Skip to main content
CI360 by Compass Island

Legal

Privacy policy

Effective August 25, 2026
Last updated August 27, 2026

This policy explains what Compass Island, LLC does with personal data in connection with the CI360 website, and the narrower set of personal data we process for our own purposes as the company behind CI360. It is written to be read, not to be tolerated.

1. Who we are

CI360 is a product of Compass Island, LLC. For the personal data described in this policy, Compass Island, LLC is the data controller and is responsible for how that data is handled.

Compass Island, LLC
808 Lady Street, Suite D #57
Columbia, SC 29201
United States

Privacy questions and requests: privacy@compassisland.co

2. What this policy covers

This policy covers this website and the inquiries people send through it.

It is not the policy that governs operational content inside the CI360 application. The two are separate, and the distinction matters to anyone assessing us as a vendor.

Operational content a customer puts into CI360 — traveler records, itineraries, locations, alerts, messages, check-ins, and the audit trail behind them — is handled on that customer's instructions. For that content Compass Island generally acts as a processor, and what we may do with it is set by the customer's agreement with us and the data processing terms attached to it, not by this policy.

There is a narrower set of information that we process for our own purposes, and there we act as a controller. It covers account administration, the business contact details of the people who administer and use a deployment, billing information, security and service logs generated by running the platform, and support correspondence. This policy describes that processing, along with the website.

We do not claim that a customer is automatically the controller of everything held in the application, and we do not claim that role for ourselves either. Which role applies to a given category of data is set out in the agreement covering that deployment.

3. What we collect

Information you give us. The demo and contact form asks for your first and last name, work email address, organization, what brings you to us, and whether travel data already feeds a system in your environment. If you write to us directly, we hold that correspondence and whatever you choose to put in it.

Technical information. Our web server keeps standard request logs: IP address, browser and device type, the pages requested, the referring page, and a timestamp.

Analytics information, if you accept it. If you accept analytics in the cookie banner, our measurement tools collect the pages you view, how you reached them, approximate location derived from your IP address, browser and device characteristics, and how you interact with a page — clicks, scrolling and mouse movement. Section 5 names the tools and explains what each one does.

Anti-spam signals. The form records how long it was on screen before submission, and it includes a hidden field that a person filling in the form never sees. Both exist to separate people from automated submissions. Neither is used to identify you or to build a profile.

We do not ask for or intentionally seek to collect special category data through this website, we do not profile visitors, and no decision about you is made automatically. Please do not submit sensitive personal information through free-text website forms unless it is necessary for your inquiry.

Separately, we may hold professional contact details obtained from a conference, a referral, a public professional profile, or a business development tool. Where we do, they are held only so that we can get in touch about CI360, and we delete them on request. Where the GDPR or the UK GDPR applies and we obtained your professional contact information from another source, we provide the privacy information required by applicable law within the period that law allows and, where we use the information to contact you, no later than our first communication with you.

4. Why we use it, and our legal basis

Where the GDPR or the UK GDPR applies, these are the purposes and the basis we rely on for each.

Purpose
Legal basis
Responding to a demonstration request or an inquiry, evaluating whether there is a potential customer relationship, and following up appropriately. The person who writes to us is acting for their employer, so we do not rely on steps taken prior to a contract with an individual.
Legitimate interests
Keeping the site available, and preventing spam and abuse.
Legitimate interests
Measuring how the site is used, through Google Analytics 4 and Microsoft Clarity. Neither collects anything until you accept analytics in the cookie banner, and you can withdraw consent at any time.
Consent
Meeting legal, tax and record-keeping obligations.
Legal obligation

Where we rely on legitimate interests, we have weighed our interest in reaching and supporting business customers against your interest in being left alone, and we have kept the data to the minimum that serves the purpose. You can object to that processing; section 10 explains how.

5. Cookies and similar technologies

This site sets no advertising cookies and runs no advertising or retargeting pixels. Nothing beyond the strictly necessary storage below is used unless you accept analytics.

