← Back to DocuRise

DOCURISE PRIVACY POLICY

Effective Date: February 18, 2026

1. Introduction

RiseCraft, LLC ("DocuRise") is a Delaware company providing document security and analytics tools. This policy explains how we handle data.

2. What We Collect

From Document Owners: Account information (name, email, payment details).

From Viewers (on behalf of Document Owners): Engagement metrics (views, time spent, scroll depth), device/browser type, general location, and an anonymous session ID (UUID). If a Viewer submits a lead form, that information goes directly to the Document Owner.

3. How We Use Data

To provide, maintain, and improve the Service. We also collect anonymized, aggregated Usage Data to improve platform performance.

4. How We Share Data

We do not sell your data. We share it only:

5. Data Retention

6. Your Rights

6.1 Document Owners: Access, update, export, or delete your data via account settings or support@docurise.io.

6.2 Viewers: Direct requests to the Document Owner. If you can't reach them, contact support@docurise.io.

6.3 U.S. State-Specific Rights (CCPA). We do not sell personal information. California residents may request to know what personal information we hold and request its deletion by contacting support@docurise.io.

6.4 Supplemental Terms for South Korea (PIPA). If you are located in South Korea, the following applies in addition to the terms above:

7. International Transfers

Data is processed in the United States.

8. Children

The Service is not for anyone under 18. We do not knowingly collect data from children.

9. Security

We use commercially reasonable measures including encryption in transit and at rest. No method is 100% secure.

10. Changes

We may update this policy and will post changes with an updated effective date. Material changes will be communicated by email or in-app notice.

Contact: support@docurise.io


DocuRise Privacy Note — PIPA Addendum (South Korea)

Effective Date: February 15, 2026

This Addendum applies to users located in South Korea and supplements the DocuRise Privacy Policy. In the event of any conflict between this Addendum and the Privacy Policy, this Addendum prevails for users in South Korea. This Addendum is provided in accordance with the Personal Information Protection Act (개인정보보호법, "PIPA").

1. Personal Information Protection Officer

The person responsible for the protection of personal information is:
Name: Gayoung Park
Title: CEO
Email: support@docurise.io

All inquiries, complaints, and requests relating to the processing of personal information may be directed to the above contact.

2. Items of Personal Information Collected

2.1 Required Items

CategoryItems CollectedPurposeRetention Period
Account registrationEmail address, nameService provision, authenticationDuration of account; deleted within 30 days of closure
PaymentStripe customer ID, subscription ID (card numbers are not stored by DocuRise)Billing and subscription managementDuration of account; billing records retained up to 7 years for tax compliance
Viewer accessEmail address, IP address, country, device type, user agentDocument access verification, analytics provision to Document OwnerAs determined by the Document Owner's subscription plan; deleted when the document or account is deleted

2.2 Optional Items (Collected Only When Configured by Document Owner)

CategoryItems CollectedPurposeRetention Period
Lead capture formName, company, phone number, industry, years of experience, referral source, marketing consentLead generation on behalf of Document OwnerAs determined by the Document Owner; deleted when the document or account is deleted
Viewer engagementScroll depth, section dwell time, link clicks, CTA clicks, session durationAnalytics on behalf of Document OwnerAccording to Document Owner's subscription plan
Viewer contentComments, feedback ratings, feature requestsFeedback provision to Document OwnerDeleted when the document or account is deleted

2.3 Instagram Integration (Collected Only When Document Owner Connects Their Account)

CategoryItems CollectedPurposeRetention Period
Instagram accountAccount ID, username, encrypted access tokenTo securely maintain authenticated access to the Instagram API and execute user-configured messaging actions.Until account is deleted
Instagram interactionsComment text, commenter ID (hashed), follower status (hashed), DM contentTo process comment-triggered workflows, prevent duplicatesCompleted/failed events deleted after 30 days; all data deleted upon disconnection

