Skip to content

Privacy Policy

Corply Privacy Policy

Last updated: September 25, 2026

Corply handles sensitive founder, company, filing, payment, and document information. This policy explains what we collect, why we use it, when we share it, and how founders can make privacy requests.

Important Summary

  • We use founder and company information to provide incorporation, filing, document, approval, payment, support, security, and company record workflows.
  • We do not sell personal information.
  • We do not use customer company data, founder documents, or uploaded records to train AI models.
  • We share information with service providers and workflow participants only when needed to operate Corply, complete authorized workflows, comply with law, or protect the service.
  • Payments for Corply's own charges are entered on Stripe's secure checkout page. For accounts billed through Corply Pay, Corply's payment software, card details are entered into secure payment fields provided by Finix, our card processor, and bank details into a secure bank form provided by Payabli, our bank (ACH) processor. These processors collect and store full card numbers, card security codes, and bank account numbers; Corply does not receive or store them.
  • Corply Cards are issued by a sponsor bank through Lithic, our card-issuing processor. Full card numbers and security codes are shown only in Lithic's secure card frame; Corply does not store them.
  • Formation workflows can require sensitive information. Do not upload anything you are not authorized to provide.

1. Scope

This Privacy Policy explains how 0Lumen Labs Corp. d/b/a Corply collects, uses, discloses, retains, and protects information when you visit our websites, create an account, use Corply products, communicate with us, or authorize company formation, filing, document, approval, payment, or support workflows.

This policy applies to Corply's services. It does not apply to websites, portals, banks, registered agents, government agencies, payment processors, identity providers, attorneys, accountants, or other third-party services that operate under their own privacy policies.

2. Information We Collect

  • Account and contact information, including name, email address, phone number, login metadata, team membership, role, and support communications.
  • Founder and company information, including proposed company names, entity details, addresses, founder names, ownership details, equity context, officer/director/incorporator information, tax and filing facts, and workflow instructions.
  • Documents and records you provide or generate, including formation documents, founder approvals, signatures, uploaded files, generated drafts, filing evidence, receipts, audit logs, and company memory records.
  • Payment and billing records, including Corply Pay checkout, payment, receipt-number, renewal-schedule, invoice, refund, dispute, and bank-return records and the related processor reference identifiers (such as Finix transfer, identity, and payment-instrument identifiers and Payabli transaction, customer, and stored-method identifiers); payment-method type and, when the processor provides them, card brand, card funding type, expiration, and last four digits, or bank name, account type, and last four digits; order amount and currency; billing status; your registered-agent renewal choice; authorization evidence, including the authorization text you accepted (for bank payments, Corply's ACH debit authorization), when you accepted it, the Terms and Billing & Refund Policy versions in effect, and the IP address and browser user agent used; receipts; and limited payment metadata. Card details are entered into secure payment fields provided by Finix and bank details into a secure bank form provided by Payabli, which send them directly to those processors. The processors collect and store full card numbers, card security codes, and full bank account numbers. Corply does not receive or store those full card credentials or full bank account numbers. For payments processed by Stripe, Corply keeps the Stripe customer, Checkout, PaymentIntent, subscription, invoice, refund, and dispute identifiers and descriptors it records.
  • Bank account details for ACH payments. You never give Corply your bank login credentials, and Corply does not request your account balances or transaction history. When you enter a bank account in Payabli's secure form, Payabli may check that it is a valid, open U.S. account that can accept debits. Corply keeps its own record of the ACH debit authorization you accepted, including when you accepted it and the IP address and browser user agent used.
  • Corply Pay payment requests. If your company uses Corply Pay to send invoices, payment requests, or reimbursement requests, we process the request details you enter (such as the payer's name, email address, and organization, line items, memo, and expense details), the payer's payment status and receipt, and the software fee, gross, and net amounts of each payment. Payers enter card or bank details only in the processors' secure fields. To receive payments, your company completes the processors' own onboarding (identity, ownership, and payout bank account verification), which Finix and Payabli collect under their own terms and privacy policies; Corply keeps the resulting onboarding status, processor references, and the last four digits of the payout account.
  • Corply Cards. If your company uses Corply Cards, we process the cardholder's name and email address, card nickname, type, state, spending limits and controls, the last four digits and expiration of each card, card transaction details (such as amount, status, merchant name, merchant category code, city, and country), and a record of each time a card's full details are viewed. Lithic and the sponsor bank that issues the cards process card data and any account-holder information they require under their own terms and privacy policies. Full card numbers and security codes appear only in Lithic's secure card frame, only on the web, and Corply does not store them.
  • Usage, device, and security information, including IP address, browser type, device identifiers, session data, pages viewed, product events, error logs, authentication events, and anti-abuse signals.
  • AI and automation workflow inputs and outputs, including prompts, extracted facts, summaries, generated drafts, task state, review notes, and operational decisions needed to provide the service.

3. Sources of Information

We collect information directly from you, from other users who invite you or act for the same company, from product usage, from documents you upload, from service providers that support approved workflows, and from public or government sources when needed to complete or verify company workflows.

4. How We Use Information

  • Provide, operate, personalize, and improve Corply.
  • Prepare, route, review, submit, track, and store company formation, filing, approval, document, registered-agent, EIN, compliance, payment, and support workflows you request or authorize.
  • Maintain company records, audit trails, receipts, evidence, deadlines, and workflow history.
  • Authenticate users, administer accounts, manage access, prevent fraud and abuse, debug issues, monitor reliability, and protect security.
  • Communicate about account activity, support requests, approvals, filings, payments, purchase acknowledgments, renewal reminders and approvals, billing confirmations, policy changes, security notices, and service updates.
  • Analyze product usage and business performance. Where analytics is enabled, product events may be associated with your account identifier, email address, and profile information. We also use aggregated usage reports.
  • Comply with legal obligations, enforce our Terms of Use, respond to lawful requests, and protect Corply, users, third parties, and the public.

