Privacy Policy
Last updated 13 September 2026
This policy explains what Docs on File collects, why, who it is shared with, and how long it is kept. It covers both the businesses who use the service and the vendors whose documents pass through it.
Two kinds of people are involved
Most of this policy turns on a distinction worth stating up front.
Customers — event venues, property managers, contractors and other businesses — sign up, create an account, and use the service.
Vendors — caterers, photographers, DJs, rental companies — do not sign up and are not our customers. A customer enters their name and email address, and the service contacts them to ask for a certificate of insurance. If you are a vendor reading this, your information reached us from a business you work with, not from us finding you. That business decides what is held about you; see “If you are a vendor” below.
What we collect
From customers: name and email address for the account, business name and address, and the minimum coverage amounts configured for each risk tier.
About vendors, provided by the customer: business name, contact email address, and a risk tier.
Documents: the certificate of insurance files that are uploaded, and the information recorded from them — named insured, certificate holder, coverage lines and limits, additional-insured status, effective and expiration dates, and the issuing agency’s details. Certificates are mostly business information, but a named insured is sometimes an individual, and contact blocks can contain personal names, addresses, and phone numbers.
Optional information vendors provide: a general description of what they need on site, if they choose to give one.
Onboarding answers: your industry, roughly how many vendors you work with, how you track their paperwork today, what you would expect to pay, and what you want the service to do. We use these to decide what to build and how to price it.
Records of messages sent: which reminder went to which address and when, so the same message is not sent twice.
We do not collect payment card details. If paid plans are in use, card details go directly to Stripe and we never see them.
Why we use it
To run the service: storing documents, recording what they contain, comparing recorded limits against the minimums a customer set, showing status, and sending the reminders the service exists to send. We also use it to support customers and to keep the service secure and working.
We do not sell personal information, and we do not use uploaded documents to advertise to anyone.
Automated reading of documents
Uploaded documents are sent to Anthropic’s API so their contents can be read and the review fields pre-filled. This is an automated step that assists a person; it does not make any decision on its own, and every document is reviewed and approved by a person at the customer’s business.
When a customer chooses to have a pasted vendor list read automatically, that text is also sent to Anthropic’s API, which picks out vendor names, email addresses and tiers. The result is shown to the customer to check and edit; nothing is created until they choose to import it.
A customer can turn this off, in which case documents are stored and fields are typed in by hand.
Who we share it with
We use the following providers to run the service. They process information on our instructions and for no other purpose.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, file storage, and login | United States |
| Vercel | Hosting the application | United States |
| Anthropic | Reading uploaded documents and pasted vendor lists to pre-fill fields | United States |
| Resend | Sending email | United States |
| Stripe | Payments, if and when paid plans are in use | United States |
We may also disclose information where the law requires it. We do not otherwise share it with third parties.
How long we keep it
Documents and vendor records are kept while a customer’s account is open, and for twelve months after it closes, so a customer can come back or export what it needs. After that they are deleted.
Certificates are deliberately kept rather than deleted at expiry: being able to show what was on file on the date of a past event is a large part of why businesses keep this record at all.
A customer can delete an individual document, a vendor, or its whole account earlier than that, at any time.
How it is protected
Uploaded files are held in private storage and are not publicly reachable. Customer staff view them through short-lived links generated for that request. Each customer’s data is separated at the database level, so one customer cannot read another’s. Access to production systems is limited to people who need it.
No service can promise perfect security, and we do not. If a breach affects your information, we will tell you and any regulator the law requires us to tell.
If you are a vendor
You can ask to stop receiving emails from us about a particular business at any time, using the link in any message we send you.
The business you work with holds the working relationship with you and decides what records to keep about that relationship, so requests to correct or delete your information are best raised with them first. You can also contact us at support@docsonfile.com, and we will pass the request on and tell you what happens.
Your choices as a customer
You can view, correct, export, or delete your data from within the product. If anything is not reachable there, ask us and we will do it.
Children
The service is for businesses. It is not directed at children and we do not knowingly collect information from them.
Changes to this policy
If we change this policy in a way that materially affects how information is used, we will give notice before the change takes effect. The date at the top shows when it was last revised.
Contact
Reach us at support@docsonfile.com.