Skip to content
Coverwright
Legal

Privacy Policy

Last updated 24 July 2026

Draft. This page has not yet had a legal review. It describes our intended practices in good faith but should not be treated as final until reviewed by a licensed professional.

1. Who we are

Coverwright is operated by Aidas Vyšniauskas, a sole trader carrying out individual activity (individuali veikla) under certificate No. 1495712, Lithuania (“Coverwright”, “we”) — the controller of the personal data described below. Contact: hello@coverwright.com · +370 633 45595. A registered address will be added here once one is set up; see the draft banner above.

2. What we collect

  • Intake answers — the questions about your business (industry, headcount, tools you use, data you handle, and similar) that the documents are built from.
  • Purchase record — email address, which tier you bought, amount paid, and a Stripe session reference, stored so you can be identified as a paying customer and, if signed in, see past purchases on /dashboard.
  • Account info — only if you choose to sign in: your email (and name/avatar if you use Google), handled by our authentication provider, Clerk. Signing in is optional.
  • Reminder signup — only if you ask for one: your email address, the month your insurance renews, the date you agreed and the exact wording you agreed to. Used to send one reminder a year and nothing else. Every reminder carries a one-click unsubscribe link, and unsubscribing takes effect immediately.
  • Continuous subscription — only if you add it at checkout: the domain you give us, your Stripe subscription status, and the result of two automated checks run against that domain monthly (whether SPF, DKIM and DMARC records are present — plain DNS lookups, sent to no third party — and, once configured, whether the domain appears in a known, disclosed data breach via Have I Been Pwned’s API). Results are shown on your dashboard and, if you choose to regenerate your documents, can be reflected in them.

The intake has no free-text field except your business name — please don’t put anyone’s personal details in it.

Measurement

We run no third-party analytics, no advertising scripts and no tracking cookies. We do keep our own count of how many people reach each step — a page was viewed, a check was started, an intake was completed — so we can tell which of the things we write is worth writing more of.

Those counts carry no identifier of any kind: no cookie, no device fingerprint, no IP address, no account reference, and no generated visitor ID. Two of them can never be linked to each other or to you, which is a real limitation for us and the reason we chose it — it tells us that a page was seen a thousand times without telling us anything about who saw it. The time is recorded to the hour rather than the second for the same reason.

Separately, if you arrive through a link that carries a campaign or referral tag (for example ?ref= or utm_source=), that tag and the name of the site that linked you — the site’s address only, never the full page or any search terms — are kept in your own browser’s storage. If you go on to buy, they are attached to your purchase so we can pay the person who referred you. If you don’t buy, they never leave your browser and you can clear them by clearing site data.

3. How intake answers are stored

While you’re answering questions, your answers live in your browser only (localStorage) — nothing is sent to us until you complete a purchase. Once you pay, a snapshot of your answers is stored against your purchase record so the same document set can be re-downloaded later. Stripe itself never sees your business answers — only payment details.

4. Why we process your data (legal bases)

We process your data on the following legal bases:

  • to generate and deliver your documents, provide re-download access, and operate your optional account — performance of a contract (GDPR Art 6(1)(b));
  • to keep purchase and invoicing records — legal obligation (Art 6(1)(c), Lithuanian accounting and tax law);
  • to prevent fraud and secure the service — legitimate interests (Art 6(1)(f));
  • where we ever ask for anything optional beyond this — consent (Art 6(1)(a)), which you can withdraw at any time.

5. Who we share data with

We use a small number of processors to run the service:

  • Stripe — payment and subscription processing.
  • Clerk — optional account sign-in.
  • Neon (via Vercel) — database hosting for purchase and subscription records.
  • Vercel — application hosting.
  • Have I Been Pwned — only for Continuous subscribers, and only once this integration is fully configured: your domain is sent to their API to check for known breaches.

We don’t sell your data, and we don’t share it with anyone outside of running the service itself.

6. International transfers

Our processors (Stripe, Clerk, Neon, Vercel) are US companies. Where your data is transferred outside the EEA, the transfer is protected by the EU–US Data Privacy Framework (for certified processors) or the European Commission’s Standard Contractual Clauses incorporated into our agreements with them. Our database and hosting region is to be confirmed with engineering before this page leaves draft.

7. How long we keep it

We keep your purchase record and document snapshot for 3 years from purchase so you can re-download and repurchase updates, then delete the snapshot. Invoicing and accounting data is kept for 10 years as Lithuanian law requires. If you ask us to delete your data sooner, we delete everything except what tax law obliges us to keep.

8. Your rights

You can ask us to access, correct, export, or delete the personal data we hold about you at any time by emailing hello@coverwright.com. If you delete your data, we delete your account, intake snapshot, and generated documents, but must keep the basic purchase and invoicing record (amount, date, and the email it was issued to) for 10 years under Lithuanian accounting and tax law — deleting your data ends your ability to re-download your documents. If you’re in the EU or EEA, this includes the rights available to you under GDPR, including the right to lodge a complaint with a supervisory authority — for us, the State Data Protection Inspectorate of the Republic of Lithuania (VDAI, vdai.lrv.lt) — or the authority where you live or work.

We haven’t appointed a data protection officer — the conditions that require one (public-authority processing, or large-scale regular monitoring or special-category processing) don’t apply to us. As an EU-established controller, an EU representative isn’t applicable. We market Coverwright to US businesses and do not target the UK market, so we haven’t appointed a UK representative; if we ever market to UK buyers, this page will say what changed.

9. US customers

We don’t sell your personal information, and we don’t share it for cross-context behavioral advertising — we run no advertising scripts and no third-party analytics at all, and our own step counts carry no identifier that could be tied to you (see “Measurement” above). If you’re a resident of a US state with its own privacy law (California, Virginia, Colorado, Connecticut, Texas, and a growing list of others), the access, correction, and deletion rights described above are available to you on the same terms, by emailing hello@coverwright.com. We won’t discriminate against you for exercising them.

10. Health-data intake answers

If your intake answers say your business handles health information, that’s information about your business’s activities, not health data about an identified person — GDPR’s special category rules (Art 9) aren’t engaged by that answer. For the same reason, Coverwright is not a HIPAA business associate to you: no patient records are ever entered into it, and none should be.

11. Cookies

We use only the cookies necessary for the site to function — session/authentication cookies set by Clerk when you sign in, and Stripe’s checkout session. No advertising or cross-site tracking cookies.

We also use your browser’s own local storage, which is not a cookie and is never sent to us automatically: it holds your intake answers while you work through them, and any campaign or referral tag from the link you arrived by. Clearing site data in your browser removes both.

12. Contact

Questions about this policy or your data: hello@coverwright.com.