Skip to content

Privacy Policy

Last updated 21 August 2026.

This Privacy Policy explains how Compass (“Compass”, “we”, “us”) collects, uses, and shares personal data when you visit our website, request a demo, or use the Compass customer intelligence platform (the “Service”). It also describes the choices available to you. Compass provides features designed to support your own privacy and compliance obligations, but this policy describes our practices — not legal advice.

Who this policy covers

This policy applies to two groups. First, people who interact directly with Compass — for example, visitors to our website and representatives of merchants who administer a Compass workspace. Second, the end customers of our merchant customers, whose data a merchant chooses to bring into Compass. For that second group, the merchant is the controller of the data and Compass acts as a processor on their behalf; those relationships are governed by our Data Processing Addendum.

Data we collect

  • Account and contact data — name, work email, company, and role when you request a demo or create a workspace.
  • Merchant customer data — profile, commerce, engagement, consent, and ecosystem activity that a merchant connects from sources such as Shopify, Surveys, and VendorStreet.
  • Usage data — how you interact with the Service, including features used and actions taken, so we can operate and improve the product.
  • Device and log data — IP address, browser type, and similar technical information collected automatically when you use the Service.

How we use data

  • To provide, maintain, and secure the Service, including unified profiles, audiences, campaigns, and journeys.
  • To respond to requests, provide support, and communicate about your account.
  • To improve product quality, reliability, and performance.
  • To detect, prevent, and address abuse, security incidents, and technical issues.

We do not sell personal data. We do not use merchant customer data to train foundation models, and we process it only to provide the Service under our agreement with the merchant. In particular, we do not sell, rent, or share a merchant’s customer contact data — including email addresses, mobile phone numbers, and the messaging consent and opt-in records attached to them — with third parties or affiliates for their own marketing or promotional purposes. Messaging opt-in data and consent are disclosed only to the subprocessors that deliver messages and operate the Service on the merchant’s behalf, and only so that they can do so.

Cookies and analytics

This website uses Google Analytics, loaded through Google Tag Manager, to measure site traffic and understand how visitors use the site. Which rules apply depends on where you appear to be. If you appear to be in the EEA, the UK or Switzerland, nothing is requested from Google and no analytics cookies are set until you accept via our cookie banner — decline, or simply ignore it, and no Google script loads at all. Everywhere else, analytics start on your first page view and the banner invites you to opt out; if you decline we stop analytics, switch Google Analytics off for this site, and delete the analytics cookies already set, so only that first page view was ever counted. We work out which applies from your browser's own time-zone setting — a rough guess that a VPN or a trip abroad will fool. We deliberately do not use the Geolocation API (which would prompt you) or an IP address lookup, and an unreadable time zone falls back to the stricter, consent-first rules. Either way we use analytics only — we do not load advertising or cross-site tracking cookies. You can change your choice at any time using the Cookie settings link in the footer. This applies to the compass.st marketing website; the Compass application does not load website analytics.

Consent and marketing communications

Messages a merchant sends through Compass. Marketing sent through Compass depends on the consent captured and maintained by the merchant, who is the controller for those recipients. Compass includes consent tracking and suppression features designed to support lawful, permission-based sending, and our Acceptable Use Policy sets out what we require of every sender. If you received a message sent through Compass and want it to stop, use the unsubscribe or opt-out mechanism in that message, or contact the merchant who sent it — they control the list.

Messages we send you ourselves. When you request a demo, contact us, or create a workspace, we email you about that request, your account, and the Service. Where you have opted in, we also send occasional marketing email about Compass — product news, releases, and event invitations. Message frequency varies, and consent to marketing email is never a condition of evaluating or using the Service. You can withdraw that consent at any time using the unsubscribe link in any marketing email, or by emailing privacy@compass.st. Opting out of marketing does not stop transactional and service email about your account, billing, security, or support, which we need to send in order to operate the Service. Compass currently sends its own marketing by email only.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise a right relating to data we control, contact us at privacy@compass.st. If your request concerns data a merchant brought into Compass, we will refer you to the relevant merchant, who acts as the controller, and support them in responding.

Retention

We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Merchant customer data is retained according to the merchant’s configuration and instructions; on termination it is deleted or returned as described in our Data Processing Addendum.

Subprocessors

We use a limited set of vendors to help operate the Service, such as infrastructure, email delivery, billing, error monitoring, and analytics providers. Our current list is available on our Subprocessors page, which we update as our vendors change.

Security

Compass runs on Cloudflare infrastructure and uses tenant isolation, encryption in transit and at rest, and access controls to protect data. No system is perfectly secure, but we maintain safeguards designed to protect personal data against unauthorized access, alteration, and loss. You can learn more on our Security page.

International transfers

Compass operates on globally distributed infrastructure, and data may be processed in countries other than your own. Where required, we use appropriate safeguards designed to protect data transferred across borders.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, provide additional notice.

Contact us

Questions about this policy or your data can be sent to privacy@compass.st. You can also reach us through our contact page.