Compass PM
Privacy

Privacy Policy

Last updated: 5 February 2026

Compass PM ("Compass PM", "we", "our", "us") is operated by Uplift Communications Corporation. This policy explains what personal data we collect, why we collect it, who processes it, and the rights you have over it. It applies to the Compass PM web app at app.compasspm.com, the Compass PM mobile apps for iOS and Android, and any communications we send you (billing receipts, slippage alerts, Monday weekly status emails, mobile push notifications).

1. What we collect

  • Account: name, email, hashed password (bcrypt), currency preference, account type (personal / enterprise), organization ID.
  • Google Sign-In (optional): if you authenticate with Google, we receive your Google-verified email and display name only. We never read your Google Drive, Gmail, Calendar, or any other Google service.
  • Project data you enter: project plans, tasks, dependencies, estimates, actuals, baselines, risks, teammate names, portfolio and program metadata, uploaded CSVs.
  • Billing (if you subscribe): Stripe customer ID, subscription status, seat count. We never see or store your card number — Stripe tokenizes it on its own servers.
  • Mobile push token (optional): if you install the Compass PM mobile app and grant notification permission, your device's Expo Push Token (an opaque Apple/Google-issued identifier) is stored against your account solely to deliver slippage alerts.
  • Operational logs: request IDs, approximate IP, user-agent, and timestamps retained for 30 days for abuse-prevention and support.

2. How we use it

  • Operating Compass PM features (Gantt scheduling, baselines, risk scoring, exports, share links).
  • Sending transactional email: slippage alerts, Monday morning status packs, invites, billing receipts, password resets. We do not send marketing email without separate consent.
  • Delivering mobile push notifications when a project slips past its stated due date.
  • Processing payments and seat changes through Stripe.
  • Generating AI content you request — Executive Summary, Suggest Risks, Mitigation Coach — by sending the minimum necessary project context to our LLM provider (see §4).

3. Authentication & session security

Passwords are stored as bcrypt hashes — never in plaintext — and we never log them. Logged-in sessions use a signed JWT delivered as an HttpOnly, Secure, SameSite=Lax cookie so it is not accessible to third-party scripts. If you choose Google Sign-In, authentication is brokered by the Emergent Managed Google Auth integration; the OAuth handshake takes place on Google's servers and only the resulting email + name are returned to us.

4. AI / LLM processing

Our AI features (Executive Summary, Suggest Risks, Mitigation Coach) call large-language-model providers (OpenAI, Anthropic Claude, Google Gemini) through the Emergent LLM proxy. Only the specific project context required for the prompt is sent — for example, a risk description and the current risk score — and the request is routed server-to-server using Emergent-managed credentials. Provider policies prohibit training on API traffic by default. We do not share teammate PII, billing data, or passwords with any LLM provider.

5. Payments (Stripe)

All subscription payments are processed by Stripe, Inc. We rely on Stripe Checkout and the Stripe Billing Portal, which means your card number is captured directly by Stripe and never touches Compass PM servers. We store your Stripe customer ID, subscription status, price lookup key, and seat count. Stripe's own privacy policy applies to the card data and is available at stripe.com/privacy.

6. Mobile push notifications

The Compass PM mobile app uses the Expo Push service (operated by Expo, Inc.) to deliver notifications through Apple's APNs and Google's FCM. If you decline the system notification prompt, no token is ever stored and no notifications are sent. If you later want to revoke notifications, disable them in the Compass PM app's system settings on your device, or use the Delete my account flow (§9) to purge your token entirely.

7. Sub-processors

  • MongoDB Atlas — primary application database (encrypted at rest and in transit).
  • Stripe, Inc. — payment processing and billing portal.
  • Resend — transactional email delivery.
  • Expo, Inc. — mobile push dispatch to APNs / FCM.
  • Emergent LLM proxy — routes AI prompts to OpenAI / Anthropic / Google providers.
  • Google LLC — Google Sign-In (only when you choose it).

8. Data retention

We retain your project data for as long as your account is active. Operational logs are rotated after 30 days. When you delete your account (§9), all of your project, task, risk, teammate, invite, audit, branding, and push-token records are permanently removed from our live database within 24 hours. Stripe is instructed to cancel any active subscription at that time. Backups are automatically rotated and all deleted records are purged from backups within 30 days.

9. Your rights & account deletion

You can access, export, and permanently delete your account at any time from Settings → Danger Zone → Delete my account inside the app. You can also email privacy@upliftc.com and we will complete the deletion within 7 days. Residents of the EU, UK, California, Virginia, and other jurisdictions with similar laws have the right to request access, correction, portability, or deletion of their personal data; those requests are honoured without discrimination.

10. Children

Compass PM is a business tool and is not directed to anyone under 13. We do not knowingly collect data from children.

11. Changes

We will update the date at the top of this page whenever we make a material change and, if you are a paying customer, email you a summary at least 7 days before the change takes effect.

12. Contact

Uplift Communications Corporation — privacy@upliftc.com. For EU residents, data-protection enquiries can be sent to the same address.

© 2026 Uplift Communications Corporation · Compass PM · Home