Privacy Policy

How PolicyCraft handles account, handbook, and transaction information.

Last updated: September 23, 2026

Information you provide

PolicyCraft may receive your name, email address, account credentials, company information, selected operating states, handbook content, custom policy text, uploaded plain-text handbook content, and company branding that you choose to provide.

Account security data

Passwords are stored as one-way password hashes rather than readable passwords. Session identifiers and password-reset tokens are used to authenticate accounts and recover access. Password-reset tokens are time-limited, single-use, and stored in hashed form.

How information is used

Information is used to authenticate users, generate and save handbooks, provide handbook analysis, enforce purchased access levels, prevent abuse, support customers, process purchases, and maintain the security and reliability of the service.

Saved handbook content

If you save a handbook to your account, the handbook data is stored so you can return to it later. Avoid entering Social Security numbers, employee medical information, protected health information, payment-card information, confidential legal communications, or other sensitive personal data that PolicyCraft does not need to build the handbook.

Service providers

PolicyCraft uses Cloudflare infrastructure for application hosting and database services. Stripe is used for payment processing. Resend may be used to deliver account-related email such as password-reset messages. Those providers process information according to their own terms and privacy practices.

Payment information

Payment-card entry occurs through Stripe's checkout service. PolicyCraft stores transaction-related identifiers and order status needed to confirm payment and provide the purchased access tier; it does not intentionally store full payment-card numbers.

Security and abuse prevention

PolicyCraft uses access controls, server-side authorization, secure session cookies, request throttling, signed-payment verification, and output-encoding controls designed to reduce unauthorized access and common web attacks. No internet service can guarantee absolute security.

Sharing and sale of information

Gemelli Business Services does not sell PolicyCraft customer information to advertisers. Information may be shared with service providers as needed to operate the platform, process payments, deliver account email, comply with law, or protect the service and its users.

Questions and requests

For privacy questions or account/data requests, contact info@gemellibiz.com.