Comma Compliance Privacy Policy

Learn how Comma Compliance Inc collects, uses, and protects your personal data. Read our Privacy Policy to understand your rights and our commitments.

Effective March 15, 2026 (last updated June 18, 2026)

1. Information We Collect

a. Information You Provide

We may collect personal information that you voluntarily provide when you:

  • Register for an account.
  • Use our Services.
  • Contact our support team.

Examples of such information include:

  • Name and contact details (e.g., email address, phone number).
  • Billing and payment information.
  • Data uploaded to the Services (“User Data”).

b. Automatically Collected Information

When you use our Services, we may collect information automatically, such as:

  • Device information (e.g., IP address, browser type).
  • Usage data (e.g., pages visited, time spent on the Services).
  • Cookies and similar technologies (see Section 7).

c. Third-Party Information

We may receive information about you from third-party services if you link or integrate those services with our platform.

d. Messages Archived on Managed Devices

Where an organization deploys our enterprise messaging-archival application to its corporate-managed Android devices, we collect, on that organization’s behalf, the SMS, MMS, and RCS messages stored on those devices - including message content, attachments, participants, and timestamps. This collection is described in Section 5 (Compliance Archiving of Messages on Managed Devices).

2. How We Use Your Information

Except for archived messages described in Section 5, which are used only as described in Section 5(c), we use the information we collect for the following purposes:

  • To provide, maintain, and improve our Services.
  • To authenticate your account and ensure secure access.
  • To communicate with you, including sending updates, notifications, and support messages.
  • To process payments and manage subscriptions.
  • To comply with legal and regulatory obligations.
  • To analyze usage trends and enhance user experience.

3. Sharing and Disclosure of Information

We do not sell your personal information. However, we may share your information in the following circumstances:

a. With Service Providers

We may share information with third-party vendors who assist us in operating the Services, such as payment processors, cloud hosting providers, and customer support tools.

b. As Required by Law

We may disclose your information to comply with legal obligations, such as responding to subpoenas, court orders, or government requests.

c. In Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.

We may share your information for other purposes if you provide explicit consent.

No mobile information, including mobile phone numbers and text messaging opt-in or consent data, will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors that support delivery of the Services - such as messaging providers and aggregators (e.g., Twilio) and customer support tools, solely as needed to deliver the SMS and other Services you have requested - is permitted. All other categories of information sharing described in this Policy exclude text messaging originator opt-in data and consent, which will not be shared with any third parties.

4. SMS and Text Message Communications

If you provide your mobile phone number and opt in to receive text messages from us, the following terms apply:

  • Purpose. We use SMS solely to deliver the Services you have requested, including account verification, security alerts, transactional notifications, and customer support replies. We do not send marketing or promotional SMS.
  • Message Frequency. Message frequency is minimal and varies based on your use of the Services. We only send messages as required to deliver the Services.
  • Message and Data Rates. Message and data rates may apply. Check with your mobile carrier for details about your plan.
  • Opt-Out. You can opt out of SMS at any time by replying STOP to any message you receive from us. After you opt out, you will receive a single confirmation message and we will not send you further SMS unless you opt in again.
  • Help. For help, reply HELP to any message or contact us at support@commacompliance.com.
  • Carriers. Mobile carriers are not liable for delayed or undelivered messages.

5. Compliance Archiving of Messages on Managed Devices

Comma Compliance provides an enterprise messaging-archival application (the “Comma Compliance Messages Archiver” for Android) that organizations deploy to their corporate-managed (fully-managed, device-owner) Android devices to meet regulatory, legal-hold, and internal-policy obligations to retain employees’ business communications. This Section describes how that application collects and handles message data. It applies only to devices an organization has enrolled and configured for archiving; it does not apply to personal devices or to visitors to our websites.

a. Enterprise-Administered

The application operates only after an organization’s administrator has enabled message archiving for the organization and the device has been connected to that organization - either through administrator-delivered managed configuration or through the employee’s own authenticated sign-in to the organization. The organization that deploys the application controls the resulting archive; Comma Compliance processes the data on that organization’s behalf as its service provider.

b. What We Collect

On a managed device, the application reads and archives the SMS, MMS, and RCS messages that the device’s default messaging app has received and stored, including:

  • Message content - text bodies and attachment files (such as images, video, voice messages, and contact cards).
  • Participants - sender and recipient phone numbers and, where available, associated contact names.
  • Metadata - timestamps, read receipts, reactions, edits, and delivery status.

The application reads only messages the device’s default messaging app has already received and stored. It does not intercept, weaken, or bypass any messaging app’s transport encryption, and it does not capture messages from third-party messengers (such as WhatsApp, Signal, or Telegram), which do not flow through the device’s standard messaging storage.

c. How We Use It

Archived messages are transmitted only to the organization’s designated compliance archive and are used solely to provide the archival Service the organization has requested. This data is not used for advertising, is never sold, and is not shared with anyone other than the organization that administers the archive and the subprocessors that operate the Service on our behalf (for example, cloud hosting).

Archiving is never covert. While archiving is active, the device displays a persistent, non-dismissible notification stating that messages are being archived for compliance and naming the organization. Before any message access is requested, the application shows a plain-language screen explaining what is captured, that the organization administers the archive, and that messages are encrypted on the device before they are sent. Each organization is responsible for providing any notice to, and obtaining any required consent or other authorization from, the individuals whose messages are archived, as required by the laws that apply to it.

e. Security

Messages and attachments are encrypted on the device before transmission and are sent only to the Comma Compliance archive configured for the organization, over an encrypted connection. Each device generates its own cryptographic keypairs on the device; the private keys remain on the device and never leave it, and the on-device queue of pending data is encrypted at rest.

f. Retention and Deletion

Archived messages are retained by the organization in accordance with its own retention and legal-hold policies; the organization controls retention and deletion of its archive. An administrator can revoke a device at any time, which stops further archiving from that device. Requests to access or delete archived messages should be directed to the organization that administers the archive, and Comma Compliance will assist that organization in fulfilling those requests as its service provider.

6. Data Retention

Except for archived messages, which are retained as described in Section 5(f), we retain your information for as long as necessary to provide the Services or as required by applicable laws. User Data will be deleted following account termination, subject to any legal retention obligations.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience. These technologies help us:

  • Remember your preferences.
  • Analyze usage trends.
  • Provide a secure and personalized experience.

You can manage cookie preferences through your browser settings. However, disabling cookies may affect the functionality of our Services.

8. Security

We implement reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, loss, or misuse. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information.
  • Restriction: Request restriction of processing your information.
  • Portability: Request transfer of your information to another service.
  • Objection: Object to processing based on legitimate interests.

To exercise your rights for information Comma Compliance controls, contact us at support@commacompliance.com. For archived messages that an organization administers, see Section 5(f).

10. International Users

If you access the Services from outside the United States, your information may be transferred to and processed in the United States. By using the Services, you consent to such transfer and processing. This consent does not extend to the archived messages described in Section 5: because the individuals whose messages are archived are not necessarily users of the Services, the deploying organization is responsible for establishing the lawful basis for any cross-border transfer of those messages and for meeting its own international data-transfer obligations to those individuals. Comma Compliance acts as the organization’s processor in effecting such transfers.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be effective upon posting to our website. Your continued use of the Services constitutes acceptance of the revised Privacy Policy.

12. Contact Information

If you have any questions or concerns about this Privacy Policy, please get in touch or contact us directly:

Comma Compliance

Email: support@commacompliance.com

Phone: 888-884-3318

Address: 2261 Market Street STE 22253, San Francisco, CA 94114