Skip to Main Content

Privacy Policy

Privacy, in Normal Human Language.

Effective September 15, 2026. This policy explains how SBG Software Services, a trade name of SBG Compliance Services, LLC, handles information through this website, authenticated portals, intake system, and service engagements.

Information We Collect

We collect information you choose to provide, such as contact details, account information, intake answers, project communications, approvals, legal acceptance records, support reports, and materials needed to perform an engagement. Authenticated systems also create operational records such as timestamps, account identifiers, document versions, integrity hashes, authorization events, and security/audit evidence. Do not paste passwords, MFA or recovery codes, private keys, payment credentials, secret API keys, or actual regulated records into ordinary intake or contact fields. If a project involves sensitive information, describe the category first so SBG can determine an appropriate handling method.

How We Use Information

We use information to evaluate requests, communicate with you, administer accounts and projects, prepare proposals and agreements, perform and verify services, provide secure source transfer and handoff, investigate problems, protect the service, maintain business and legal records, and meet applicable obligations. SBG does not sell, rent, or broker personal or client data, share it for advertising or third-party marketing, or treat privacy as a revenue stream. Information may be disclosed to service providers reasonably necessary to operate or perform the engagement, as authorized or instructed by the client, or when legally required.

Operational Email, Calls, and Texts

At intake submission, SBG asks for explicit consent to contact the submitter at the contact information provided by email, phone call, or text about that request and any resulting project, including matters that may need timely attention. This consent is for operational engagement communication only; SBG does not request promotional or third-party marketing consent through the intake checkbox. Carrier message or data rates may apply to texts. Ordinary project communications should not contain passwords, MFA codes, private keys, protected health information, payment-card data, or other regulated records that belong in an approved secure workflow.

When SBG Processes Client-Controlled Data

For account, intake, contracting, security, and business-administration records, SBG determines why the information is needed for its own operations. When a client gives SBG access to personal information contained in the client's application, database, source materials, or test environment solely so SBG can perform the agreed service, the client generally determines the purpose of that processing and represents that it has the authority to provide access. SBG uses that client-controlled information only as reasonably necessary for the engagement, documented instructions, security, legal obligations, or other purposes expressly permitted by the governing agreement. Individuals seeking rights concerning data controlled by an SBG client may need to direct the request to that client.

AI-Assisted Processing

AI-assisted engineering and analysis are part of SBG's normal methodology. Project information may be processed by appropriate AI-assisted development tools when reasonably necessary to perform the engagement. AI output is not treated as inherently correct, and SBG remains responsible for the review and verification included in the agreed scope. SBG does not intentionally use client confidential information to train a general-purpose model for SBG or another client. We do not knowingly provide authentication secrets to an external AI service merely for convenience. A project involving regulated or unusually sensitive data may require additional review before that information can be processed by any AI-assisted tool.

Service Providers and Third Parties

We use service providers and project platforms for hosting and application infrastructure, authentication, object storage and source transfer, repositories, transactional email, hosted payment processing, development, AI-assisted tooling, and other functions reasonably necessary to operate the service or perform an engagement. Current workflows include Base44 platform services, Google account/email services where used, Cloudflare R2 for designated source-file storage and transfer, and Stripe-hosted Checkout when SBG offers an eligible online payment. Providers may change as the service evolves and process information under their own terms and privacy practices. Production resources intended to belong to a client should, where practical, ultimately be held in or transferred to client-controlled accounts.

Payments

The SBG portal does not collect or store full payment-card numbers. When SBG offers an eligible online card payment, the Client is directed to Stripe-hosted Checkout and Stripe processes the payment method information under its own terms and privacy practices. SBG receives and retains limited provider/payment evidence needed to bind and reconcile the transaction, such as provider object identifiers, amount, currency, status, timestamps, refund/dispute/Radar-review state, and signed webhook provenance. A browser return or success screen is not treated as proof of payment; SBG verifies provider-side evidence before treating an online payment as verified. Approved external payment methods may also be recorded with limited administrative transaction metadata. The SBG payment model does not require storage of full card numbers, automatic subscription renewal, automatic future charging, or automatic refunds.

Regulated and Especially Sensitive Data

Selecting a sensitive-data category in an intake is a review flag, not permission to transmit the underlying records. Do not send protected health information, full payment-card data, Social Security numbers, government-ID images, children's records, or similarly regulated or high-risk data unless SBG has expressly accepted that handling in writing and the required contract, provider capability, access controls, and other safeguards are in place. For example, work requiring SBG to create, receive, maintain, or transmit HIPAA-regulated protected health information may require a Business Associate Agreement and compatible subcontractors before access is allowed.

