Effective Date: March 21, 2026
Governing Law: State of Florida, United States
PermitArk LLC operates a SaaS platform at permitark.com for environmental compliance deadline tracking. This Privacy Policy explains how we collect, use, store, share, and protect personal information, and describes your rights. By using the Service, you agree to the practices described here.
Account information: first name, last name, email address, company name.
Facility and compliance data: facility name, address, state, industry, EPA ID, permit types, permit numbers, expiry dates, custom deadlines, completion records, confirmation numbers, and notes.
Documents: files you upload to the Service including permit applications, filed reports, and compliance certifications.
Settings: reminder preferences, manager contact, escalation settings.
Payment information: billing name and address. Card numbers are collected and stored by Stripe — PermitArk LLC never stores full payment card numbers.
Automatically collected: IP address, browser type, pages viewed, actions taken, session identifiers (in HTTP-only cookies), and application error data captured by Sentry.
To provide the Service: generating compliance calendars, sending deadline reminders, storing documents, and producing reports.
To process payments through Stripe.
To send transactional emails related to your deadlines and account.
To improve the Service using aggregated, non-identifiable usage data. We may use aggregated, anonymized compliance data (never identifying individual users or facilities) to improve regulatory deadline accuracy across the platform.
To comply with legal obligations and enforce our Terms of Service.
We do not use your personal information for advertising, marketing to third parties, or profiling.
PermitArk LLC does not sell, rent, or trade your personal information. We share data only with the following sub-processors, each bound by a data processing agreement: Supabase (database hosting and file storage), Stripe (payment processing), Resend (transactional email delivery), Sentry (error monitoring and logging), Vercel (application hosting and deployment), Cloudflare (DNS, network security, and email routing), and GitHub (source code repository and version control). All sub-processors are based in the United States.
We may disclose information if required by law or court order. We will notify you of any government data access request to the extent permitted by law.
Contract performance: processing necessary to provide the Service you signed up for. Legitimate interests: error monitoring, security, and service improvement. Legal obligation: retaining billing records as required by applicable law. You may withdraw consent at any time by updating your notification settings or contacting [email protected].
We use authentication cookies (HTTP-only, Secure, SameSite=Strict) set by Supabase to maintain your login session. These are strictly necessary for the Service to function. We also use session-only preference cookies for UI settings.
We do not use third-party advertising cookies, cross-site tracking cookies, Google Analytics, Facebook Pixel, or behavioral tracking technologies.
Do Not Track: PermitArk LLC honors Do Not Track ("DNT") browser signals. When a DNT signal is detected, we do not collect analytics or behavioral data beyond what is strictly necessary to operate the Service.
Account and compliance data: retained for the life of your subscription and for 30 days following cancellation or termination. You may export your data at any time during the 30-day window. After 30 days, data is permanently deleted and purged from backups within 90 days.
Payment records: Stripe retains payment records per PCI-DSS requirements. PermitArk LLC retains billing history (amounts, dates, plan tier) for 7 years for financial compliance.
Error and log data: retained for 90 days in Sentry and 30 days in application logs.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Supabase). Authentication tokens are stored in HTTP-only cookies — never in localStorage. Row-level security at the database level ensures users can only access their own organization's data. All API endpoints are rate-limited. File uploads are validated server-side.
In the event of a data breach likely to result in risk to your rights, we will notify affected users within 72 hours of becoming aware, as required by applicable law.
All users may: access their data through account settings or by emailing [email protected]; correct inaccurate information; export compliance data and documents at any time; delete their account and request data deletion; and opt out of non-essential communications.
California residents (CCPA/CPRA): you have rights to know, delete, correct, and opt out of data sales. PermitArk LLC does not sell personal information. To submit a request, email [email protected]. We will respond within 45 days as required by law.
EEA and UK residents (GDPR): you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data protection authority. Contact [email protected]. We will respond within 30 days.
PermitArk is operated in the United States. All data is stored on US servers. If you access the Service from outside the US, your data will be transferred to and processed in the US. For EEA/UK users, we rely on Standard Contractual Clauses or other lawful transfer mechanisms where required.
The Service is not directed to children under 18. PermitArk LLC does not knowingly collect information from children under 18. Contact [email protected] immediately if you believe we have collected information from a minor and we will delete it promptly.
PermitArk LLC will notify you by email and within the Service at least 14 days before material changes take effect. Continued use after changes constitutes acceptance.
Privacy questions and data rights requests: [email protected]
Legal notices: [email protected]
PermitArk LLC, Florida, United States · permitark.com