Draft for review. This document is a working draft prepared for review by the company's counsel before launch. State privacy laws (including California, Virginia, Colorado, and others) may impose additional requirements; a licensed attorney should review and finalize this policy. Bracketed items must be completed.
Effective date: ____________ · Last updated: ____________
1. Overview
This Privacy Policy explains how POA Lock Inc. ("POALock," "we," "us") collects, uses, and protects information when you use the POALock registry and verification service (the "Service"). By using the Service, you agree to this Policy. It should be read together with our Terms of Service.
2. Information we collect
Information you provide
- Registration details — information about an instrument you register, such as the principal's and agent's names, the type of instrument, the governing state, the execution date, notary and witness information, and the status you declare.
- Documents and media — where you choose to upload them, a copy of the executed instrument, a capacity-confirmation video, a competency certificate, or proof-of-death materials. These are encrypted at rest (see Security).
- Contact information — an email or phone number you provide for receipts, alerts, watch subscriptions, reset requests, or death reports.
- Death-report information — if you report a principal's death, the name, relationship, and contact information you provide, and any supporting materials you attach.
- Identity-verification information — where you request a management-key reset, information and identification you submit for that review.
Information collected automatically
- Payment information — payments are processed by our payment processor (Stripe). We do not receive or store full card numbers; we receive limited transaction details (such as confirmation, amount, and the last four digits) from the processor.
- Usage and device data — standard server logs such as IP address, browser type, pages accessed, and timestamps, used for security, diagnostics, and to operate the Service.
Note on credentials: we do not store your management key. Only a one-way cryptographic hash is retained, which cannot be reversed to recover the key.
3. How we use information
- To operate the registry: create and maintain registrations, issue verification codes, and record declared status changes.
- To answer verification and status checks from parties you share a code with.
- To process payments and send receipts.
- To deliver alerts and watch notifications you or a relying party request, and to communicate about your registration (for example, reset or death-report notices).
- To secure the Service, prevent abuse and fraud, and enforce our Terms.
- To comply with law and respond to lawful requests.
4. What a verification (status check) reveals
The Service is designed so that a person you give a verification code to can check the instrument's declared status. Depending on the registration, a status check may disclose non-sensitive details you registered (such as the parties' names, instrument type, state, and execution date) so a relying party can match them against the document in front of them. A status check does not disclose your management key, and it does not release the underlying document unless you separately authorize retrieval. Consider this before registering sensitive details, and share verification codes only with parties you intend to have check the status.
5. How we share information
We do not sell your personal information. We share information only as follows:
- Service providers — processors who help us operate the Service under confidentiality obligations, such as payment processing (Stripe), email delivery, and hosting.
- People you authorize — parties to whom you give a verification code or a one-time retrieval password, consistent with the feature you use.
- Legal & safety — when required by law, subpoena, or legal process, or to protect the rights, safety, or property of POALock, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
6. How we protect information
We use technical and organizational safeguards designed to protect information, including: encryption of uploaded documents and media at rest (AES-256); storing management keys only as one-way hashes; encryption in transit (HTTPS); and access controls on administrative functions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your management key and verification code.
7. Data retention
We retain registration records and associated information for as long as the registration is maintained and as needed to operate the Service, resolve disputes, and comply with legal obligations. Because a power of attorney and its verifiable status may need to be confirmed years after execution, registration records are generally retained on a long-term basis. [Specify retention periods and deletion practices after review by counsel.] Where you close or delete a registration, we may retain limited records as required for legal, security, or accounting purposes.
8. Your choices & rights
- Access & correction — the party holding a registration's management key can view and update it; contact us for other requests.
- Alerts — you can decline or unsubscribe from optional alert emails.
- State privacy rights — depending on where you live, you may have rights to access, correct, delete, or restrict certain personal information, and to appeal a decision. [Insert jurisdiction-specific rights and the request/verification process — e.g., California CPRA, Virginia, Colorado — after review by counsel.] To make a request, contact us using the details below.
9. Cookies & local storage
The Service uses browser storage and similar technologies for essential functionality (such as keeping you signed in during a session and remembering non-sensitive preferences). [If analytics or non-essential cookies are added, disclose them and any opt-out here after review by counsel.]
10. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. Material changes take effect when we post the updated Policy and update the "Last updated" date, or as otherwise required by law. Your continued use after changes take effect means you accept the updated Policy.
Questions or privacy requests: support@poalock.com · (212) 608-1660 · POA Lock Inc.