COI Guardian

Trust & Security

How COI Guardian protects your vendor insurance data and what you can expect from us.

This page is maintained by the app owner to answer common security and privacy questions. It describes the controls and practices currently enabled in COI Guardian.

Authentication & access

COI Guardian uses Supabase Auth for authentication. You can sign in with Google OAuth or email and password. Every user is tied to a company, and Row-Level Security (RLS) policies make sure your team can only read and write data that belongs to your company.

Hosting & infrastructure

The application is hosted on Lovable Cloud, which uses Supabase as the underlying database and storage platform. Your uploaded COI documents are stored in a private storage bucket with company-scoped access controls. This page is maintained by the app owner to describe the current practices.

Data collection & use

We collect the minimum data needed to run COI Guardian: account information (name, email, company), property and vendor details, certificate files, and reminder settings. We do not sell your data. We use it only to provide the service: tracking expirations, sending reminders, and letting you review compliance.

Subprocessors

COI Guardian uses Stripe to process payments, Brevo to send transactional emails, and Supabase through the Lovable Cloud platform for authentication and data storage. Google Analytics 4 (Google) is used for aggregated website analytics only after you accept the Analytics category. Microsoft Clarity is currently disabled, and no advertising or retargeting pixel is integrated.

Cookies & analytics

COI Guardian uses essential authentication cookies plus, only with your consent, Google Analytics 4 for aggregated website analytics. Analytics is off by default and can be refused or withdrawn at any time through “Cookie preferences”. Microsoft Clarity is currently disabled and no advertising or retargeting pixel is active.

Retention & deletion

If you delete your COI Guardian account, your company data is kept for 30 days and then permanently removed. You can request earlier deletion by emailing us. After the retention period, data is removed from active systems and backups age out according to the platform provider's lifecycle.

Privacy requests & contact

For questions about your data, deletion requests, or to exercise your privacy rights, email us at clienti@coi-guardian.com. We will respond as quickly as possible, typically within a few business days.

Security reports

If you discover a security issue or vulnerability, please report it to clienti@coi-guardian.com. We will investigate and respond promptly. Please do not publicly disclose the issue before we have had a chance to fix it.

Shared responsibility

COI Guardian runs on the Lovable Cloud platform. The platform provides the underlying infrastructure, database, and auth primitives, while the app owner is responsible for the application logic, data access rules, and user-facing security practices. Keeping your account credentials safe, inviting only trusted team members, and reviewing vendor access regularly are important parts of staying secure.