Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your information.
1. Introduction & Data Controller
This Privacy Policy explains how OpenCompany (“we,” “us,” or “OpenCompany”) collects, uses, shares, and protects personal information when you use our website, formation wizard, and client portal. OpenCompany acts as the Data Controller for the personal information described below.
We are committed to complying with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), regardless of where you are located. If you have any questions about this policy or how your data is handled, contact our privacy team at privacy@opencompany.com.
2. Information We Collect
a) Information you provide directly:
- Account information: name, email address, phone number, and country.
- Formation information: business name, registered and mailing addresses, member/shareholder details, and ownership structure.
- Payment information: processed directly by Stripe — we do not store your full card details.
- Documents: passport copies, ITIN documentation, and other business documents you upload.
b) Information collected automatically:
- IP address, browser type, and device information.
- Pages visited, time spent, and click activity via analytics tools.
- Cookies and similar tracking technologies (see Section 9).
c) Information from third parties:
- Stripe: payment status and transaction identifiers.
- Google (if you sign in with Google): your name, email address, and profile photo.
We track how you use our own Services, but we do not track you across third-party websites, and we do not currently process or respond to browser “Do Not Track” signals.
3. How We Use Your Information
- Process your LLC or corporation formation order.
- Communicate order status updates and respond to support requests.
- Send compliance reminders, such as annual report deadlines.
- Improve and develop our Services.
- Detect, investigate, and prevent fraud and security incidents.
- Comply with our legal and regulatory obligations.
- Send marketing communications — only where you have given consent, and always with an easy way to opt out. Opting out of marketing does not opt you out of non-promotional messages we need to send you, such as order confirmations, security alerts, and other transactional or account-related communications.
4. Legal Basis for Processing (GDPR)
- Contract performance: processing needed to deliver your formation order and related services.
- Legitimate interests: fraud prevention, platform security, and service improvement.
- Legal obligation: retaining tax records and complying with anti-money-laundering (AML) rules.
- Consent: marketing emails, which you can withdraw at any time.
5. Data Sharing
We do not sell your personal information. We share it only with the following categories of recipients, and only as needed to deliver the Services:
- Stripe — to process payments.
- Resend — to deliver transactional and account emails.
- Supabase — our database host (US region).
- Secretary of State offices — when filing your formation documents.
- The IRS — when applying for your EIN.
- Registered agent partners — to provide registered agent service in your formation state.
- Law enforcement — only when required by a valid court order or legal process.
Nothing in this Policy restricts our ability to share information that has been aggregated or de-identified such that it can no longer reasonably be used to identify you.
6. Data Storage & Security
Your data is stored with Supabase in a US region. We encrypt data at rest and in transit (TLS 1.3), and we enforce role-based access control on a least-privilege basis, meaning staff can only access the data necessary for their role.
We perform regular security reviews of our infrastructure. In the event of a data breach affecting your personal information, we will notify affected users and relevant supervisory authorities within 72 hours, as required under GDPR.
No security measure is perfect, and no method of transmission over the internet is 100% secure. Keeping your account password confidential is part of protecting your own information — you are responsible for activity under your account, and should notify us immediately at privacy@opencompany.com if you believe your credentials have been compromised.
7. Data Retention
- Account data: retained while your account is active, plus 3 years after closure.
- Formation documents: retained for 7 years to meet tax compliance requirements.
- Payment records: retained for 7 years under financial recordkeeping regulations.
- Deleted accounts: personal data is anonymized within 90 days of deletion.
8. Your Rights (GDPR + CCPA)
Depending on where you live, you have the right to:
- Access — request a copy of all personal information we hold about you.
- Rectification — ask us to correct inaccurate information.
- Erasure (“right to be forgotten”) — ask us to delete your account and data, subject to records we are legally required to keep.
- Portability — receive your data in a machine-readable format.
- Object — object to our processing your data for marketing purposes.
- Restrict processing — ask us to limit how we use your data.
To exercise any of these rights, email privacy@opencompany.com. We respond to all requests within 30 days, as required under GDPR.
10. International Transfers
Because our infrastructure and the entities we help you form are located in the United States, your data may be transferred outside your home country. For users in the European Union, transfers are protected by Standard Contractual Clauses (SCCs). For users in Vietnam, our processing practices are designed to comply with Vietnam's Cybersecurity Law and Personal Data Protection Decree.
11. Children's Privacy
The Services are not directed at, and we do not knowingly collect personal information from, anyone under 18 years old. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly.
12. Third-Party Links
Our Services may link to third-party websites and services, such as Stripe, Mercury, or the IRS. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies before providing them with any information.
13. Changes to This Privacy Policy
We may update this Privacy Policy as our Services or legal obligations change. We will notify you by email of any material changes. Your continued use of the Services after a change takes effect constitutes acceptance of the updated policy.
14. Contact & DPO
For privacy-related inquiries, contact privacy@opencompany.com. We aim to respond within 30 days. If you are located in the EU, you also have the right to lodge a complaint with your local data protection supervisory authority.