Privacy Policy

Last updated: July 20, 2026. This policy explains how Compli LLC ("Compli," "MiCompli," "we," "us") handles information in connection with the MiCompli website and service (the "Service").

MiCompli is a business tool for employers, so most of what we handle is business information, not consumer data. This policy is shorter than most because we deliberately collect very little — that's the product, not a marketing line. It applies to the MiCompli website, app, and related communications. Your use of the Service is also governed by our Terms of Service.

1. Information we collect

  • Account data: your email address, a hash of your password, an optional business display name, your role (customer/distributor/advisor/admin), and your subscription state.
  • Payment data: handled by our third-party payment processor. We never see or store full card numbers; we store only your customer and subscription identifiers and your billing status.
  • Documents and records you generate: the handbook, posters, plan documents, letters, annual notices packets, calendar receipts, and time-off records you create, stored securely and versioned so they stay available and current wherever you log in. The Time-Off tool stores employee names and hours only, and the annual-notices distribution log stores the name of each recipient, the notice, and the date (see Section 2).
  • Ask MiCompli conversations: the questions you ask the AI advisor and its answers, kept as a record of what you were told and when. Use it for rule-level questions, not individual employee records.
  • Acceptance and audit records: when you accept the Terms or a distributor agreement, we record the date, the document version, and the IP address the acceptance came from, so we can show what was agreed to and when.
  • Security signals: to protect our public forms from bots we use a third-party bot-protection service, which processes limited signals (such as IP address, browser user-agent, and a challenge token) solely to tell humans from bots. It does not use tracking cookies and is not used to profile or advertise to you.
  • Operational telemetry and logs: which features your account used and when, content-library versions, and error traces with payloads stripped. Telemetry never includes your document contents or wizard answers.
  • Marketing-list email: if you ask to be notified of Michigan law changes (for example, from the exposure-check tool), we store your email address for that purpose only.
  • Distributor/partner data: if you join the partner program, we store your application, referral codes, commission and payout records, and (for referring partners) the limited attribution data described in Section 4.

2. What we deliberately do not collect

We do not collect, store, or process sensitive personal data — no Social Security numbers, no dates of birth, no salaries, no employee census, no dependents, and no health information (PHI). The only employee information the Service holds anywhere is a name, in two places: the Time-Off tool records employee names with the hours they accrue and use, and the annual-notices distribution log records the name of each person you handed a notice to, the notice, and the date. Both exist because Michigan and federal law require an employer to be able to prove those two things. Nothing more is stored about an employee in either. MiCompli is not a HIPAA-regulated platform and does not handle protected health information. You should not enter sensitive personal data into the Service, and the product is designed so you don't need to.

3. How we use information

We use the information above to:

  • provide, maintain, and secure the Service and your account;
  • generate, store, version, and export your documents and records;
  • process your subscription and payments through our payment processor;
  • send you account, billing, verification, legal, and service emails, and — if you opted in — law-change updates;
  • operate the Ask MiCompli advisor, the compliance calendar, and law-change monitoring;
  • protect the Service from bots, fraud, and abuse, and keep records of agreement acceptances;
  • run the distributor program, including calculating commissions and showing referring partners the limited data in Section 4;
  • understand and improve how the Service is used (using telemetry that excludes your document contents);
  • comply with law and enforce our Terms.

We do not use your data for third-party advertising, and we never sell or rent your data.

4. How we share information

We share information only as needed to run the Service and only with the following categories of recipients:

  • Service providers (sub-processors) that operate the Service on our behalf under agreements limiting their use of the data to providing their service to us. These include providers for payment processing and billing; application hosting and our account database (located in the United States); transactional email delivery; the artificial-intelligence service that powers Ask MiCompli — which processes your questions and inputs under commercial terms that prohibit using your content to train AI models; and bot-protection on our public forms (described in Section 1). We use reputable, established providers chosen to keep your data secure, and a current list of our sub-processors is available on request at erica@micompli.net.
  • Your referring partner, if any. If you signed up through a referring distributor, that partner sees only your business display name, subscription status, and start date — nothing else. They never see your account contents, employees, or documents.
  • Legal and safety. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Compli LLC, our users, or the public.
  • Business transfers. If Compli LLC is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy.

5. Cookies and similar technologies

We use a small number of first-party cookies that are necessary for the Service to work: a session cookie that keeps you logged in, and a short-lived referral cookie that remembers a distributor's referral code if you arrived through one. We do not use advertising or cross-site tracking cookies. Our bot-protection tool does not set tracking cookies.

6. Data security

We protect information with encryption in transit (HTTPS/TLS), password hashing, access controls, tenant isolation so each account's data is scoped to that account, and server-side handling of secrets and AI calls (our AI keys are never exposed to your browser). Our biggest safeguard is by design: because we never collect sensitive employee data, there is far less at risk. No system is perfectly secure, so keep your own exported copies of important documents.

7. Data retention and deletion

We keep account data while your account exists. You can delete your account at any time from the Account page; deletion permanently removes your account and its documents and records from our active systems and cancels your subscription (export anything you want to keep first — it cannot be undone). Some records are retained after deletion where we need them: our payment processor keeps transaction records as financial regulations require, and we keep limited records for legal, accounting, security, and audit purposes (for example, agreement-acceptance records and commission records). Marketing-list emails are kept until you unsubscribe.

8. Your choices and rights

  • Access and export: you can view and export your documents and records from within the Service at any time.
  • Correction: you can update your account details in the app, or contact us for help.
  • Deletion: you can delete your account and its data as described in Section 7.
  • Marketing emails: you can unsubscribe from law-change update emails at any time; we will still send necessary account, billing, and service messages.

Depending on where you live, you may have additional rights under applicable privacy laws (such as the right to access, correct, delete, or obtain a copy of your personal information). To exercise any right, contact us at the address in Section 11 and we will respond as required by applicable law. We will not discriminate against you for exercising a right.

9. International users and data location

The Service is operated from and hosted in the United States and is intended for U.S. employers. If you access it from outside the United States, you understand your information will be processed in the United States.

10. Children's privacy

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

11. Changes and contact

We may update this policy; if we make a material change we will update the "Last updated" date above and, where appropriate, notify you by email. Privacy questions or requests: erica@micompli.net.