Skip to content
OrgStatistics
  • Features
    • Org BoardEvery division, department and post on one living chart.
    • StatisticsGraphs for every post, with targets, notes and trends.
    • Policies, SOPs & ChecklistsWrite down how the work is done, once, and attach it to the post.
    • TrainingCourses built from your own SOPs, policies and checklists.
    • GlossaryYour words, defined once and linked everywhere.
    • EthicsCodes of conduct that people read and acknowledge.
    • Routing FormsStep-by-step sign-offs with a locked, printable record.
    All features →
  • Statistics
  • Pricing
  • Contact
Sign inGet started
  • Org Board
  • Statistics
  • Policies, SOPs & Checklists
  • Training
  • Glossary
  • Ethics
  • Routing Forms
  • All features
  • Pricing
  • Contact
  • Sign in
Get started

Last updated September 25, 2026

Privacy Policy

This policy explains what personal data OrgStatistics collects on this website and in the OrgStatistics app, why we collect it, and the choices you have. We have tried to keep it short and plain.

On this page

  1. Who we are
  2. The short version
  3. This website
  4. Cookies and analytics
  5. The OrgStatistics app
  6. Content your company adds
  7. Invitations and email
  8. AI features
  9. Who we share data with
  10. How and why we use data
  11. Security
  12. How long we keep data
  13. Your rights
  14. Children
  15. Changes to this policy
  16. Contact us

Who we are

OrgStatistics runs this website (orgstatistics.com) and the OrgStatistics app at app.orgstatistics.com. In this policy, "we", "us" and "our" mean OrgStatistics. "You" means anyone who visits the website or uses the app.

The app helps companies build an org board, track statistics, and keep their policies, procedures, checklists, training, glossary, ethics records and routing forms in one place. A company that signs up is our "customer". The people it invites into its workspace are "users".

The short version

  • We collect what we need to run the website and the app, and nothing more on purpose.
  • We do not sell personal data. We do not share it for advertising.
  • The content a company puts in its workspace belongs to that company. We process it for them.
  • AI features only run when a user clicks an AI button. Then only the text for that task goes to our AI provider.
  • Analytics on this website are optional. In Europe they stay off unless you accept.

This website

When you contact us

If you use the contact form, we receive your name, email address, company name if you give it, the topic you pick, and your message. The form sends this to us as an email through Mailgun, our email provider. We use it to reply to you. We do not add you to a mailing list.

Technical data

This website runs on Cloudflare's network. To deliver pages and protect the site from abuse, Cloudflare processes technical request data such as your IP address, browser type, and the pages you ask for. This site does not use advertising trackers. It uses one optional analytics service, described below.

Cookies and analytics

This site uses one optional service: Cloudflare Web Analytics. It tells us how many people visit each page, which site sent them, their browser and device type, their country, and how fast the page loaded. Cloudflare says the service does not use cookies, local storage, or fingerprinting to track visitors. Cloudflare processes this data for us under its privacy policy. We do not sell it, share it for advertising, or use it to identify you.

Whether analytics start before you choose depends on where you visit from. When a page loads, it asks our server which rule applies. Our website runs on Cloudflare's network, which works out your country from your IP address. Our server code returns only the rule and does not store or log your country.

  • Europe — the European Union, the European Economic Area, the United Kingdom, Switzerland, their overseas territories, Jersey, Guernsey, the Isle of Man, Andorra, Monaco, San Marino, and Vatican City: analytics stay off until you choose Accept analytics. We use the same rule if we cannot tell where you are, if the check fails, or if your browser blocks site storage.
  • Everywhere else: analytics are on by default. First, the page checks that your browser can remember a choice to turn them off, by saving a test value and deleting it straight away; if it cannot, analytics stay off. Keep analytics on, or closing the notice, keeps that default while you visit from outside Europe; if you later visit from Europe, we ask you. Choose Turn off analytics in the notice, or use Cookie settings, to switch analytics off wherever you are.
  • Global Privacy Control: if your browser sends this signal, analytics stay off until you turn them on, wherever you are. If you allowed analytics before your browser started sending the signal, we ask again.

Reject, Turn off analytics, and closing the notice in Europe all keep analytics off, wherever you visit from later. You can reopen here or from the footer of any page to change your choice at any time. If you turn analytics off after they started, the page reloads so they stop. Closing the settings window without saving keeps your existing choice.

After you make a choice or close the notice, we store orgstatistics.cookie-consent in your browser's local storage. The record contains your choice, the services you allowed, whether your browser sent Global Privacy Control, the notice version, and save and expiry times. A choice counts for 180 days; after that we ask again and delete the old record the next time you visit. It is stored on your device, is not sent to us by the consent tool, and is not used as a tracking identifier. Preferences apply to the current site hostname and browser; another device or hostname may ask again. If your browser blocks site storage, analytics are off by default and a choice you make applies to the current page only.

Necessary technologies are separate. Cloudflare may set security cookies before the page or notice loads; the notice does not block or delete these. When you sign in to the app, it keeps a sign-in session in your browser so you stay signed in. These are needed for the site and the app to work and are not used to track you. If you use the light / dark switch, we save your choice as orgstatistics.theme in your browser's local storage so the next page opens in the same theme; it never leaves your device. Your browser's cookie controls can restrict cookies more broadly, though that may stop a security check or sign-in from working. We will update this notice and ask again before we add another optional service.

The OrgStatistics app

When you create an account or are invited to a workspace, we store:

  • Account details: your email address and name. If you set a password, it is stored only in hashed form.
  • Workspace details: the workspaces you belong to and your role in each one.
  • Basic activity data: what is needed to run and secure the service, such as when you last signed in.
  • Technical data: IP address, browser type and request logs, used to deliver the app, fix problems, and stop abuse.

App data is stored in a Supabase and Postgres database on a server we run ourselves, not in a shared third-party database service.

Content your company adds

Customers put their own content into the app: org boards, posts and the names of the people who hold them, statistics, policies and procedures, checklists, training records, glossary terms, ethics records, and routing form entries. This content often includes personal data about the customer's employees and contractors.

For this content, the customer is the controller and we are its processor. That means the customer decides what goes in, who can see it, and how long it stays. We process it only to provide the app to that customer and as the customer instructs. We do not use it for our own purposes, and we do not use it to train AI models.

If you are an employee and your company uses OrgStatistics, please send questions or requests about your data to your company first. If you contact us, we will pass your request to the customer and help them answer it.

Customers should not add sensitive data they do not need, such as health details, to the app. If they do, they are responsible for having a lawful reason to do so.

Invitations and email

The app sends email through Mailgun. This includes invitations, sign-in and password emails, and notices about your account or workspace. When a workspace admin invites someone, we use the email address they enter to send that person an invitation. Mailgun processes the recipient's address, the message, and delivery data such as whether it arrived, so the email can be delivered.

AI features

Some features can use artificial intelligence, for example to help draft a policy. These features are off unless a customer connects its own account with an AI provider by adding its own API key.

  • When someone uses an AI feature, the content needed for that request is sent to the provider the customer chose.
  • That provider handles the content under the customer's own agreement with it. Its terms and privacy policy apply, not ours.
  • We store the key only to make those requests for that workspace. We do not use it for anything else.
  • If no key is connected, no workspace content is sent to any AI provider.

Who we share data with

We use a small number of service providers. They process data for us and only as needed to do their job:

  • Cloudflare — hosting, network delivery, security, and optional website analytics.
  • Mailgun — sending email from the app and the contact form.
  • OpenRouter and the AI model provider it routes to (OpenAI) — only the text for an AI task a user starts.

We may also share data if the law requires it, to protect our rights or the safety of others, or as part of a merger or sale of the business. In a sale, this policy would continue to apply to your data.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Some providers may process data outside your country, including in the United States. Where the law requires it, we use appropriate safeguards for these transfers.

How and why we use data

We use personal data to:

  • provide the app and the features a customer turns on;
  • create and secure accounts, and send service emails;
  • answer messages and support requests;
  • understand, in aggregate, how the website is used, if analytics are allowed;
  • prevent abuse and fraud, and meet legal duties.

If you are in Europe or the UK, our legal bases are: to perform our contract with you or your company; our legitimate interests in running, securing and improving the service; your consent, for optional analytics; and legal obligations. You can withdraw consent at any time.

Security

We send data over encrypted connections (HTTPS). Access inside a workspace follows the roles the customer sets. Access to our systems is limited to people who need it to run the service. No system is perfectly secure. If a breach affects your personal data, we will tell the affected customers, and you where the law requires it.

How long we keep data

  • Accounts and workspace content: for as long as the account or workspace is active. When a customer deletes content or closes a workspace, we delete it from the live system, and copies in backups are removed as those backups expire.
  • Contact form messages: as long as needed to answer you and handle any follow-up.
  • Technical logs: for a limited time, to keep the service running and secure.
  • Your analytics choice: in your own browser, for 180 days, as described above.

We may keep some records longer if the law requires it.

Your rights

Depending on where you live, you may have the right to:

  • see the personal data we hold about you and get a copy;
  • correct data that is wrong;
  • have your data deleted;
  • limit or object to how we use it;
  • receive your data in a portable format;
  • withdraw consent you gave, without affecting what happened before.

Europe and the UK: these rights come from the GDPR and the UK GDPR. You can also complain to your local data protection authority.

California and other US states: you can ask what personal data we collect and how we use it, and ask us to correct or delete it. We do not sell or share personal data, so there is nothing to opt out of. We will not treat you differently for using these rights. We honour Global Privacy Control as described above.

To use any of these rights, contact us. We may need to confirm your identity first. We will answer within the time the law requires. If your request is about content in a customer's workspace, we will pass it to that customer, because they control that data.

Children

OrgStatistics is a tool for businesses. It is not meant for children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, please contact us and we will delete it.

Changes to this policy

We may update this policy as the website and app change. The date at the top shows the current version. If a change is significant, we will tell customers by email or in the app before it takes effect.

Contact us

Questions about this policy or your data? Use our contact form and choose "Question" as the topic. See also our Terms of Service.

Put your company on one board.
Then watch it grow.

Get started →See pricing
OrgStatistics
Org BoardStatisticsPolicies, SOPs & ChecklistsTrainingGlossaryEthicsRouting Forms
All featuresPricingContactPrivacy PolicyTerms of Service

© 2026 OrgStatistics