Información legal
Política de privacidad
Última actualización August 2026.
01Who we are
Compliant Park is a product of Quiet Park Media. We provide a compliance record-keeping service for food-service businesses. This policy explains what we collect, why, and what you can ask us to do with it.
02What we collect
Cuenta information. Su nombre, business name, email address, a hashed password, and your language preference. We never store your password in a readable form.
Location information. The businesses you attach to your account, including the public permit identifier (CAMIS), address, and the published inspection record we retrieve for them.
Records you create. Compliance items, notes, due dates, inspection-visit logs, and walk completions that you enter.
Files you upload. Documentars such as service reports, certificates, insurance and photographs, with any title, vendor, issue date and expiry date you record.
Usage and security data. Actuarivity within your account, and failed sign-in attempts with the originating IP address, kept for up to 24 hours solely to block password guessing.
Payment information. When paid plans are enabled, card details are handled entirely by our payment processor. We never receive or store your card number.
03Public data
Inspection results, grades, scores and violation codes are public records published by the New York City Department of Health and Mental Hygiene through NYC Open Data. We retrieve and display that information; we do not create it and cannot change it. Where a public record is missing, we say so rather than inferring a value.
04How we use it
To operate your account and show your record. To estimate inspection windows from published cycle rules. To store and return the files you upload. To secure the service. To contact you about your account or a service issue.
We do not sell your data. We do not share it with advertisers. We do not use your private records to build a product for anyone else.
05Who else touches it
Hosting. The application and database run on our web host's infrastructure.
Payments. When paid plans are enabled, a payment processor handles the transaction.
Public data sources. We request records from NYC Open Data. Those requests identify this application, not you.
We do not otherwise disclose your information except where legally required.
06How it is protected
Traffic is encrypted with HTTPS under a strict transport policy. Passwords are hashed. Session cookies are HTTP-only, same-site and secure.
Uploaded documents are stored outside the public web root and never given a public URL. Every request for a file checks that it belongs to a location on your account.
Sign-in attempts are rate-limited by account and by network address. Administrative actions are recorded in an audit log.
No system is perfect. If we become aware of a breach affecting your information, we will tell you.
07How long we keep it
Cuenta and location records are kept while your account is open. Removing a location deletes its records, violations, activity and uploaded files immediately, including the files on disk.
Security logs of failed sign-ins are discarded after 24 hours. Audit records of administrative actions are retained for accountability.
You can ask us to close your account and delete your data.
08Your rights
You may ask for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live you may have further rights under laws such as the GDPR or the CCPA, including the right to object to certain processing and not to be discriminated against for exercising them.
We do not sell personal information.
10Changes
If we change this policy we will update the date shown and, for material changes, tell account holders directly.
This describes how the service works today. It is not a substitute for advice from your own attorney about your business.