ClearPolicy

Privacy Policy

Last updated: August 6, 2026

ClearPolicy ("we," "our," or "us") respects your privacy. This Privacy Policy explains what information we collect, how we use it, the third parties and integrations involved in providing the service, and how we protect it.

If your organization uses ClearPolicy to manage people and send document requests, see also our Data Processing Agreement, which describes how we process personal data on your organization's behalf, where that data is hosted, and the security measures we apply. Our Terms of Service govern use of the service generally.

Information We Collect

We collect only the information necessary to provide the service and operate, secure, support, and improve ClearPolicy.

For account holders (organizations)

  • Name
  • Email address
  • Organization name
  • Login and account information
  • Password hash and authentication/security settings, such as email verification status and two-factor authentication status, when enabled
  • If you register a passkey, we store a credential identifier and public key associated with your account, plus a label you choose and usage metadata (such as last used time). We do not receive or store biometric data from your device.
  • Account preferences and settings
  • Billing and subscription information, including subscription status, trial status, Stripe customer identifier, payment method type, and payment method last four digits, as provided by our billing processor
  • Social login and connected account information when you choose to use third-party sign-in or integrations, such as provider account identifier, email address, profile image, access scopes, and encrypted access or refresh tokens

For people (policy recipients)

  • Name
  • Email address
  • Phone number (if provided)
  • Policy and document activity, including sent, viewed, reminded, expired, acknowledged, and signed timestamps
  • Recipient message content included by the sending organization, if any

Automatically collected information

  • IP address
  • Browser and device information
  • Access timestamps
  • Session and security-related data needed to authenticate users, maintain sessions, and protect the service
  • Usage and analytics information collected through our analytics tools, which may include page visits, navigation events, referring pages, and user or organization-level identifiers used to understand product usage

For electronic signatures and acknowledgments

  • Typed name for electronic signatures (historical click-only completions may not include a typed name)
  • Completion timestamp
  • IP address at time of completion
  • Browser/user agent information at time of completion
  • Document version signed
  • Activity log history associated with the request, such as viewed, reminded, expired, signed, or acknowledged events
  • A document integrity hash used to confirm the completed document matches the version presented at the time of completion

Paper on file (when your organization records a wet-ink completion)

  • An uploaded signed paper copy (file) associated with a pending document request
  • Completion method (paper versus electronic)
  • Which team member recorded the paper completion, and when it was recorded

Paper on file is stored so your organization can keep a complete compliance record in ClearPolicy when someone cannot complete online. It is separate from the electronic signature evidence described above.

Document content and files

  • Documents, revisions, uploaded PDFs, editor content, exported PDFs from supported import integrations, and related file metadata
  • Source metadata for imported or synced records, such as the originating provider or external record identifier

Google Drive Integration (Optional Feature)

When you choose to connect your Google Drive account to import documents:

What Google data we collect

  • Your Google account email address (for authentication)
  • Google Doc IDs and names of documents you explicitly select via the Google Picker
  • Google account profile information made available during sign-in, such as your name and profile image, if you choose Google sign-in

We do not access, scan, or collect any other files or data from your Google Drive beyond the files you explicitly authorize or select for use with the feature.

How we use Google data

  • We export the Google Docs you select as PDF files for policy management and signature collection
  • Exported PDFs are stored in our secure infrastructure and treated as policy documents
  • We only access Google Docs you explicitly choose through our document picker interface
  • Google authentication tokens are encrypted and stored securely

How Google data is shared

  • We do not sell Google Drive data
  • We do not disclose Google Drive content to third parties except as necessary to provide the service, comply with law, or where you separately authorize an integration or API client to access your ClearPolicy data
  • Google data is used solely to provide the document import feature you requested
  • Your Google authentication can be disconnected at any time from Settings → Integrations

Google data protection and retention

  • All Google authentication tokens are encrypted in our database
  • Access to Google Drive is limited to read-only permissions for document export
  • We use industry-standard encryption (HTTPS/TLS) for all data transmission
  • You can revoke ClearPolicy's access to your Google Drive at any time through your Google Account settings
  • Once a Google Doc is exported as a PDF, we no longer access the original Google Doc unless you later choose to reconnect or refresh the import
  • If you disconnect Google Drive access, the Google Drive scope and related access needed for Drive import are removed

Microsoft OneDrive Integration (Optional Feature)

When you choose to connect your Microsoft account with OneDrive access to import documents:

What Microsoft data we collect

  • Your Microsoft account email address or user principal name (for authentication and to identify the connected account)
  • OneDrive or SharePoint file identifiers, names, and related metadata for files you explicitly select for import
  • Microsoft account profile information made available during sign-in, such as your name, if you choose Microsoft sign-in

We do not access, scan, or collect other files or data from your OneDrive beyond the files you explicitly authorize or select for use with the feature.

