Legal
Privacy Policy
How Audit Machine collects, uses, and protects your information.
Who We Are
Audit Machine (“Company,” “we,” “us,” or “our”) operates the Service.
Mailing address:
5830 E 2nd St, Ste 7000 #38290
Casper, WY 82609, USA
Privacy contact: privacy@auditmachine.io
Support: support@auditmachine.io
Legal: legal@auditmachine.io
This Privacy Policy explains how we collect, use, disclose, and protect personal information, and the rights available to individuals in the United States. We apply a California CPRA-style baseline to all U.S. users (and describe additional state rights below), even if a particular state law’s numeric threshold may not yet apply to us.
Our Terms of Service govern use of the Service. Related notices: Cookie Policy, Subprocessors, DMCA Policy, Refund Policy, Acceptable Use Policy. If there is a conflict about privacy commitments, this Policy controls for privacy disclosures; the Terms control contractual use of the Service.
Scope; Who This Policy Covers
This Policy covers personal information we process about:
- Visitors to our marketing site
- Account holders and purchasers
- Individuals who contact support
- Agency users who submit client Target Sites (as to the agency user’s own data)
Not covered as “your” personal information: content that appears on a third-party Target Site you ask us to analyze (that content is processed to generate a Report for you; see Section 5). If Target Site content includes personal information about other people, you are responsible for having a lawful basis / authorization to request that analysis.
Children. The Service is for users 18+. We do not knowingly collect personal information from children under 13 (COPPA) or create accounts for anyone under 18. If you believe we have collected such data, contact privacy@auditmachine.io and we will delete it.
Employees / B2B contacts. Job applicants and business contacts may be covered by separate notices.
Categories of Personal Information We Collect
We collect the following categories (CPRA-style). Some information is collected automatically; some you provide; some comes from processors (e.g., Stripe).
We do not intentionally collect Social Security numbers, driver’s license numbers, precise GPS, biometric templates for identification, or health diagnoses in the standard Audit Machine flow.
3.1 Notice at Collection (summary)
We collect personal information to: create and secure accounts; run OTP login; accept payment; generate and deliver Reports; provide support; prevent fraud/abuse; comply with law; and improve the Service (including evaluating AI/automation quality).
We do not sell personal information for money. We may use advertising/analytics technologies that some state laws treat as “sharing” or “targeted advertising”; you can opt out (Section 9).
Retention: see Section 8.
How to exercise rights: Section 9.
How We Use Personal Information (Business / Commercial Purposes)
We use personal information to:
- Provide the Service — account creation, authentication, URL intake, Report generation/delivery, dashboard history
- Process payments and refunds — via Stripe; billing descriptor may show “Audit Machine”
- Customer support and communications — transactional emails (OTP, receipts, Report links); respond to requests
- Security, fraud prevention, and abuse detection — rate limiting, malware/scan defenses, chargeback review
- Improve and develop the Service — quality review of automated findings, debugging, analytics (see AI section)
- Marketing (optional) — if you opt in or as otherwise permitted by law; you may unsubscribe anytime
- Legal compliance — tax, accounting, law-enforcement requests, enforce Terms, defend claims
- Corporate transactions — merger, acquisition, financing, or transfer to a successor entity
We will not use personal information for materially different, unrelated, or incompatible purposes without notice and consent where required.
Target Sites, Scraping, and AI Processing
5.1 Target Site Data
When you submit a Target Site URL, we (and our processors) may retrieve publicly available pages, assets, screenshots, metadata, and related public signals needed to produce the Report. That data may include personal information that appears publicly on the Target Site (e.g., names in testimonials). We process it on your instructions to deliver the Service you requested.
You must have authority to request analysis of the Target Site (see Terms §3).
5.2 AI / Automated Decision Tools
We use AI models and automated workflows (which may include third-party model providers) to draft findings, summarize public signals, prioritize fixes, and assist human review.
- Outputs can be wrong or incomplete.
- We do not use this processing to make decisions that produce legal or similarly significant effects about consumers without human involvement in the product sense of credit, employment, housing, etc.
- We may use de-identified or aggregated metrics to improve quality.
Model training. We do not sell your personal information to model providers for their general training. Where a provider’s default settings might allow retention for abuse monitoring or service improvement, we configure enterprise/API options to limit training on customer content when available. Details depend on the then-current subprocessors list (Section 7).
5.3 De-identified / Aggregated Data
We may create de-identified or aggregated datasets (e.g., anonymized CRO pattern statistics). We maintain them without attempting to re-identify individuals, except as needed to test de-identification or as required by law.
Cookies, Analytics, and Advertising Technologies
Details are in our Cookie Policy. In summary, we and our partners may use cookies, local storage, pixels, and similar technologies for:
- Strictly necessary — login session, security, load balancing, checkout
- Preferences — language/UI settings
- Analytics — understand traffic and feature usage
- Advertising / measurement (if enabled) — campaign performance; may be “sharing” / targeted advertising under state law
Your choices: browser controls; in-product cookie preferences (when available); Global Privacy Control (Section 9.4); “Do Not Sell or Share” / “Limit the Use” links (Section 9).
We honor browser Global Privacy Control (GPC) signals as a valid opt-out of sale/sharing and targeted advertising for that browser, as described in Section 9.4.
How We Disclose Personal Information
We disclose personal information to:
7.1 Sale / Sharing status (last 12 months — disclosure template)
If we do not run third-party advertising pixels, treat “Possibly” rows as No operationally and update this table when ads are enabled. Keep the “Do Not Sell or Share” mechanism available regardless.
