Privacy Policy

Last updated: December 13, 2025

1. Introduction

ERC Enterprises, LLC ("Company," "we," "us," or "our") operates The Notary Guide application, browser extension, website, and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and handling your data with transparency and care. Please read this Privacy Policy carefully. By using the Service, you consent to the data practices described in this policy.


2. Our Commitment: We Will NEVER Sell Your Data

ERC Enterprises, LLC makes the following unequivocal commitment:

WE WILL NEVER SELL, RENT, LEASE, OR OTHERWISE COMMERCIALLY TRANSFER YOUR PERSONAL DATA TO THIRD PARTIES FOR THEIR MARKETING OR ADVERTISING PURPOSES.

This commitment is absolute and without exception. Your trust is fundamental to our business, and we will never monetize your personal information through data sales.


3. Information We Collect

3.1 Information You Provide Directly

When you create an account or use the Service, you may provide:

Data Type Purpose Required
Email Address Account creation, authentication, communication Yes
Password Account security (stored as secure hash only) Yes (if using email/password)
Full Name Account personalization Optional
Commissioned State(s) Provide state-specific compliance information Yes
Commission Expiration Date Commission tracking and renewal reminders Optional
Subscription Selection Service tier and billing For paid tiers

3.2 Information Collected Automatically

When you use the Service, we automatically collect:

Device and Technical Information:

  • Device identifier (anonymous UUID generated locally)
  • Browser type and version
  • Operating system
  • Extension version
  • General location (country/region level only, not precise location)

Usage Information:

  • Features and guides accessed
  • Session duration and frequency
  • Navigation patterns within the Service
  • Error logs and crash reports
  • Performance metrics

Session Information:

  • Session identifier (anonymous UUID)
  • Timestamps of activity
  • Authentication status

3.3 Information We Do NOT Collect

We want to be explicitly clear about what we do NOT collect or have access to:

Data Type Collected? Explanation
Documents you notarize NO We never see, access, or store any documents
Signer information NO We have no access to names, addresses, or IDs of people you notarize for
Transaction details NO We do not record what notarial acts you perform
Precise geolocation NO We do not track GPS coordinates or precise location
Contacts or address books NO We do not access your device contacts
Browsing history NO We do not track websites you visit outside our Service
Financial account details NO Payment processing is handled entirely by Stripe
Credit card numbers NO We never see or store your payment card information
Social Security numbers NO We do not collect government ID numbers
Notary journal entries NO Your official notary records remain private
Commission certificate data NO We do not access your actual commission documents
Biometric data NO We do not collect fingerprints, facial recognition, or similar data

4. How We Use Your Information

We use the information we collect for the following purposes:

4.1 Service Provision

  • Authenticate your account and manage your subscription
  • Provide state-specific notary compliance information
  • Deliver personalized guidance based on your commissioned state(s)
  • Process subscription payments and manage billing

4.2 Service Improvement

  • Analyze usage patterns to improve features
  • Identify and fix bugs and technical issues
  • Develop new features based on user needs
  • Optimize performance and user experience

4.3 Communication

  • Send service-related announcements and updates
  • Respond to your inquiries and support requests
  • Send subscription renewal reminders (if applicable)
  • Notify you of material changes to our Terms or Privacy Policy

4.4 Security and Compliance

  • Detect and prevent fraud, abuse, and unauthorized access
  • Comply with legal obligations
  • Enforce our Terms of Service

5. Third-Party Service Providers

We work with carefully selected third-party service providers to operate the Service. Each provider has been chosen for their strong privacy and security practices.