How we use Microsoft data

  • We download the Word documents or PDFs you select and convert Word documents to PDF for policy management and signature collection
  • Imported PDFs are stored in our secure infrastructure and treated as policy documents
  • We only access OneDrive files you explicitly choose through our document picker interface
  • Microsoft authentication tokens are encrypted and stored securely

How Microsoft data is shared

  • We do not sell OneDrive data
  • We do not disclose OneDrive content to third parties except as necessary to provide the service, comply with law, or where you separately authorize an integration or API client to access your ClearPolicy data
  • Microsoft data is used solely to provide the document import feature you requested
  • Your OneDrive access can be disconnected at any time from Settings → Integrations

Microsoft data protection and retention

  • All Microsoft authentication tokens are encrypted in our database
  • Access for OneDrive import is limited to read-only permissions for document download and export
  • We use industry-standard encryption (HTTPS/TLS) for all data transmission
  • You can revoke ClearPolicy's access at any time through your Microsoft account permissions or work or school admin settings, as applicable
  • Once a file is imported as a PDF, we no longer access the original OneDrive file unless you later choose to reconnect or import again
  • If you disconnect OneDrive access, the Microsoft files scope and related access needed for OneDrive import are removed

Planning Center Integration (Optional Feature)

When you choose to connect your Planning Center account to sync people and lists:

What Planning Center data we collect

  • Your Planning Center account identifier (for authentication)
  • Names, email addresses, and phone numbers of people in lists you explicitly choose to sync
  • List names you map to ClearPolicy groups
  • Access scopes and encrypted authentication tokens needed to maintain the connection

How we use Planning Center data

  • To create and update people records in your ClearPolicy organization
  • To assign documents based on group membership
  • We only access lists you explicitly connect through integration settings

How Planning Center data is shared

  • We do not sell Planning Center data
  • We do not disclose Planning Center-sourced data to third parties except as necessary to provide the service, comply with law, or where you separately authorize an integration or API client to access your ClearPolicy data
  • Data is used solely to provide the sync feature you requested
  • Your Planning Center connection can be disconnected at any time from Settings → Integrations

Microsoft sign-in (optional)

In addition to Google sign-in described above, we support optional Microsoft sign-in for team members. If you choose to use Microsoft sign-in, we may collect and store your Microsoft account identifier, email address, name, profile image, access scopes, and encrypted authentication tokens as necessary to authenticate you and maintain the connection. Planning Center is an optional integration for syncing people and lists, not a sign-in method — see the Planning Center section above.

API, automation, and AI-connected integrations

ClearPolicy may allow organizations to connect authorized API clients, automation platforms, and AI-enabled tools. Depending on the permissions granted, these integrations may access organization data such as people, documents, document status, and document request / completion information. We process and disclose that data only as needed to provide the authorized integration and subject to the permissions granted by the organization.

AI-assisted features

We use AI service providers for limited features such as internal organization classification and in-app product support for team members. These features may process team member account information, billing context, support messages, and related conversation context. Routine product workflows are not designed to send people records or document content to these providers; team members should not include people data, document content, or other sensitive information in support messages.

We do not use customer people records or document content to train third-party artificial intelligence models.

How We Use Information

We use information to:

  • Deliver policy acknowledgment requests
  • Track acknowledgment activity
  • Send notifications and reminders
  • Maintain account security
  • Improve the service
  • Authenticate users and connected accounts
  • Provide billing, subscription management, customer support, and in-app product support assistance
  • Generate receipts, reports, exports, and audit history
  • Detect, prevent, and investigate fraud, abuse, unauthorized access, and other security incidents

We do not sell personal data or use it for third-party advertising on other sites.

Policy Content

Policies uploaded or written in ClearPolicy belong to the organization that created them. We do not review, modify, or reuse policy content for any other purpose except as necessary to store, display, process, secure, transmit, export, and support the service features you use.

Email Communications

We send emails only for:

  • Account access
  • Policy acknowledgment requests
  • Notifications and reminders
  • Important service updates
  • Billing and subscription-related notices
  • Integration or security notices when action is required

Recipients can stop receiving reminder emails by contacting the organization that sent the request or by contacting us at [email protected] where applicable.

Data Sharing

We do not share, sell, or transfer personal data to third parties except:

  • When required to operate the service (email delivery, infrastructure providers, payment processing, analytics, authentication providers, and integration providers)
  • When you authorize an API client, automation, AI integration, or other connected service to access your data
  • When required by law
  • In connection with enforcing our terms, protecting rights and safety, preventing fraud or abuse, or responding to security incidents
  • To measure the effectiveness of our own marketing campaigns, as described in the Advertising and conversion measurement section below

We never sell your data to third parties for advertising, marketing, or any other commercial purpose.

Data Security

We use reasonable administrative, technical, and physical safeguards to protect your data. Access is limited to authorized systems and personnel.