We do not knowingly sell or share personal information of consumers under 16.
7.2 Categories of third parties (business purposes)
Cloud infrastructure providers; payment processors; email delivery providers; security/fraud vendors; analytics providers; AI model API providers; customer support platforms; professional service firms.
Retention
We retain personal information only as long as reasonably necessary for the purposes described, including:
Retention may be extended for disputes, legal holds, or statutory requirements. When no longer needed, we delete or de-identify.
Your Privacy Rights (U.S. State Privacy Rights)
Depending on your state of residence, you may have some or all of the following rights (we extend the core set nationally):
- Right to Know / Access — confirm processing and access categories / specific pieces (subject to verification and exceptions)
- Right to Delete — request deletion, subject to legal exceptions (e.g., complete transactions, security, legal compliance)
- Right to Correct — correct inaccurate personal information
- Right to Data Portability — receive a portable copy of certain information
- Right to Opt Out of Sale / Sharing / Targeted Advertising
- Right to Limit Use and Disclosure of Sensitive Personal Information (where applicable)
- Right to Opt Out of Certain Profiling used for decisions that produce legal or similarly significant effects (we do not engage in such profiling in the standard Service)
- Right to Non-Discrimination — we will not deny goods/services or charge different prices solely for exercising privacy rights (financial incentives, if ever offered, will be explained in a separate notice)
- Right to Appeal — if we deny your request, you may appeal (Section 9.3)
9.1 How to Submit a Request
Email privacy@auditmachine.io with the subject line “Privacy Request,” or use any in-product privacy form we publish. Tell us which right you want to exercise and the email associated with your account.
Authorized agents (including California): you may designate an authorized agent. We will require proof of authority and may still need to verify your identity directly.
9.2 Verification
We verify requests by confirming control of the account email and may ask for additional information reasonably necessary to verify identity (we will not require sensitive documents unless needed for high-risk requests).
9.3 Timing; Appeals
We will respond within 45 days of receipt (or sooner if required by your state). We may extend once by 45 days where reasonably necessary and permitted, with notice.
If we deny your request, you may appeal by replying to our decision email within a reasonable time. If appeal is denied, you may contact your state Attorney General.
9.4 Opt-Out of Sale / Sharing / Targeted Ads; GPC
- Use the site footer link: “Do Not Sell or Share My Personal Information” (and “Limit the Use of My Sensitive Personal Information” if shown).
- Enable Global Privacy Control (GPC) in your browser. We treat a valid GPC signal as an opt-out of sale/sharing and targeted advertising for that browser/device.
- You may also email privacy@auditmachine.io with “Opt Out.”
Opt-outs do not stop strictly necessary processing needed to provide the Service you request (e.g., delivering a Report you bought).
9.5 State-Specific Notes (non-exhaustive)
We designed this Policy to satisfy the strictest common requirements among comprehensive state laws in effect as of 2026 (including California CCPA/CPRA; Virginia VCDPA; Colorado CPA; Connecticut CTDPA; Utah UCPA; Texas TDPSA; Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and similar statutes).
Texas: TDPSA provides consumer rights broadly for businesses serving Texas residents (with an SBA small-business exemption in some cases). We still honor the rights menu above for Texas residents.
Colorado / Connecticut / California (and others recognizing universal opt-out): GPC honored as described.
Where a state grants a right we do not list, contact us and we will honor applicable law.
Financial Incentives
We do not currently offer financial incentive programs that trade discounts for sale of personal information. If that changes, we will provide a separate CPRA-compliant notice of material terms and right to withdraw.
Security
We use commercially reasonable safeguards designed to protect personal information (access controls, encryption in transit, least-privilege practices, logging). No security program is perfect. You are responsible for protecting your account credentials and the devices you use.
If we become aware of a breach affecting your personal information, we will notify you and regulators as required by applicable law.
International Users
We are U.S.-based. If you access the Service from outside the United States, you understand your information may be processed in the U.S. and other countries where our providers operate, which may have different data-protection laws.
EEA/UK/Switzerland: We do not currently market the Service as targeting the EEA/UK/CH and have not appointed an Article 27 representative. If that changes, we will update this Policy and provide GDPR-required disclosures (controller identity, legal bases, transfer mechanisms, DPO if appointed). Do not use the Service if you need GDPR-covered processing terms that we have not yet offered.
Third-Party Sites
Reports and the Site may link to third-party websites. Their privacy practices are governed by their own policies. We are not responsible for third-party content or practices.
Changes to This Policy
We may update this Policy periodically. We will post the updated Policy with a new “Last Updated” date. For material changes, we will provide additional notice (email or in-product) as required by law. Continued use after the effective date constitutes acknowledgment of the updated Policy, except where consent is required.
Contact Us
Privacy requests & questions: privacy@auditmachine.io
Support: support@auditmachine.io
Mail: Audit Machine, 5830 E 2nd St, Ste 7000 #38290, Casper, WY 82609, USA
California “Shine the Light”
California residents may request a list of certain third parties to whom we disclosed personal information for their own direct marketing purposes in the prior calendar year. We do not disclose personal information to third parties for their own direct marketing purposes. To make a request, email privacy@auditmachine.io.
Accessibility
We aim to make this Policy accessible. If you need it in an alternative format, contact privacy@auditmachine.io.
Appendix A — CPRA Categories Collected / Disclosed (12-month lookback template)
Update operationally at least annually:
