Privacy Policy
Effective Date: June 6, 2026 · Last Updated: June 6, 2026
Welcome to Sterling Safeguard, a compliance management platform owned and operated by Sterling Safeguard LLC ("Sterling Safeguard," "we," "our," or "us").
We value your privacy and are committed to protecting the confidentiality, integrity, and security of the information entrusted to us. This Privacy Policy explains how we collect, use, disclose, store, and safeguard information when you access or use the Sterling Safeguard platform, website, mobile applications, and related services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understand this Privacy Policy.
1. Scope of this Privacy Policy
This Privacy Policy applies to:
- The Sterling Safeguard website
- The Sterling Safeguard web application
- Customer accounts
- Mobile applications (if applicable)
- Customer support interactions
- Marketing communications
- Training modules
- Documentation portals
- All related online services operated by Sterling Safeguard LLC
This Privacy Policy does not replace any separate data processing, security, or vendor agreement executed between Sterling Safeguard LLC and a customer, where applicable.
2. Information We Collect
Depending on how you interact with the Service, we may collect the following categories of information.
A. Account Information
When you create an account, we may collect:
- Name
- Organization name
- Job title
- Business email address
- Telephone number
- Billing address
- Usernames
- Encrypted passwords
- Multi-factor authentication settings
- Subscription information
B. Compliance Information
Customers may upload or create information including:
- Risk assessments
- Policies
- Procedures
- Evidence documents
- Compliance reports
- Audit documentation
- Written Information Security Program (WISP) documents
- Vendor records
- Security questionnaires
- Employee training records
- Incident reports
- Compliance scores
- Action plans
C. Customer Financial and Personal Information (NPI)
Depending on how customers use the Service, Sterling Safeguard may receive, maintain, or process Non-Public Personal Information ("NPI") as defined under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 C.F.R. Part 314).
Customers are encouraged to upload only the minimum amount of NPI necessary for legitimate compliance purposes.
Sterling Safeguard LLC implements safeguards designed to align with the FTC Safeguards Rule in its handling of NPI processed through the Service.
D. Payment Information
Subscription payments are processed through Stripe, a secure third-party payment processor. Sterling Safeguard LLC does not store complete payment card numbers on its own systems. Stripe maintains its own privacy and security policies.
E. Device and Technical Information
We may automatically collect:
- Browser type
- Operating system
- Device identifiers
- IP address
- Geographic region (approximate)
- Time zone
- Log files
- Session information
- Crash reports
- Error logs
- Performance metrics
F. Usage Information
We collect information about how users interact with the Service, including:
- Login history
- Feature usage
- Dashboard activity
- Compliance progress
- Training completion
- AI interactions
- Search history within the Service
- File uploads
- Administrative actions
- Security events
3. How We Use Information
We use information to:
- Provide the Service
- Authenticate users
- Deliver compliance tools
- Generate AI-assisted documents and recommendations
- Calculate compliance scores
- Monitor system performance
- Improve product features
- Provide customer support
- Process payments
- Detect fraud
- Maintain security
- Comply with legal obligations
- Respond to customer requests
- Send product updates
- Conduct analytics
- Improve user experience
We do not sell personal information to third parties.
4. AI Features
Certain features of the Service use artificial intelligence, powered in part by Anthropic's Claude API, to assist customers in generating policies, reports, recommendations, summaries, risk assessments, and other compliance-related content. AI-generated content is intended to support — not replace — professional judgment. Customers remain responsible for reviewing, approving, implementing, and maintaining all AI-generated content before relying upon it.
5. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Maintain user sessions
- Authenticate users
- Remember preferences
- Improve website performance
- Analyze website traffic
- Enhance security
- Measure product usage
Users may control cookies through browser settings; however, disabling certain cookies may affect functionality.
6. How We Share Information
We may share information with:
Service Providers
Including providers such as:
- Vercel (application hosting and infrastructure)
- Supabase (database and authentication infrastructure)
- Stripe (payment processing)
- Resend (email delivery)
- Anthropic (artificial intelligence features, via the Claude API)
- Additional providers of data backup, analytics, and security monitoring services
This list reflects our current service providers and may change as our technology stack evolves. Each provider is contractually required to safeguard information appropriately.
Legal Requirements
We may disclose information when required by law or when we reasonably believe disclosure is necessary to:
- Comply with legal obligations
- Respond to subpoenas
- Protect rights
- Prevent fraud
- Investigate security incidents
- Protect public safety
Business Transactions
If Sterling Safeguard LLC undergoes a merger, acquisition, investment, financing, asset sale, or corporate restructuring, customer information may be transferred as part of that transaction, subject to applicable legal obligations.
7. Data Security
Sterling Safeguard LLC implements commercially reasonable administrative, technical, and physical safeguards designed to protect customer information. Security measures may include:
- Encryption in transit using TLS
- Encryption of stored data where appropriate
- Role-based access controls
- Multi-factor authentication
- Audit logging
- Security monitoring
- Regular backups
- Vulnerability management
- Secure software development practices
- Employee security training
No online system can guarantee absolute security.
8. Data Retention
We retain information only for as long as necessary to:
- Provide the Service
- Meet contractual obligations
- Comply with applicable laws
- Resolve disputes
- Enforce agreements
Customers may request deletion of information, subject to legal, contractual, and regulatory retention requirements.
9. Customer Responsibilities
Customers are responsible for:
- Maintaining accurate account information
- Protecting login credentials
- Managing user access
- Uploading only authorized information
- Maintaining appropriate backups
- Reviewing AI-generated content
- Complying with the FTC Safeguards Rule and other applicable laws
10. Your Privacy Rights
Depending on your jurisdiction, you may have rights to:
- Access personal information
- Correct inaccurate information
- Request deletion
- Request data portability
- Object to certain processing
- Withdraw consent where applicable
- Lodge a complaint with a supervisory authority
We will respond to applicable requests in accordance with law.
California and Other State Privacy Rights. Residents of California may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. Sterling Safeguard LLC does not sell or share personal information as defined under the CCPA/CPRA. Residents of other states with comprehensive privacy laws may have similar rights under applicable state law. To exercise any of these rights, contact us using the information in Section 16 below.
11. Children's Privacy
The Service is intended for business use and is not directed to children under the age of 13. We do not knowingly collect personal information from children.
12. International Users
The Service is intended primarily for organizations located in the United States. Information collected through the Service is generally processed and stored in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Customers outside the United States are responsible for ensuring that their use of the Service complies with applicable local laws.
13. Third-Party Links
The Service may contain links to third-party websites or services. Sterling Safeguard LLC is not responsible for the privacy practices or content of third-party sites.
14. FTC Safeguards Rule Compliance
Sterling Safeguard LLC implements safeguards designed to align with the FTC Safeguards Rule (16 C.F.R. Part 314) in its handling of customer information. Nothing in this Privacy Policy limits a customer’s independent obligation to maintain its own Information Security Program as required under the FTC Safeguards Rule.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or the Service. Material changes will be communicated through the Service or by other appropriate means. The "Last Updated" date at the top of this Policy indicates when the most recent changes were made. Continued use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the revised Policy, except where applicable law requires additional notice or consent.
16. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact:
Sterling Safeguard LLC
Attn: Privacy Officer
Charlotte, North Carolina, USA
Email: support@sterlingsafeguard.com