Sensitive credentials and integration tokens are encrypted at rest where supported by our systems. We also use HTTPS/TLS in transit and role-based access controls within the product.

Third-Party Services

ClearPolicy uses third-party services to operate, including:

  • Stripe for payment processing and billing management
  • Resend for transactional email delivery
  • Cloud infrastructure providers for application hosting, database hosting, document conversion, private file storage, and independent backup copies of high-value files (primarily in the United States)
  • Matomo for product and marketing analytics (hosted in Seattle, United States), which may use cookies or user-level identifiers in the application
  • Laravel Nightwatch for application monitoring and error tracking
  • OpenAI for limited AI-assisted features, including internal organization classification and in-app product support for team members — see the AI-assisted features section above
  • Authentication providers such as Google and Microsoft when you choose to use sign-in
  • Planning Center for optional people and list synchronization when you enable that integration

We also use Zapier and may provide API access and MCP access to authorized third-party integrations and AI-enabled tools. Data accessed through these integrations is limited to what is necessary for the integration to function and is subject to the third party's own privacy policy.

These providers have their own privacy policies and security measures. Customer data is stored primarily in the United States. Some providers may process limited technical metadata in other locations as part of normal service delivery. See our Data Processing Agreement for hosting and sub-processor details.

Advertising and conversion measurement

We may use conversion measurement technologies on our marketing website to evaluate the effectiveness of our own advertising on platforms such as Google and Meta. Depending on your journey, this may include page visits, signup or account-creation events, hashed email identifiers, click-attribution parameters (such as gclid or fbclid), and limited device or network information.

We use this only to understand whether our marketing is working — not to sell personal data, deliver third-party ads on other sites, or build advertising profiles for unrelated purposes.

Data Retention

Account data: Data is retained as long as an account is active or as required to provide the service.

Document and acknowledgment records: Organizations may archive or delete certain people, documents, or related records through the ClearPolicy interface, subject to product rules and data integrity safeguards. Completed signature and acknowledgment records are retained to preserve legal audit trails and are not subject to a scheduled purge date. See our Data Processing Agreement for more detail.

Google Drive integration: Authentication tokens are retained until you disconnect the relevant Google connection or access scope.

Microsoft OneDrive integration: Authentication tokens are retained until you disconnect the relevant Microsoft files connection or access scope.

Planning Center integration: Authentication tokens are retained until you disconnect the relevant Planning Center connection or access scope.

Account and organization removal: What happens depends on whether your organization has completed document requests:

  • Organizations with completed document requests: The organization is deactivated, access ends, and completion records are retained for legal audit purposes as described in our Data Processing Agreement
  • Organizations with no completed document requests: Associated personal data may be deleted from our active systems when you remove the organization

You may request export or deletion assistance at any time by contacting [email protected], subject to retention rules that apply to completed signature and acknowledgment records.

Your Rights

You may request:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion of your data
  • Export of your data
  • Information about authorized third-party integrations connected to your account, where applicable

To exercise these rights, contact us at [email protected].

People (policy recipients): If you received a policy acknowledgment request and have questions about your data, you may contact the organization that sent the request or reach us directly at [email protected].

Your Responsibilities

Organizations using ClearPolicy are responsible for:

  • The content of their policies
  • How acknowledgment data is used internally
  • Compliance with applicable laws and regulations
  • Ensuring they have an appropriate legal basis, notice, and consent where required for the personal data they upload, import, sync, or collect through ClearPolicy
  • Managing the third-party integrations, API clients, and automation tools they authorize to access their ClearPolicy data

ClearPolicy does not provide legal advice.

Data Processing Agreement

When your organization uploads people records, sends document requests, or collects signatures and acknowledgments through ClearPolicy, you are the data controller and ClearPolicy acts as your data processor for that information.

Our Data Processing Agreement covers that processing relationship in detail, including:

  • Where customer data is hosted (United States)
  • Sub-processors used to operate the service
  • Security measures and breach notification
  • Retention of signature and acknowledgment records
  • Deletion, export, and international transfer documentation

The Data Processing Agreement is incorporated into our Terms of Service and applies when you create or use a ClearPolicy account.

Children's Privacy

ClearPolicy is not intended for use by children. We do not knowingly collect personal data directly from children.

Cookies and Analytics

We use cookies and similar technologies for authentication, session management, security, user preferences, and analytics.

  • Essential cookies help keep users signed in, maintain secure sessions, and protect the service
  • Preference cookies may remember settings such as interface appearance or navigation state
  • Analytics tools may collect information about page visits, navigation, device/browser details, and user or organization-level identifiers to help us understand and improve product usage

We do not use cross-site advertising trackers for retargeting or sell analytics data for advertising purposes. We may use conversion-measurement technologies on our own sites and application to evaluate our marketing campaigns, as described in the Advertising and conversion measurement section above.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date.

Contact Us

If you have questions about this Privacy Policy, contact us at: [email protected]

Related policies: