Policy
Drafted 2026-08-12, updated 2026-08-19. Not yet reviewed by outside counsel.
Draft — pending review
This Privacy Policy was drafted under JustComply's no-attorney-review process (Claude drafts, Harry's approval is the clearance — no outside counsel review is a precondition) and has not been approved yet. Nothing on this page is final, and none of it should be relied on until this notice is removed.
1. What this covers
This policy describes how JustComply collects, uses, and stores information when you use the free scanner, create a free account, or install the free monitoring banner.
2. What we collect
Using the free scanner (no account)
- The URL you submit for scanning.
- If you choose to unlock the full report by giving your email, we store that email address along with the URL and summary results (score, violation and incomplete-check counts) so we can send you the report and, if you opt in, follow up about JustComply.
Creating a free account
- Your email address and a workspace/contact name.
- Sites you register for scanning, and the ownership-verification status for each (verified via a DNS record or a file placed on your site — we don't collect anything beyond confirming the check passed).
- Scan results tied to your verified sites: score, violations found, the specific elements flagged, and history over time.
Installing the free monitoring banner
The banner sends a lightweight install signal back to us — which page it's loaded on and when it was last seen — so we can confirm it's installed and tell you if it stops reporting in. It does not collect information about your site's own visitors (no IP address or visitor identifier is recorded by this signal).
Security and abuse-prevention logging
Every scan request is logged with the requesting IP address, the target URL, and the outcome, to prevent abuse of the scanning service and to debug failures. See Section 6 for how long this is kept.
Booking a demo call
If you book and complete a demo call with our team, we record that the call happened against your account — who marked it complete on our end and an optional internal note — so a related discount can unlock automatically. We don't record or store the contents of the call itself.
We do not currently, and will not, sell your personal information to third parties.
3. What scanning actually touches
When JustComply scans a URL, it loads that page in an automated browser and runs a check against its rendered content. JustComply does not store a copy of the scanned site's full page content — it stores the scan's structured results (score, violations found, the specific elements flagged) rather than the page itself.
4. How we use what we collect
- To run the scans you request and show you the results.
- To send you the report you asked for, and — only if you opted in — occasional product updates.
- To operate your account and the monitoring banner.
- To prevent abuse of the free scanner (rate limiting).
- To pay a referral reward when someone signs up through your referral link (see Section 8).
- To determine whether your account qualifies for a discount tied to completing a demo call (see refund and coupon terms).
5. Where your data lives
JustComply's application data is stored with Supabase (Postgres-based infrastructure) and the application runs on Vercel. Both are third-party infrastructure providers bound by their own security practices and data-processing terms; JustComply does not operate its own physical servers.
6. Data retention
Scan results and security-log IP addresses are retained for 90 days by default, after which scan detail is removed and logged IP addresses are anonymized by an automated job. 90 days is an industry-typical default set as a product decision. Account and workspace data is retained for as long as your account is active. Free-checker email captures are retained until you ask us to delete them.
7. Your choices and rights
- Delete your workspace: if you have an account, you can permanently delete your entire workspace — sites, scans, and account data — yourself from Settings. This is a real, working, self-service deletion (not a support-ticket promise) and only the workspace owner can do it. It cannot be undone.
- Delete free-checker data: if you used the free scanner without an account and gave us your email, contact us (Section 10) to have that email and its associated scan summary deleted.
- Unsubscribe: every email we send includes an unsubscribe option.
- Access or export: contact us (Section 10) if you want a copy of the personal data we hold about you.
8. Cookies and local storage
This is the complete list of cookies and browser storage JustComply's own pages set — audited directly against the running product, not a generic template. Every one is essential to making the product work; none is a tracking or advertising cookie.
- Signed-in session (cookie): if you have an account, an essential cookie keeps you signed in. This is required for the product to work and isn't used for tracking.
- Referral link (cookie): if you arrive via someone's referral link, we set a first-party cookie (
jc_ref, 30 days) so we can credit them if you later sign up. The click itself is logged with a one-way hashed identifier, not your raw IP address. - In-progress form drafts (local storage): a handful of pages save what you're typing on your own device only — a call checklist, a policy-questionnaire draft, or the domain you typed on the free scanner before you signed in — so you don't lose it. Nothing here ever leaves your browser or is read by us.
As of this writing, JustComply does not use third-party analytics or advertising cookies/trackers — no such package is included in the product. If that changes, this section will be updated first.
9. Children's privacy
JustComply is not directed at children under 13, and we don't knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we'll delete it.
10. Contact
Questions about this policy, or requests to access/delete your data: harry@mycrazyagency.com.
11. Changes to this policy
We may update this policy as the product changes. We'll post the updated version here with a new effective date.