Privacy Policy
This policy explains what data Compass collects, why, and what you can do about it. Compass is operated by Compass Studio (referred to as “we,” “us,” or “Compass” below). The product runs at getcompass.studio.
1. What we collect
When you sign up and use Compass, we collect:
- Account details: your name, email address, password (hashed, never readable to us), and optionally an avatar image.
- Workspace content: leads, contacts, notes, pricing inputs, calendar entries, and other information you choose to enter.
- Webhook data: any lead enquiry payload your website or third-party tools (Zapier, Meta Lead Ads) send to your webhook endpoint.
- Usage signals: anonymous pageview counts and Core Web Vitals via Vercel Analytics. No cross-site tracking, no advertising cookies.
- Session cookies: required to keep you signed in. Set by our auth provider (Supabase) and read only by Compass.
2. How we use it
- To run the service you signed up for.
- To send transactional email (signup confirmation, password reset, results emails you trigger).
- To debug errors, monitor uptime, and improve performance.
- To bill you, if you're on a paid plan (handled by Stripe; we never see your full card number).
We do not sell your data. We do not share it with advertisers. We do not train AI models on your workspace content.
3. Where it's stored
Your workspace data lives in a managed Postgres database on Supabase (Singapore region). Email is sent through Brevo. Hosting and edge delivery is on Vercel. Each provider has its own privacy practices; links to their policies are at the bottom of this page.
Workspaces are isolated by row-level security: every query is scoped to your user ID at the database layer, so other Compass users cannot read your data even if our application code had a bug.
4. Third-party services we rely on
- Supabase: database, authentication, and file storage. Privacy.
- Vercel: hosting, edge delivery, and anonymous analytics. Privacy.
- Brevo: transactional email delivery. Privacy.
- Stripe (paid plans): payment processing. Privacy.
- Google (only if you connect a calendar): calendar availability and booking entries. See section 5 below for exactly what we access and why. Privacy.
5. Google Calendar, and how we handle Google user data
Connecting a Google calendar is optional. Nothing here applies unless you choose to connect one, and you can disconnect at any time. When you do connect, Google asks you to approve a specific set of permissions. Here is plainly what Compass does with them.
What we access
- The names of your calendars, so you can choose which ones Compass should pay attention to.
- Busy and free times on the calendars you picked, so your booking page only offers times you are genuinely free.
- The entries Compass itself creates and updates: the bookings your clients make, and the Compass calendars set up to hold them. Compass can only change entries and calendars it created.
- The email address of the Google account you connected, so the app can show you which account is linked.
We do not read the contents of your personal calendar entries. For your own calendars, Compass looks only at when you are busy, never at what you are doing, who you are with, or where.
Why we use it
Three reasons, and only these three: to show accurate availability on your booking pages, to create and keep in step the bookings your clients make, and to label which Google account is connected.
What we never do with it
- We do not sell it, and we never will.
- We do not pass it to anyone else, beyond the hosting and database providers listed above that are needed to run the feature you asked for.
- We do not use it for advertising, ad targeting, or building any profile of you.
- We do not use it to train AI models, ours or anyone else's.
- No human at Compass reads it. It is used by the software to answer the questions above and nothing more.
How it is stored
The permission you grant is held as a token in our database (Supabase, Singapore region), on the server only. It is never sent to your browser, and it is scoped to your workspace, so no other Compass user can reach your calendar. Busy and free times are read when they are needed and used to work out the answer; we do not keep a copy of your calendar.
How to disconnect
Go to Settings, then Calendars, and choose Disconnect. That deletes the stored permission from our database, so Compass can no longer reach your calendar at all. You can also remove Compass yourself from your Google Account permissions page. Bookings Compass already put in your calendar stay there, because they are yours; you can delete any of them the normal way.
Limited Use
Compass's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Your rights
You can, at any time:
- Accessyour data, by exporting it from Settings → Account.
- Correct inaccurate information by editing it in the app.
- Deleteyour account and all associated workspace data from Settings → Account. Deletion is permanent and cannot be reversed.
- Object to specific processing orport your data elsewhere by emailing hello@getcompass.studio.
If you're in the EU/UK we treat these as your GDPR rights; in California, CCPA; in Australia, the Australian Privacy Principles. Whichever jurisdiction protects you most strongly is the one that applies.
7. Retention
We keep your data while your account is active and for up to 30 days after deletion (so you can recover if you change your mind). After that the data is purged from production. Backups follow the same lifecycle, with one additional grace window of up to 30 days.
8. Security
All traffic is HTTPS-only with HSTS preload. Auth credentials are stored as salted hashes by Supabase. The service role key (which would bypass row-level security) is held server-side only and never sent to browsers. Workspaces are isolated at the database layer, not in application code.
9. Children
Compass is for people running businesses. We don't knowingly collect data from anyone under 16; if you believe a minor has signed up, email us and we'll delete the account.
10. Changes to this policy
If we make material changes we'll email signed-in users at least 14 days before they take effect. Minor wording changes (typos, clearer phrasing) happen without notice. The “Last updated” date at the top of this page is the source of truth.
11. Contact
Privacy questions or requests: hello@getcompass.studio.
This document is plain-English on purpose. Where there's ambiguity, the Terms of Service and applicable law govern.