3. Provision of Personal Information to Third Parties

We provide personal information to the following third parties to operate the Service:

RecipientContactItems ProvidedPurposeRetention Period
Stripe, Inc.privacy@stripe.comEmail, subscription dataPayment processingDuration of subscription; per Stripe's retention policy
Supabase, Inc.support@supabase.comAll application dataDatabase hosting and authenticationDuration of account
Vercel, Inc.privacy@vercel.comIP address, request dataWeb hosting and edge computingPer Vercel's retention policy
Resend, Inc.support@resend.comEmail address, email contentTransactional email deliveryPer Resend's retention policy
Upstash, Inc.support@upstash.comRate limit keys, encrypted job payloadsRate limiting, async task processingTransient (no long-term storage)
Functional Software, Inc. (Sentry)compliance@sentry.ioError logs, request contextError monitoringPer Sentry's retention policy
Meta Platforms, Inc.N/A (via Instagram Graph API)Instagram account data, message contentDM Workflow (when connected)Per Meta's data retention policies
PostHog, Inc. (if enabled)privacy@posthog.comAnonymized usage eventsProduct analyticsPer PostHog's retention policy
Google LLC (if enabled)N/A (via Google Analytics)Anonymized page viewsWeb analyticsPer Google's retention policy

4. Overseas Transfer of Personal Information

Your personal information is transferred to and processed outside of South Korea as follows:

RecipientCountryItems TransferredPurposeMethodTiming
RiseCraft, LLCUnited StatesAll personal information described in Section 2Service operation and provisionEncrypted network transmissionContinuous, upon use of the Service
Supabase, Inc. (AWS)United States / Singapore (ap-southeast-1)All application dataDatabase hostingEncrypted network transmissionContinuous
Stripe, Inc.United StatesEmail, subscription dataPayment processingEncrypted network transmissionUpon payment events
Vercel, Inc.United States / Global edgeIP address, request dataWeb hostingEncrypted network transmissionUpon each request
Resend, Inc.United StatesEmail address, email contentEmail deliveryEncrypted network transmissionUpon email events
Upstash, Inc.United StatesRate limit keys, encrypted payloadsRate limiting, task queueEncrypted network transmissionContinuous
Functional Software, Inc. (Sentry)United StatesError logsError monitoringEncrypted network transmissionUpon errors
Meta Platforms, Inc.United StatesInstagram data (when connected)Messaging WorkflowEncrypted network transmission (via Graph API)When workflow is active

RiseCraft, LLC ensures that all overseas recipients maintain security measures that meet or exceed the standards described in this Addendum and the Data Processing Addendum.

5. Destruction of Personal Information

When personal information is no longer needed for the purpose for which it was collected, or when the retention period has expired, we destroy it as follows:

Destruction timelines:

6. Rights of Data Subjects

Under PIPA, you have the right to:

To exercise these rights, contact support@docurise.io. We will process your request within 10 days. If we cannot comply with a request, we will notify you of the reason.

You may also exercise these rights through a legal representative by submitting a power of attorney.

Refusal of consent: You may refuse to provide optional personal information (e.g., name, company, phone number in lead capture forms). Refusal to provide required information (e.g., email address for account creation) may limit your ability to use the Service.

7. Measures to Ensure the Security of Personal Information

We implement the following technical, managerial, and physical measures:

8. Installation and Operation of Cookies

We install cookies that are strictly necessary for the operation of the Service:

Cookie NamePurposeExpiry
NEXT_LOCALELanguage preference (en/ko)Persistent
viewer_session_{id}Document viewing sessionSession
password_verified_{id}Password verification for protected documentsSession

Optional analytics services (PostHog, Google Analytics), if enabled, may set additional cookies. You can refuse or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent normal use of the Service.

9. Changes to This Addendum

We may update this Addendum and will post changes with an updated effective date. Material changes will be communicated by email or in-app notice at least 30 days before they take effect.

Contact: support@docurise.io