Legal

Privacy Policy

Effective August 17, 2026

This policy explains how the operator of LocalAuditHQ (“we,” “us,” or “our”) handles information when you use the website-auditing service.

Information we collect

Account and workspace information. We collect your name, email address, authentication records, organization, team memberships, invitations, and account settings.

Business and audit information. We collect the business details and public website URL you submit. The service reads public, same-origin HTML while respecting applicable robots rules and without executing page scripts. We store page extracts, technical signals, scores, findings, recommendations, comparisons, and report snapshots needed to provide and improve the service.

Demo and contact information. A public demo may store the audited URL and generated report. If you request the report by email, we store that address and delivery status. Consent to receive occasional follow-up tips is optional, separate, and recorded with the time it was given.

Billing information. We store Stripe customer, subscription, plan, and payment-status identifiers. Payment-card details are entered directly with Stripe and are not received or stored by LocalAuditHQ.

Service and usage information. We record audit jobs, provider usage, error context, plan codes, feature events, counts, and similar operational data. Server-side product telemetry uses internal identifiers and does not send email addresses, business names, phone numbers, audited URLs, or report contents.

How we use information

  • Provide accounts, audits, reports, comparisons, sharing, team access, billing, and support.
  • Send requested reports, authentication messages, invitations, service notices, and audit alerts.
  • Secure the service, enforce plan limits, prevent abuse, diagnose failures, and measure reliability and activation.
  • Send occasional product tips only when you separately consent. You may withdraw that consent at any time.
  • Comply with legal obligations and protect users, the service, and others.

Service providers

We use service providers to operate LocalAuditHQ: Supabase for authentication and database services, Vercel for hosting and application execution, Stripe for subscription billing, OpenAI for optional generated insights, Resend for product email, and PostHog for server-side product telemetry. They process information under their own terms and privacy commitments.

Website text sent to an AI provider is constrained to the summaries needed to generate insights. Deterministic scores and evidence do not depend on the AI provider.

Sharing and public links

We do not sell personal information. We share information with service providers as described above, when you direct us to share a report or invite a teammate, when required by law, or to protect rights and safety.

Client reports and emailed demo reports may be opened through time-limited links that do not require an account. Their random tokens are shown in the URL; only token digests are stored. Anyone with an active link can open that report, so share it carefully. Workspace administrators can revoke client report links.

Retention and security

We retain account and audit history while a workspace uses the service and as reasonably needed for billing, security, support, and legal obligations. Emailed demo report links are designed to expire after seven days. Client share links expire after the selected period or when revoked. Invitation links expire after seven days.

We use access controls, organization-scoped authorization, encrypted transport, hashed link tokens, and restricted server credentials. No system is perfectly secure, and we cannot guarantee absolute security.

Your choices

You may ask to access, correct, export, or delete personal information, subject to legal and operational retention requirements. Account settings let you correct your name and password. Workspace owners and administrators control team membership and report links.

To withdraw follow-up marketing consent or make a privacy request, email privacy@localaudithq.com. Service and security messages may still be necessary while your account remains active.

Children and changes

LocalAuditHQ is a business service and is not directed to children under 13. We may update this policy as the service changes. We will update the effective date and provide additional notice when a material change requires it.