Privacy Policy
This policy explains what we collect, why, and the choices you have. We keep it plain because privacy tools written in legalese help no one.
Last updated August 2026
ComplyMo ("ComplyMo," "we," "us") provides a compliance widget that adds accessibility, GDPR, and cookie-consent tooling to a website with a single line of code. This policy covers two distinct groups: our customers (the people who sign up for an account) and end-visitors (the people who visit a website that runs the ComplyMo widget). The relationship differs for each, and we call out which is which throughout.
A note we repeat where it matters: ComplyMo provides compliance tooling, not legal advice. This policy describes our own data practices; it is not a template for yours.
Data we collect from customers
When you create and use a ComplyMo account, we collect:
- Account details — the email address you sign up with, and basic profile information you choose to add.
- Workspace and project configuration — the names of your workspaces and projects, the domains you connect, and the widget settings you choose (languages, consent categories, theme, and similar).
- Billing information — handled by our payment processor. We store a customer reference, plan, and invoice history; we do not store full card numbers on our servers.
- Support and product communications — messages you send us and our replies.
Widget analytics (aggregated and pseudonymous)
To show you how your widget is performing, we collect aggregated usage metrics such as counts of widget loads, consent prompts shown, and consent choices recorded. These metrics are pseudonymous: they are tied to a project, not to a named individual, and we do not build advertising or marketing profiles from them.
How the widget handles end-visitor data
When the ComplyMo widget runs on a customer's site, it may record an end-visitor's consent decision so the site can honor it on later visits. That record is kept pseudonymously — for example, a consent state stored against a random identifier rather than a name or email.
- We log consent decisions so preferences persist and can be demonstrated if challenged.
- We do not sell end-visitor personal data, and we do not use it to target advertising.
- For end-visitor data, the customer running the widget is the controller and ComplyMo acts as their processor. The customer's own privacy notice governs that relationship; our Data Processing Addendum sets out the terms.
Cookies on our own site
The complymo.com marketing site uses a small number of cookies for essential session handling and privacy-respecting analytics. The full list, purposes, and durations are in our Cookie Policy.
Sub-processors
We rely on a short list of trusted vendors to run the service. Each is bound by contract to protect the data they handle:
- Cloud hosting and infrastructure — to run the application and store data.
- Stripe — to process payments and manage subscriptions.
- Email delivery — to send transactional and account email.
We keep our sub-processor list current and update it here when it changes materially.
How we use data
- To provide, operate, and secure the service.
- To bill for paid plans and prevent fraud.
- To respond to support requests and send essential account notices.
- To understand aggregate usage so we can improve the product.
Data retention
We keep customer account data for as long as your account is active. When you close your account, we delete or anonymize personal data within a reasonable period, except where we must retain records to meet legal, tax, or accounting obligations. Aggregated, pseudonymous analytics that cannot be linked back to an individual may be kept longer.
International transfers
ComplyMo is based in the United States, and data may be processed there and in other countries where we or our sub-processors operate. Where data moves across borders, we rely on recognized safeguards — such as Standard Contractual Clauses — to protect it.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. You can exercise most of these directly from your dashboard, or by emailing us. We do not discriminate against you for exercising these rights.
End-visitors who want to exercise rights over data collected through a widget should contact the site that runs it, since that business is the controller. We will support our customers in responding to those requests.
Security
We use industry-standard security practices — encryption in transit, access controls, and regular review — to protect the data we hold. No system is perfectly secure, but we work to reduce risk and to respond quickly if something goes wrong.
Changes to this policy
We may update this policy as the product and the law evolve. When we make material changes, we will revise the date above and, where appropriate, notify you directly.
Contact us
Questions about privacy or a data request? Email privacy@complymo.com. For anything else, reach us at hello@complymo.com.

