Privacy Policy

Last updated: April 1, 2026

Duey Compliance, Inc. · California, United States · privacy@getduey.com

Your privacy matters to Duey Compliance. This Privacy Policy explains what information we collect, how we use and protect it, and the choices available to you — including your rights under the California Consumer Privacy Act (CCPA/CPRA) and other applicable state laws.

Contents
  1. Introduction and Scope
  2. Information We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. Data Retention
  6. Cookies and Tracking Technologies
  7. Data Security
  8. Your Privacy Rights
  9. Children's Privacy
  10. International Data Transfers
  11. Business-to-Business Data
  12. AI and Automated Decision-Making
  13. Third-Party Links and Integrations
  14. Changes to This Privacy Policy
  15. Contact Us

1. Introduction and Scope

Duey Compliance, Inc. ("Duey," "we," "us," or "our") operates the Duey Compliance platform accessible at getduey.com and through related mobile applications and APIs (collectively, the "Service" or "Platform"). This Privacy Policy describes our practices for collecting, using, disclosing, and protecting personal information and business information in connection with your use of the Service.

This Policy applies to:

  • Visitors to our website and marketing pages
  • Registered account holders and their authorized users
  • Business owners, operators, and representatives who use the Platform
  • Individuals who contact us for support, sales, or other inquiries

This Policy does not apply to the practices of third parties that we do not own or control, or to individuals that we do not employ or manage, except as described herein.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account, use the Service, or communicate with us, you may provide the following categories of information:

  • Account Registration Data: Name, email address, phone number, job title, and password
  • Business Profile Data: Business legal name, DBA names, business type and structure, industry vertical(s), Federal Employer Identification Number (FEIN), California Entity Number or other state identifiers, business address(es), mailing address, formation date, number of employees, annual revenue range, and operational details relevant to your compliance profile
  • Location Data: Business address, physical locations of operation, counties and municipalities where you conduct business
  • Licensing and Permit Data: Existing license numbers, permit types, agency names, expiration dates, and compliance history that you upload or enter
  • Document Data: Permits, licenses, certificates, notices, and other compliance documents you upload to the Platform
  • Payment Information: Billing name, address, and credit or debit card information (processed through our third-party payment processor; Duey does not store full card numbers)
  • Communications: Messages you send to our support team, feedback, survey responses, and any other communications with us

2.2 Information Collected Automatically

When you access or use the Service, we and our service providers automatically collect:

  • Log Data: IP address, browser type and version, operating system, referring URLs, pages visited, features used, date and time of access, and session duration
  • Device Information: Device type, unique device identifiers, device operating system, and mobile network information
  • Usage Data: Features and pages accessed, searches performed, compliance scans run, obligations viewed, deadlines set, and user interactions with the Platform interface
  • Cookies and Tracking Data: See Section 6 (Cookies and Tracking Technologies) for details
  • Performance Data: Error logs, crash reports, and performance diagnostics used to maintain and improve the Service

2.3 Information from Third-Party Sources

We may collect or receive information about you or your business from:

  • Government Databases: California Secretary of State, California Department of Consumer Affairs, Contractors State License Board (CSLB), California Department of Alcoholic Beverage Control (ABC), county assessor and recorder databases, municipal licensing portals, and other public agency sources used to verify or supplement your business profile
  • Business Verification Services: Third-party providers used to verify business identity and legitimacy
  • Data Enrichment Providers: Services that help us supplement business profile data with publicly available information
  • Professional Referral Networks: If a compliance professional refers you to the Platform, we may receive basic contact information from that referral
  • OAuth Integrations: If you connect third-party accounts (such as state licensing portals), we receive the data you authorize through that connection

2.4 Sensitive Business Information

The nature of compliance management means we may collect sensitive business information, including details about regulatory violations, pending investigations, government notices, and financial information. We treat this information with heightened care and use it only as necessary to provide and improve the Service.

3. How We Use Your Information

3.1 Providing and Improving the Service

We use the information we collect primarily to operate and deliver the Service, including:

  • Creating and managing your account and business profile
  • Discovering and surfacing applicable compliance obligations based on your business type, industry, and location
  • Generating compliance calendars, deadline alerts, and status reports
  • Monitoring license and permit expiration dates through automated checks
  • Facilitating document storage and compliance tracking
  • Processing payments and managing your subscription
  • Providing customer support and responding to inquiries
  • Conducting internal research and development to improve the Service
  • Training and improving our compliance obligation algorithms and data models (using aggregated, de-identified data only)

3.2 Communications

We use your contact information to communicate with you about:

  • Compliance deadline alerts and regulatory reminders
  • Account and subscription notifications (renewals, receipts, changes)
  • Platform updates, new features, and service announcements
  • Marketing and promotional communications about Duey products and services (subject to your opt-out rights)
  • Responses to your support requests and inquiries

You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by adjusting your notification preferences in your account settings. Transactional and operational communications (e.g., receipts, security alerts, critical compliance reminders) may continue even if you opt out of marketing.

