Legal

Privacy Policy

Last updated: 2026-05-19

1. Data We Collect

Marketing site: email addresses (newsletter, waitlist, contact, demo request, ROI calculator submissions), UTM parameters, page view data.

Digital store: email, name, payment information (processed by Stripe — we do not store payment card data), purchase records.

SaaS application: organization profile, user profiles (name, email, role), technician profiles, license records (license type, state, number, issue/expiry dates), CE log entries, uploaded license documents, alert history, subscription data.

2. How We Use Your Data

Marketing: to send the content you requested (newsletter, ROI report), notify you when the product is available (waitlist), respond to inquiries (contact, demo). SaaS application: to deliver the license compliance service you subscribed to, process subscription billing, send renewal alerts per your configuration.

3. Third-Party Services

  • Supabase (Supabase Inc., USA) Database hosting, authentication, and file storage for both Project B (marketing/store) and Project A (SaaS app).

    Supabase DPA
  • Stripe (Stripe Inc., USA) Payment processing for SaaS subscriptions and digital product purchases. We do not store payment card data.

    Stripe Privacy Policy
  • Vercel (Vercel Inc., USA) Application hosting and serverless function execution.

  • Resend (Resend Inc., USA) Transactional email delivery.

  • Twilio (Twilio Inc., USA) SMS alert delivery for Professional+ tier subscribers.

  • Plausible Analytics (Plausible Analytics OÜ, EU) Privacy-friendly cookieless analytics for page view data. No personal data transmitted to Plausible.

  • Sentry (Functional Software Inc., USA) Error tracking. Sensitive personal data is not included in error payloads.

  • Google Analytics (if enabled) (Google LLC, USA) Cookie-based analytics for search and campaign attribution. See Cookie Policy for details.

4. Data Retention

Marketing contact data: retained until deletion requested. SaaS data: retained for the subscription lifetime plus 90 days. After 90 days, all SaaS organization data is permanently deleted.

5. Your Rights

Canadian residents (PIPEDA): right to access and correct personal information. EU/UK residents (GDPR): right to access, rectification, erasure, restriction, portability. California residents (CPRA): right to know, delete, correct, and opt out of sale/sharing.

To exercise rights, email eddy@licenseroadmap.com.

6. Cookies

See our Cookie Policy for the full list of cookies used.

7. Contact

Rovaryn Digital Inc., eddy@licenseroadmap.com.