ClauseSignal
Latest changesSearch clausesPricingSign inWatch clauses

Legal

Privacy Policy

Last updated August 19, 2026.

What we collect

Freyr And Sons LLC, a Texas limited liability company, operates ClauseSignal and is responsible for the personal data described in this policy. "We" and "us" below mean Freyr And Sons LLC.

ClauseSignal collects only what the service needs to work:

  • Your email address and authentication identity.
  • The exact FAR/DFARS clause identifiers you choose to watch.
  • Subscription and billing state identifiers from Stripe (plan, status, renewal date) — never your card number or other card data, which Stripe collects directly.
  • Minimal operational events needed to deliver notifications and diagnose problems (for example, email delivery status), plus the first timestamps when an account starts a trial, activates a watch, becomes paid, or cancels. Those four lifecycle timestamps measure the launch experiment and are deleted with the account.
  • Your IP address and basic request metadata, processed by Vercel's hosting firewall to rate limit and protect public pages, search, and sign-in. We do not store IP-address rate limit counters in our application database; Vercel handles firewall and request-log retention under its provider controls.
  • Anonymous page-view data for public clause, clause-history, clause-search, and pricing pages, processed by Vercel Web Analytics. We remove query strings and do not send page views from account, authentication, billing, support, or legal pages. Vercel reports aggregated pathname, time, referrer, coarse location, browser, operating-system, and device information. It uses no analytics cookie, does not associate a page view with an account, and discards its anonymous visitor identifier after 24 hours.
  • Strictly necessary authentication and session cookies set by our auth provider so you stay signed in. We set no advertising, tracking, or analytics cookies.

We do not accept or want your contracts, solicitations, proposals, or any controlled, proprietary, or otherwise sensitive documents. Do not send us that material.

How we use it

We use your data to operate your watchlist, send change and account notifications, process billing, and keep the service secure and reliable. Anonymous public-page traffic helps us evaluate whether relevant visitors find the product. We do not sell your data or use it for advertising.

Who processes it

The following service providers and payment parties handle data:

  • Vercel — hosts the application, provides its network firewall, runs background scheduling, and processes the limited anonymous public-page analytics described above.
  • Neon — hosts the database and manages authentication (sign-in, email verification, sessions).
  • Stripe and Link — process payments, hold your card details, and provide transaction support. For Managed Payments purchases, Link is the merchant of record and manages order and subscription records; we receive the billing-state identifiers needed to provide access.
  • Resend — delivers transactional and notification email on our behalf.
  • An AI provider (OpenAI) — reserved for an optional future plain-language summary feature. This processor is not active in the current version of the service; regulatory text would be treated as data, not instructions, if this feature is enabled.

Retention and deletion

You can request account deletion at any time from your account page. Doing so immediately stops email delivery and pauses your watchlist after any Stripe subscription is canceled and Stripe confirms that billing is in a terminal state. If Stripe cannot confirm cancellation, deletion is not scheduled and the account remains available for a retry. Your profile, watchlist, and notification data are permanently erased after a 14-day grace period. We retain only the minimal financial records required by law and never retain card data ourselves. Accepted regulatory source history is public-domain product data, not personal data, and is kept indefinitely so other users' monitoring keeps working.

Security

Every account, billing, and watchlist action is authorized server-side. Sessions and authentication are handled by our managed auth provider; we do not build or store password hashes ourselves. Secrets are stored only in server-side environment variables and are never exposed to the browser.

Your rights

You can request access to, correction of, or deletion of your personal data by emailing support@clausesignal.com. The fastest path for deletion is the in-product request on your account page described above, which also stops billing. We respond to rights requests within 30 days, never charge for them, and never reduce your service because you made one.

ClauseSignal is a business-to-business service offered in and directed to the United States. We do not market it to consumers outside the United States and do not knowingly collect data from anyone under 18.

Contact

Questions about this policy or your data: support@clausesignal.com. See the Terms of Service for the full service terms.

ClauseSignal

Terms of ServicePrivacy PolicyDisclaimerSupport

Email-only support: support@clausesignal.com