5.1 Supabase (Authentication & Database)

Purpose: User authentication, account management, and data storage

Data Shared:

  • Email address
  • Authentication tokens
  • Account preferences
  • Commissioned state(s)
  • Subscription status

Their Privacy Policy: https://supabase.com/privacy

Data Location: United States (AWS infrastructure)

Security: SOC 2 Type II certified, AES-256 encryption at rest, TLS 1.3 in transit


5.2 Stripe (Payment Processing)

Purpose: Subscription billing and payment processing

Data Shared:

  • Email address
  • Subscription plan selection
  • Billing address (if provided)

Data Stripe Collects Directly (not through us):

  • Payment card information
  • Bank account information
  • Billing details

IMPORTANT: We never see, receive, or store your payment card numbers. All payment information is collected and processed directly by Stripe.

Their Privacy Policy: https://stripe.com/privacy

PCI Compliance: Stripe is a PCI Level 1 Service Provider


5.3 Cloudflare (Hosting & Security)

Purpose: Website and API hosting, content delivery, DDoS protection

Data Shared:

  • IP address (for routing and security)
  • Request metadata
  • Performance metrics

Their Privacy Policy: https://www.cloudflare.com/privacypolicy/

Data Location: Global edge network with data processed in region closest to user


5.4 Axiom (Analytics & Logging)

Purpose: Application monitoring, error tracking, and anonymous usage analytics

Data Shared:

  • Anonymous device identifier
  • Anonymous session identifier
  • Feature usage events (anonymized)
  • Error logs and stack traces
  • Performance metrics

Their Privacy Policy: https://axiom.co/privacy

Data Retention: 30 days for log data

Note: All data sent to Axiom is anonymized and cannot be used to identify individual users.


5.5 Google (OAuth Authentication)

Purpose: Optional single sign-on authentication

Data Shared (only if you choose Google Sign-In):

  • Email address
  • Basic profile information (name, profile picture URL)

Their Privacy Policy: https://policies.google.com/privacy

Note: Google Sign-In is entirely optional. You can use email/password or magic link authentication instead.


5.6 Third-Party Data Sharing Summary

Provider Data Shared Purpose Do They Receive PII?
Supabase Email, preferences, state Auth, storage Yes (email only)
Stripe Email, plan selection Payments Yes (email only)
Cloudflare IP address, requests Hosting, security Minimal
Axiom Anonymous usage data Analytics No
Google Email (if using OAuth) Authentication Yes (if opted in)

6. Data Retention

We retain your information only as long as necessary for the purposes described in this policy:

Data Type Retention Period
Account information Until account deletion or 2 years after last activity
Usage analytics 30 days (anonymized)
Error logs 30 days
Subscription records 7 years (for tax/legal compliance)
Support communications 3 years

After account deletion:

  • Personal data is deleted within 30 days
  • Anonymized analytics may be retained indefinitely
  • Backup copies are purged within 90 days

7. Data Security

We implement industry-standard security measures to protect your information:

7.1 Technical Safeguards

  • Encryption in Transit: All data transmitted using TLS 1.3
  • Encryption at Rest: AES-256 encryption for stored data
  • Password Security: Passwords are hashed using bcrypt (never stored in plain text)
  • Access Controls: Role-based access with principle of least privilege
  • Infrastructure Security: Hosted on SOC 2 certified infrastructure

7.2 Organizational Safeguards

  • Limited employee access to personal data
  • Regular security training
  • Incident response procedures
  • Regular security audits and vulnerability assessments

7.3 Browser Extension Security

  • Manifest V3 compliance (Chrome's most secure extension architecture)
  • Minimal permissions requested
  • No access to browsing history or other websites
  • Local storage encrypted
  • Zero third-party tracking scripts

8. Your Privacy Rights

Depending on your location, you may have the following rights:

8.1 Access and Portability

  • Request a copy of your personal data
  • Receive your data in a portable, machine-readable format

8.2 Correction

  • Request correction of inaccurate personal data
  • Update your account information at any time

8.3 Deletion

  • Request deletion of your personal data
  • Delete your account through settings or by contacting us

8.4 Restriction and Objection

  • Request restriction of processing in certain circumstances
  • Object to processing for direct marketing (we don't do this anyway)

8.5 Withdraw Consent

  • Withdraw consent at any time where processing is based on consent
  • This does not affect the lawfulness of prior processing

8.6 Exercising Your Rights

To exercise any of these rights, contact us at:

We will not discriminate against you for exercising your privacy rights.