Security and Source Materials

We use reasonable administrative and technical safeguards appropriate to the information and prefer least-privilege, collaborator, team, temporary, or revocable access where feasible. If SBG determines that an authorized Audit, Rescue, or eligible Maintenance workflow genuinely requires a client source ZIP, the archive must use the authenticated project-specific Secure Source Upload opened by SBG after the applicable agreement, supplemental-data, and payment gates are cleared. Ordinary email attachments and third-party file-sharing links are not approved source-archive submission methods. Repository, platform, test, or staging access is coordinated separately when appropriate. Source sent unexpectedly outside the approved workflow is not treated as an authorized project submission merely because SBG received it; SBG may decline to use it, direct the sender to the approved workflow, and isolate or securely remove unnecessary copies when appropriate, subject to incident, dispute, legal-hold, or other binding preservation requirements. No electronic system, transmission method, or storage provider can be guaranteed absolutely secure. Security controls and statements on this site describe SBG's practices; they are not a claim of HIPAA, PCI DSS, SOC, ISO, FedRAMP, or other certification unless SBG expressly identifies a specific certification in writing.

Security Incidents

SBG investigates suspected security incidents involving information in its custody and takes reasonable steps to contain and remediate confirmed issues. If SBG is storing computerized personal information on behalf of a client and a breach triggers a legal or contractual notification duty, SBG will notify the affected client in an expeditious manner consistent with applicable law, necessary investigation, restoration of system integrity, and lawful law-enforcement delay. Direct notice to affected individuals, regulators, or others will be handled by the party responsible under applicable law and the governing agreement.

Retention

We use different retention periods for different kinds of information instead of treating every file the same. As our ordinary business-record standard, durable contractual, payment, acceptance, cancellation, audit, verification, security, incident, and project-provenance records are generally retained for seven years after the latest relevant project-closing event, such as completion, final cancellation/termination, final payment or payment-dispute resolution, final Maintenance term closure, or related incident/dispute closure. That seven-year period is an SBG business-record policy, not a statement that every record is legally required to be retained for seven years; a different binding legal, tax, contractual, regulated-data, insurance, or legal-hold requirement controls where applicable. Working intake drafts, source-transfer copies, credentials, regulated data, and other sensitive working material do not automatically receive a seven-year retention period. Source-transfer working copies should be deleted when they are no longer needed for active delivery, the included 30-day defect-support/recovery needs, Maintenance baseline needs, disputes, security investigations, or legal holds. Non-secret release hashes, custody history, and handoff evidence may remain with the durable project record after underlying archive bytes are deleted. A separate paid Source Vault retention service is not currently offered. If SBG introduces one later, its retention terms will be stated before purchase.

Privacy Rights and Requests

Where applicable law provides a right to access, correct, delete, obtain a copy of, or otherwise exercise control over personal information, you may contact SBG to make that request. We may verify identity and authority before acting. We evaluate requests in light of security, contractual, recordkeeping, legal, and technical requirements, and a deletion request does not require destruction of records SBG reasonably must or may retain for legitimate business or legal purposes. If the information is held solely on behalf of an SBG client, SBG may direct the request to that client or assist the client as required by the governing agreement and applicable law. Clients should download project records and deliverables they need to preserve before requesting account closure.

Cookies, Logs, and Session Technology

The application uses authentication and session technology necessary to sign users in, protect authenticated areas, preserve appropriate session state, and operate the Client and Admin portals. Underlying hosting, authentication, security, and infrastructure providers may also receive technical information such as IP address, device/browser information, request logs, and usage/security events under their own policies. SBG does not currently operate its own advertising or cross-site behavioral-tracking program. If SBG introduces materially different tracking or advertising practices, this policy will be updated before relying on them.

Children

SBG may support adult personal/family/household software projects, but the service is not directed to children and an adult should not create an ordinary SBG account on behalf of a child. Projects that involve information about minors require explicit review of the use case, the client's authority and obligations, and the technical/service-provider requirements before SBG accepts access to that data.

Policy Changes

We may update this Privacy Policy as the service changes. Material changes will be reflected in the posted policy. Project-specific confidentiality, source handling, and legal obligations may also be governed by an accepted Services Agreement, Statement of Work, Change Order, or incorporated policy.

Contact

Privacy questions, privacy-rights requests, and formal legal notices may be sent to legal@sbgcompliance.com. General business and support questions may be sent to info@sbgcompliance.com. Active clients may also use the authenticated Client Portal for project-related privacy or security questions so the communication can be preserved with the project record. Do not include passwords, MFA codes, private keys, payment credentials, regulated records, or source archives in ordinary email. Source ZIPs are accepted only through an authorized project-specific Secure Source Upload when SBG has requested one. Formal business address: 2606 Hilliard Rome Rd, Unit #V257, Hilliard, OH 43026.