Privacy Policy
Last updated: July 2, 2025
This Privacy Policy explains what data Ordrly collects, how we use it, and the choices you have regarding your information.
Information We Collect
Account Information
- Email address and name (when you create an account or sign in with Google)
- Password (encrypted) or OAuth authentication tokens
- Subscription tier and billing information
- Account preferences and settings
Research and Chat Data
- Municipal research queries and questions
- Jurisdiction and location information for research context
- Chat conversations and AI responses (if enabled in your privacy settings)
- Research history and session data (if enabled in your privacy settings)
Usage and Analytics Data
- Device information, browser type, and IP address
- Pages visited, time spent, and user interactions
- Search patterns and feature usage analytics
- Error logs and performance metrics
Use & Processing
How We Use Your Information
We use the information we collect to provide and improve our services:
- Provide municipal ordinance research and compliance information
- Power our AI chat interface to answer your municipal research questions
- Process payments and manage your subscription
- Save your chat history and research sessions (with your permission)
- Improve our service accuracy and user experience
- Send important service updates and notifications
- Provide customer support and respond to your inquiries
- Detect and prevent fraud or abuse
Third-Party Services and Information Sharing
We work with trusted third-party services to provide our platform. We do not sell your personal information to anyone.
Service Providers We Use
- Supabase: Database hosting, user authentication, and data storage
- Stripe: Payment processing and subscription management
- OpenAI: AI-powered ordinance analysis and chat assistance
- Google Services: OAuth authentication, analytics, and search APIs
- Vercel: Website hosting and content delivery
When We Share Information
- With service providers who help us operate our platform (under strict data protection agreements)
- When required by law or to protect our rights and safety
- In connection with a business transfer (with your consent)
- With your explicit consent for specific purposes
Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption in transit (HTTPS/TLS) and at rest for sensitive data
- Secure authentication with password hashing and OAuth integration
- Regular security audits and vulnerability assessments
- Access controls and monitoring for our systems
- Secure third-party providers with SOC 2 compliance
- Regular backups and disaster recovery procedures
While we strive to protect your information, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and keep your account information confidential.
Your Rights and Choices
You have control over your personal information and how we use it:
Privacy Controls
- Control whether we save your search history and chat conversations
- Set data retention periods and enable auto-deletion
- Manage email preferences and notifications
- Access these settings in your account dashboard
Data Rights
- Access: Request a copy of your personal data
- Export: Download your search history and chat data
- Delete: Remove specific searches, chats, or your entire account
- Correct: Update inaccurate information in your profile
- Portability: Transfer your data to another service
Data Retention
We retain your information for different periods based on the type of data and your preferences:
- Account Information: Retained while your account is active, deleted within 30 days of account closure
- Search History: Retained based on your privacy settings (30 days to 2 years, or until manually deleted)
- Chat Conversations: Retained based on your privacy settings (30 days to 2 years, or until manually deleted)
- Payment Information: Billing records retained for 7 years for tax and legal compliance
- Analytics Data: Aggregated and anonymized data retained for up to 2 years
- Support Communications: Retained for 3 years to improve our service
You can configure auto-deletion settings in your account to automatically remove old data based on your preferences.
Cookies and Analytics
Essential Cookies
We use essential cookies to make our website work properly:
- Authentication and session management
- Security and fraud prevention
- User preferences and settings
Analytics
We use Google Analytics to understand how our website is used:
- Page views, user interactions, and website performance
- Aggregated usage patterns to improve our service
- No personally identifiable information is shared with Google
You can control cookies through your browser settings or opt out of Google Analytics using theiropt-out tool.
Children's Privacy
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete such information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification. We encourage you to review this policy periodically to stay informed about how we protect your information.
Contact Us
If you have any questions about this Privacy Policy, want to exercise your data rights, or need help with your privacy settings, please don't hesitate to contact us:
Support Team
Email: hello@ordrly.ai
For general support: Contact Support
We'll respond to your request within 30 days.