9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

9.1 Right to Know

You have the right to request disclosure of:

  • Categories of personal information collected
  • Sources of personal information
  • Business purpose for collection
  • Categories of third parties with whom we share data
  • Specific pieces of personal information collected

9.2 Right to Delete

You have the right to request deletion of personal information, subject to certain exceptions.

9.3 Right to Opt-Out of Sale

We do not sell personal information. Therefore, there is no need to opt out, but we honor this right regardless.

9.4 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights.

9.5 Authorized Agent

You may designate an authorized agent to make requests on your behalf.

9.6 Categories of Information (CCPA Disclosure)

Category Collected Sold Business Purpose
Identifiers (email, name) Yes Never Account management
Commercial Information Yes (subscription) Never Billing
Internet Activity Yes (usage data) Never Service improvement
Geolocation No (only country) Never N/A
Professional Information Yes (commission state) Never Service delivery

10. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

10.1 Legal Basis for Processing

We process your data under the following legal bases:

Purpose Legal Basis
Account creation and service delivery Contract performance
Billing and payments Contract performance
Service improvement and analytics Legitimate interests
Security and fraud prevention Legitimate interests
Marketing communications Consent (opt-in)
Legal compliance Legal obligation

10.2 Data Transfers

Your data may be transferred to the United States where our service providers are located. We ensure appropriate safeguards through:

  • Standard Contractual Clauses (SCCs)
  • Service providers with adequate privacy frameworks

10.3 Data Protection Officer

For GDPR-related inquiries, contact our Data Protection point of contact:

10.4 Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority.


11. Cookies and Local Storage

11.1 What We Use

The Service uses minimal cookies and local storage:

Type Purpose Duration
Authentication token Keep you signed in Session/30 days
Session ID Anonymous analytics Session
Device ID Anonymous device recognition Persistent
User preferences Remember your settings Persistent
Cached compliance data Offline functionality 24 hours

11.2 What We Don't Use

  • Third-party advertising cookies
  • Cross-site tracking cookies
  • Social media tracking pixels
  • Fingerprinting technologies

11.3 Managing Cookies

You can clear local storage and cookies through your browser settings. Note that this will sign you out and reset preferences.


12. Children's Privacy

The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately at privacy@notaryguide.app, and we will promptly delete such information.


13. Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature. We currently do not respond to DNT signals because there is no industry standard for handling them. However, we do not engage in cross-site tracking regardless of DNT settings.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on the Service
  • Updating the "Last Updated" date at the top
  • Sending an email notification (for material changes)

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.


15. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users within 72 hours of discovery
  • Provide details about what information was affected
  • Describe steps we are taking to address the breach
  • Offer guidance on protective measures you can take
  • Report to relevant authorities as required by law

16. International Users

The Service is operated from the United States. If you access the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.

By using the Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.


17. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ERC Enterprises, LLC

General Inquiries:

Data Protection Requests:

Mailing Address: ERC Enterprises, LLC Attn: Privacy 1309 Coffeen Avenue STE 12701 Sheridan, WY 82801

Response Time: We aim to respond to all privacy-related inquiries within 30 days.


18. Summary of Key Points

For your convenience, here are the key points of our Privacy Policy:

Topic Summary
Data Sales We NEVER sell your data
Documents We never access your notarized documents
Payment Info Handled entirely by Stripe - we never see card numbers
Third Parties Supabase, Stripe, Cloudflare, Axiom, Google (OAuth optional)
Analytics Anonymous usage data only
Retention Deleted within 30 days of account deletion
Security Industry-standard encryption and security measures
Your Rights Access, correct, delete, or export your data anytime
Children Service not intended for users under 18
Changes We'll notify you of material policy changes

© 2025 ERC Enterprises, LLC. All Rights Reserved.