3.3 Analytics and Research

We use aggregated, de-identified data derived from user behavior and business profiles to analyze trends, understand how the Service is used, measure the effectiveness of features, and conduct compliance research. This de-identified data may be used or shared for research or business purposes without restriction.

3.4 Legal and Safety Purposes

We may use your information to:

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from government authorities, courts, and law enforcement
  • Enforce our Terms of Service and protect the rights, property, and safety of Duey, our users, and the public
  • Detect, investigate, and prevent fraud, abuse, and security incidents

4. How We Share Your Information

We do not sell your personal information to third parties for their own marketing purposes. We share information only in the following circumstances:

4.1 Service Providers

We share information with vendors and service providers who perform functions on our behalf, such as:

  • Cloud infrastructure and data hosting providers
  • Payment processors (e.g., Stripe) for billing and subscription management
  • Email and communications service providers
  • Analytics and performance monitoring tools
  • Customer relationship management (CRM) platforms
  • Identity verification and fraud prevention services

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

4.2 Government and Regulatory Data Sources

To verify your business profile and surface compliance obligations, the Service queries public government databases and registries. This is done on your behalf to provide the Service and does not constitute a disclosure of your data to those agencies beyond what you independently have on record.

4.3 Professional Network Connections

If you choose to connect with a compliance professional through the Platform (e.g., a CPA, attorney, or licensing consultant from our referral network), we will share relevant business profile and compliance data with that professional at your direction. Such professionals are independently responsible for the data you share with them.

4.4 Aggregated and De-Identified Data

We may share aggregated, de-identified information that cannot reasonably be used to identify you or your business for industry research, marketing, analytics, or other lawful purposes.

4.5 Business Transfers

If Duey undergoes a merger, acquisition, restructuring, bankruptcy, or sale of all or substantially all of its assets, your information may be transferred as part of that transaction. We will notify you by email and/or prominent notice on the Platform in advance of any such transfer and describe your choices at that time.

4.6 Legal Requirements and Safety

We may disclose your information if we believe in good faith that such disclosure is necessary to:

  • Comply with a subpoena, court order, or other legal process
  • Respond to a government or regulatory authority request
  • Enforce our Terms of Service
  • Protect the rights, property, or safety of Duey, our users, or the public
  • Investigate potential fraud or security incidents

4.7 With Your Consent

We may share your information for any other purpose with your explicit consent.

5. Data Retention

We retain personal and business information for as long as necessary to provide the Service, fulfill the purposes described in this Policy, and comply with legal obligations:

Data CategoryRetention Period
Active account dataDuration of subscription + 2 years after account closure
Compliance and permit recordsUp to 7 years (consistent with applicable statute of limitations)
Billing records7 years (tax and accounting purposes)
Log and usage dataUp to 13 months in identifiable form, then aggregated or deleted
Marketing opt-out recordsIndefinitely, to honor your preferences

After applicable retention periods, we will securely delete or anonymize your information. You may request earlier deletion of certain data as described in Section 8 (Your Privacy Rights).

6. Cookies and Tracking Technologies

6.1 Types of Cookies We Use

Cookie TypePurposeCan Be Disabled?
Strictly NecessaryAuthentication, security, session managementNo
FunctionalLanguage preferences, remembered settingsYes
AnalyticsUsage analysis, performance improvement (e.g., Google Analytics)Yes
Marketing / AttributionCampaign effectiveness measurementYes

6.2 Managing Cookies

Most browsers allow you to control cookies through settings. You can also opt out of certain analytics and marketing cookies through our Cookie Preference Center, accessible via the "Cookie Settings" link in the footer of our website. Note that disabling strictly necessary cookies will impair your ability to use the Platform.

To opt out of Google Analytics tracking specifically, you may install the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

6.3 Do Not Track

Some browsers offer a "Do Not Track" (DNT) feature. Our Platform does not currently respond to DNT signals because there is no industry consensus on how such signals should be interpreted. We will revisit this position as standards evolve.

7. Data Security

We implement commercially reasonable administrative, technical, and physical security measures designed to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • TLS/SSL encryption for data in transit
  • Encryption of sensitive data at rest
  • Role-based access controls and least-privilege principles
  • Multi-factor authentication options for account access
  • Regular security assessments and vulnerability scanning
  • Vendor security reviews for third-party service providers
  • Incident response procedures

No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your information, we will notify you as required by applicable law.

