Legal

Privacy Policy

Stobox Technologies Inc., a company incorporated in Wyoming, US, with its registered office at 1049 Brighton Beach, Brooklyn, New York, US, operates the Compass platform. This page explains what we collect, why we collect it, and the choices you have.

What we collect

  • Account data: email, name, optional company + role, OAuth provider id.
  • Usage data: pages viewed, features used, timestamps; stored in our events table.
  • Session metadata: IP, user agent, city/country (via ipapi.co); stored in sessions.
  • Payment metadata: Stripe customer id, subscription id, invoice records. We never receive or store card numbers.
  • Assessment answers: your responses to the readiness questions. Sent to Anthropic only after you grant explicit in-product consent.
  • Uploaded content: project covers, KYB documents you upload to Supabase Storage.

Why we collect it

  • Provide and improve the service (core product operation).
  • Fulfil paid services · generate AI reports, issue invoices, process refunds.
  • Notify you about product updates you've opted into.
  • Detect abuse (rate limiting, security auditing).
  • Comply with legal obligations.

Who we share it with

Our public sub-processor list names every third-party service in the data path: Vercel (hosting), Supabase (database + auth + storage), Stripe (payments), Anthropic (AI report generation), Resend (transactional email), ipapi.co (IP geolocation). Each operates under its own Data Processing Addendum.

Your rights

You can request a copy of your data, correct inaccurate data, or request deletion of your account at any time by emailing legal@stobox.io. EU / UK residents have additional rights under GDPR / UK-GDPR (right to restrict processing, right to portability, right to object). We respond within 30 days.

Retention

Account data is retained while your account is active. On account deletion we delete all user-scoped records (profile, assessments, project data, invoices) except where we are legally required to retain them (e.g., tax records for statutory periods). Event and session logs are retained for up to 12 months for security-audit purposes, then purged.

Children

The service is not directed at people under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact legal@stobox.io and we will delete the account.

Changes

We update this policy periodically. The effective date at the bottom tells you when. Material changes will be announced in-product at least 30 days ahead of time.