Privacy Policy
Last updated: August 10, 2026
Penn Parsons LLC ("Company," "we," "us," or "our") operates CompliantVendor (the "Service"), a platform that helps organizations assess, track, and manage third-party vendor risk and compliance. This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you.
This Policy applies to everyone who visits our website or uses the Service, including: (a) staff of an organization that has subscribed to CompliantVendor ("Organization," "Organization Users"), and (b) vendor contacts invited by an Organization to complete questionnaires or submit evidence through the CompliantVendor vendor portal ("Vendor Users"). Where it matters, this Policy describes the two roles separately.
A note on roles. When an Organization uses CompliantVendor to assess a Vendor, the Organization decides what information to collect and how it will be used for its own vendor-risk-management purposes. In that relationship, the Organization is the data controller and Penn Parsons LLC acts as a service provider / processor on the Organization's behalf. If you are a Vendor User with questions about how a specific Organization uses your responses, please contact that Organization directly; we will also honor requests as described below.
1. Information We Collect
Account and registration information. When you or your Organization creates an account, we collect information such as name, work email address, job title, phone number, company name, and password (stored only as a salted hash — we never store or can recover your plain password).
Vendor and compliance data ("Service Data"). The core of the Service is data that Organizations and Vendor Users enter to assess and document vendor risk: questionnaire responses and explanations, uploaded evidence documents (e.g., policies, certifications, audit reports), remediation items and comments, risk scores and tiers, agreements and electronic signatures, and related audit-trail records. Service Data may include information a Vendor User considers sensitive about their own business (e.g., security practices, past incidents, subcontractor relationships). We do not control what an Organization or Vendor User chooses to submit as Service Data, and we ask that Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) never be entered into the Service — the Service is not authorized to store either.
Payment information. Subscription payments are processed by Stripe, Inc. We do not receive or store full payment card numbers; Stripe provides us a token and limited billing metadata (e.g., card brand, last four digits, billing address) needed to manage your subscription.
Usage and log data. We automatically collect information about how you interact with the Service — IP address, browser and device information, pages viewed, actions taken, and timestamps — for security, troubleshooting, and audit-logging purposes (many actions in the Service are recorded in an audit log visible to your Organization's administrators, by design, so that changes to compliance records are traceable).
Cookies. We use only strictly necessary cookies: a session cookie that keeps you signed in, and a preference cookie that remembers your light/dark theme choice. We do not use advertising or cross-site tracking cookies, and we do not sell or share your information for behavioral advertising.
2. How We Use Information
We use the information described above to: provide, operate, and secure the Service; authenticate users and enforce access controls; process subscription payments and manage billing; send transactional emails (e.g., sign-in links, questionnaire and remediation notifications, receipts); provide customer support; monitor for and investigate suspicious activity; maintain audit trails required for compliance workflows; and improve the Service's reliability and usability. We do not use Service Data submitted by Organizations or Vendor Users to train third-party AI models, and we do not sell personal information.
3. How We Share Information
We share information only as follows:
- With your Organization. If you are a Vendor User, the questionnaire answers, evidence, and related data you submit are shared with the Organization(s) you have authorized, exactly as described within the Service itself.
- Subprocessors. We use a small number of vetted service providers to operate CompliantVendor:
- Stripe, Inc. — payment and subscription processing.
- Amazon Web Services (AWS) — application hosting and encrypted file storage for evidence and documents.
- MailerSend — delivery of transactional email (sign-in links, notifications, receipts).
Each is bound by its own privacy and security commitments and is only permitted to use your information to provide services to us.
- Legal and safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith it is necessary to protect the rights, property, or safety of Penn Parsons LLC, our customers, or others.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; we will provide notice before information becomes subject to a different privacy policy.
- Aggregated or de-identified data. We may share information that has been aggregated or de-identified such that it no longer identifies you or your Organization.
We do not sell personal information, and we have not sold personal information in the preceding 12 months.
4. Data Security
We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption of data in transit and at rest for stored evidence files, access controls scoped to your Organization, multi-factor authentication support, and audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
5. Data Retention
We retain account and Service Data for as long as your Organization's subscription is active and as needed to provide the Service, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. An Organization may request deletion of its account data by contacting us at the email address below, subject to records we are required to retain by law or that are needed to complete an audit trail already in progress.
6. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information we hold about you, and to opt out of certain uses. Because we do not sell personal information, there is no sale to opt out of. To exercise any available rights, contact us at info@compliantvendor.com; we will verify your request and respond within the time required by applicable law. If you are a Vendor User whose data was submitted through an Organization's assessment, we may direct your request to that Organization where it is the party responsible for that data, and will still assist as required by law. We will not discriminate against you for exercising these rights.
7. Children's Privacy
CompliantVendor is a business-to-business service intended for use by working professionals. It is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will delete it.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice (such as an in-app notice or email to Organization administrators).
9. Contact Us
Penn Parsons LLC
112 Lacey Oak Lane
Bonaire, Georgia 31005
Email: info@compliantvendor.com