8. Your Privacy Rights

California residents have comprehensive privacy rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Residents of other states have additional rights that we honor as Duey expands nationally.

8.1 California Residents — CCPA/CPRA Rights

RightWhat It Means
Right to KnowRequest disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection and use, and the categories of third parties with whom we have shared it.
Right to DeleteRequest deletion of personal information we have collected about you, subject to certain exceptions (e.g., completing transactions, legal obligations, security).
Right to CorrectRequest correction of inaccurate personal information we maintain about you.
Right to Opt Out of Sale or SharingWe do not sell personal information. To the extent our use of analytics cookies could be considered "sharing" under the CPRA, you may opt out via our Cookie Preference Center.
Right to Limit Sensitive Data UseLimit our use of sensitive personal information (including government ID numbers) to what is necessary to provide the Service.
Right to Non-DiscriminationWe will not discriminate against you for exercising any CCPA/CPRA right — no service denial, different pricing, or reduced quality of service.

8.2 Rights for Residents of Other States

As Duey expands operations nationally, we recognize and honor privacy rights established by other state laws, including:

  • Virginia (CDPA): Rights to access, correct, delete, and opt out of targeted advertising and sale of personal data
  • Colorado (CPA): Rights to access, correct, delete, opt out of targeted advertising, and data portability
  • Connecticut (CTDPA): Rights to access, correct, delete, data portability, and opt out
  • Texas (TDPSA): Rights to access, correct, delete, data portability, and opt out
  • Additional states as applicable at the time of your residency

8.3 Exercising Your Rights

To submit a privacy request:

  • Email: privacy@getduey.com with the subject line "Privacy Rights Request"
  • Web form: getduey.com/privacy-request

We will verify your identity before processing your request by confirming the email address associated with your account and, for sensitive requests, asking for additional verification. We will respond to verifiable consumer requests within forty-five (45) days of receipt. If we require additional time (up to an additional 45 days), we will notify you of the extension and the reason.

8.4 Appeals

If we decline to take action on your privacy rights request, you may appeal our decision by emailing privacy@getduey.com with the subject line "Privacy Rights Appeal" within thirty (30) days of receiving our response. We will respond to your appeal within sixty (60) days. California residents who remain unsatisfied may contact the California Privacy Protection Agency at cppa.ca.gov.

9. Children's Privacy

The Service is not directed to individuals under the age of eighteen (18), and we do not knowingly collect personal information from children under 18. If we learn that we have inadvertently collected personal information from a child under 18 without verifiable parental consent, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from a child under 18, please contact us at privacy@getduey.com.

10. International Data Transfers

The Service is operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have data protection laws that differ from those in your country. By using the Service, you consent to the transfer of your information to the United States. We will implement appropriate safeguards for any cross-border data transfers as required by applicable law.

11. Business-to-Business Data

Much of the data we collect relates to your business rather than to you as an individual. We apply the full protections of this Privacy Policy to all data we collect, whether it primarily describes an individual or a business, out of an abundance of caution and respect for your privacy.

If you use the Service on behalf of a business and provide information about other individuals (such as adding authorized users or uploading documents that contain employee information), you represent and warrant that you have the authority to share such information with us and that such sharing complies with applicable law, including any applicable employment laws.

12. AI and Automated Decision-Making

The Service uses automated processes, including machine learning algorithms, to match your business profile to applicable compliance obligations, prioritize compliance risks, and generate recommendations. These automated processes do not make legally significant decisions about you as an individual. If you have concerns about how automated processing affects your compliance profile, you may contact us to request a human review.

Where we use data to train or improve AI models, we use aggregated or de-identified data that cannot reasonably be linked back to your individual business.

13. Third-Party Links and Integrations

The Service may contain links to third-party websites, resources, and government portals. We may also offer integrations with third-party platforms. We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party service before sharing information with them.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. If we make material changes, we will notify you by:

  • Sending an email to the address associated with your account
  • Displaying a prominent notice on the Platform before the changes take effect
  • Updating the "Effective Date" at the top of this Policy

Your continued use of the Service after the effective date of the revised Policy constitutes your acceptance of the changes. The most current version of this Privacy Policy is always available at getduey.com/privacy.

15. Contact Us

Duey Compliance, Inc.
Privacy inquiries: privacy@getduey.com
Security issues: security@getduey.com
California, United States

Last updated: April 1, 2026 · Version 1.0