5. AI Providers and Model Training

Corply may use AI providers and automation systems to draft, extract, summarize, classify, check, route, and suggest actions. We use those systems to provide the product and operate approved workflows.

We do not use customer company data, founder documents, uploaded records, or private workflow content to train Corply foundation models or third-party foundation models. When we use AI vendors, we configure and contract for business use cases where customer content is not used to train vendor models.

AI outputs can be incomplete or wrong. Privacy protections do not change your responsibility to review documents, facts, filings, approvals, and instructions before relying on them.

If you connect Corply to an AI agent you choose, that agent's provider processes your conversation and information returned to it under its own terms and your account settings. Corply does not control that provider's independent data-use or model-training settings.

6. How We Share Information

  • With service providers that host, secure, analyze, support, or operate Corply, including cloud infrastructure, databases, authentication, payments, email, logging, customer support, analytics, and AI providers.
  • With our payment processors: Stripe, which processes Corply's own charges, and, for accounts billed through Corply Pay, Finix, which processes card payments, and Payabli, which processes U.S. bank (ACH) payments. We share the information needed to process and authenticate payments, validate bank accounts, keep payment methods on file at your direction for the renewal and approval choices described in our Billing & Refund Policy, onboard companies that use Corply Pay to receive payments, pay partner commissions, issue refunds, prevent fraud, and manage disputes and bank returns. Stripe, Finix and Payabli process payment information under their own terms and privacy policies and may process it in the United States and other jurisdictions where they or their providers operate.
  • With Lithic, which processes Corply Cards, and the sponsor bank that issues them, to set up the card program, issue and manage cards, authorize and record card transactions, show full card details in Lithic's secure frame, and prevent fraud. Lithic and the sponsor bank process this information under their own terms and privacy policies.
  • With workflow participants you authorize or that are necessary for an approved workflow, including cofounders, company admins, signers, registered agents, filing providers, government agencies, payment processors, banks, counsel, accountants, or other third parties you involve.
  • With other users connected to the same company or workspace, according to product permissions and company administration needs.
  • With authorities, courts, regulators, or other parties when we believe disclosure is required by law, necessary to protect rights or safety, or needed to investigate fraud, security, abuse, or policy violations.
  • In connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to appropriate confidentiality protections.

7. No Sale of Personal Information

We do not sell personal information. We also do not share personal information for cross-context behavioral advertising as those terms are commonly used under U.S. state privacy laws.

8. Cookies and Similar Technologies

We use cookies and similar technologies for authentication, session management, security, fraud prevention, preferences, analytics, and product reliability. You can control cookies through your browser settings, but disabling cookies may prevent parts of Corply from working.

Our website includes Google Analytics and PostHog integrations. Where enabled, PostHog can associate activity with signed-in accounts and record sessions for product reliability. The integration includes input masking, sensitive-content masking, and exclusions for designated sensitive routes; these controls do not make all analytics anonymous.

On payment pages, Stripe's hosted checkout page and the Finix and Payabli payment fields are controlled by those processors, and on Corply Cards pages the Lithic card frame does the same. They may use their own cookies and device signals to process payments and prevent fraud under their own privacy policies. Corply's session recordings do not capture the contents of those frames.

9. Retention

We retain information for as long as needed to provide Corply, maintain company records and audit trails, comply with legal and tax obligations, resolve disputes, enforce agreements, protect security, and operate our business.

Company formation and approval records may be retained longer than ordinary account data because founders, companies, investors, banks, accountants, counsel, and diligence reviewers may later need evidence of what was approved, signed, filed, paid, or received.

We retain payment processor identifiers (Stripe, Finix and Payabli), order and authorization evidence, receipts, refund, dispute, and bank-return records, and limited payment-method descriptors as needed for accounting, tax, fraud prevention, customer support, legal claims, and audit obligations. Billing authorization records, including renewal choices, renewal approvals, cancellations, and ACH debit authorizations, are kept while the authorization is in effect and afterward for as long as payment-network, Nacha, bank, and dispute rules require. Removing a saved payment method does not require deletion of transaction records we must retain, and Corply cannot delete information retained independently by Finix, Payabli, Lithic, a sponsor bank, or Stripe under their own policies or legal obligations.

10. Security

We use technical, organizational, and administrative safeguards designed to protect information, including access controls, encryption in transit, cloud security controls, logging, and least-privilege operational practices.

No system is perfectly secure. You are responsible for protecting your credentials, limiting access to your account, reviewing invited users, and maintaining your own copies of important company documents.

11. International Users

Corply is operated from the United States and is built for U.S.-connected company workflows. If you use Corply from outside the United States, you understand that your information may be processed in the United States and other jurisdictions where our providers operate.

12. Privacy Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain personal information, or to object to certain processing. These rights may be limited where information is needed for company records, legal obligations, security, fraud prevention, or completed workflows.

To make a privacy request, email founders@0lumens.com with the subject line Privacy Request and include the email address connected to your Corply account. We may need to verify your identity and authority before acting on a request.

13. Children

Corply is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information to Corply, contact us so we can review and delete it where appropriate.

14. Changes

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new last updated date. If changes are material, we may provide additional notice through the product or by email.

15. Contact

For privacy questions or requests, contact founders@0lumens.com.