← Back to Compliance Reporter
Privacy Policy
Last updated: 25 July 2026
This policy describes what Compliance Reporter actually collects and
does with it, in plain terms. It isn't a substitute for advice from
a qualified solicitor — if you rely on this page for formal legal
compliance, have it reviewed first.
Who we are
Compliance Reporter provides UK company compliance status checks and
verifiable PDF certificates sourced from the Companies House public
register. For any question about this policy or your data, contact
contact@compliancereporter.llc.
What we collect
We collect only what the service needs to function:
- Account data — your email address and a
password. Passwords are stored as a salted hash; we never store
or can see your actual password.
- Payment confirmation — payments are handled
entirely by Stripe. We never receive or store your card details.
We only receive confirmation that a payment succeeded, linked to
your email and a certificate or subscription ID, along with the
billing name you gave Stripe at checkout — we don't ask for
your name anywhere else, but we do keep the one Stripe already
collects once you pay.
- Company check data — when you search or check
a company, we query the Companies House public register on your
behalf. If you're signed in, we may store the result so you can
find it again later.
- Certificates — the PDF certificates you
generate, and the data snapshot behind them, are stored so you
can re-download them and so third parties can verify a
certificate's authenticity using its unique code.
- Content you add — notes, tasks, and contact
details you create for companies you're tracking. If you enter
information about another person (a contact's name, email,
phone), you're responsible for having a lawful reason to store
that about them.
- Technical data — a session token that keeps
you signed in (expires automatically after 30 days of
inactivity), and your IP address, used only to prevent automated
abuse of the Companies House lookup service — never for tracking
or profiling.
What we don't do
No analytics or tracking scripts run on this site. We don't use
advertising cookies, and we don't sell or share your data with
third parties for marketing purposes.
Who we share data with
- Stripe — processes all payments and
subscription billing on our behalf.
- Companies House — the source of the
underlying public company data. We query their public register;
we don't send them any of your account data.
Why we process your data
To provide the service you've signed up for or paid for
(contract), to keep the platform secure and prevent abuse of the
shared Companies House API access (legitimate interest), and
anywhere else required by law.
How long we keep it
Account data is kept while your account is active. Certificates
are kept indefinitely by design — their entire purpose is to
remain verifiable by third parties (an employer, a supplier, a
bank) long after you generate them, so deleting your account does
not delete certificates you've already issued. Everything else
tied to your account (notes, tasks, contacts, saved checks) is
deleted when your account is deleted.
Your rights
Under UK data protection law, you can:
- Request a copy of your data — the CSV export in your dashboard
gives you this instantly for certificates, tasks, notes, and
contacts.
- Correct inaccurate account data.
- Request deletion of your account.
- Object to or restrict certain processing.
To exercise any of these, email
contact@compliancereporter.llc.
Account deletion is currently handled manually on request rather
than as a self-service button — we aim to action requests within
a few business days.
Security
Passwords are salted and hashed, never stored in plain text.
Sessions expire automatically. Card and payment details never
touch our servers — Stripe handles that entirely.
Children
This service is not directed at, or intended for, children.
Changes to this policy
If this policy changes materially, we'll update the date at the
top of this page.