Strictly necessary storage. When you make a choice in the cookie banner, that choice is recorded in your browser so we do not ask again. It holds the choice itself and nothing else — no identifier — and it is not transmitted to us.

Google Analytics 4, with your consent. The Google tag is not loaded until you accept analytics — before that, nothing is stored on your device and nothing is sent to Google. Once you accept, it records page views, referrers, approximate location from a truncated IP address, and device and browser type. Cookies _ga and _ga_<id>, kept up to 24 months. Measurement ID G-1NC42B2KZ5. Google Signals, advertising features, and data sharing for advertising are off.

Microsoft Clarity, with your consent. Clarity is not loaded until you accept analytics. Once loaded, it records clicks, scrolling, and mouse movement. Clarity may create masked session recordings and aggregated interaction heatmaps so we can see where the site is confusing. Form inputs and other designated sensitive content are masked in accordance with our configuration and Microsoft’s masking controls, so the words you type are not captured in a recording — though the fact that you moved through the form is. Cookies _clck and _clsk, kept up to 12 months.

You can change your choice at any time: cookie settings. The same control is in the footer of every page. Choosing essential only, or withdrawing consent later, stops both tools, deletes the cookies they set from your browser, and reloads the page. If your browser sends a Global Privacy Control signal, we treat it as a choice of essential only.

6. Who we share it with

We do not sell personal data, and we do not share it for advertising.

We share it with service providers under written contract — website hosting, email and business communications, and the tools we use to track sales inquiries. Where you consent to analytics, usage information may be disclosed to Google through Google Analytics 4 and to Microsoft through Microsoft Clarity, subject to their respective privacy, data-protection, and service terms. Their roles under data protection law are not identical, and Microsoft does not act solely as our processor for Clarity. We share it with professional advisers, such as our lawyers and accountants, where they need it to advise us. We disclose it to authorities where we are legally required to. And if the business or part of it is ever sold or reorganized, it may pass to the acquirer.

We will name the providers we currently use if you ask.

7. International transfers

Data covered by this policy is stored in the United States.

Where privacy law requires a transfer mechanism for personal data leaving the European Economic Area or the United Kingdom, an appropriate one is used — for example standard contractual clauses, or a provider's certification under a recognized transfer framework. Tell us which transfer you are asking about and we will tell you which mechanism applies to it.

8. How long we keep it

Inquiries and related correspondence that do not lead to a customer relationship: up to 36 months from our last contact with you.

Server logs: up to 12 months.

Analytics data, where you consented: Google Analytics event data up to 14 months. Microsoft Clarity session playback data is generally retained for 30 days; certain aggregated interaction data, heatmap data, and labeled or selected sessions may be retained for up to nine months, subject to Microsoft’s then-current retention practices.

Records we are required to keep for tax or other legal reasons: for the period the law requires.

Data held in a customer's CI360 deployment is retained according to that deployment's configuration and the customer's agreement, not these periods.

9. Security

Traffic to this site is encrypted in transit using TLS. Access to personal data is limited to the people who need it for their work. Those people use individual accounts protected by multi-factor authentication. We collect as little as we can and keep it no longer than we need it.

We describe only the controls we can stand behind. If a security review needs more detail than this, ask and we will answer specifically rather than in general terms.

10. Your rights in the EEA and the UK

If the GDPR or the UK GDPR applies to our processing of your personal data, you have the right to:

ask what we hold about you and get a copy of it

have inaccurate data corrected, and incomplete data completed

have it erased, where we have no overriding reason to keep it

restrict how we use it while a question about it is resolved

object to processing we carry out on the basis of legitimate interests

receive data you gave us in a portable form, where that right applies

withdraw consent at any time, where we rely on consent

Write to privacy@compassisland.co. We answer within one month. There is no charge, and exercising a right will not count against you in any dealing with us. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.

If your request concerns data held inside a customer's CI360 deployment, tell us and we will point you to the organization that controls it, or pass the request on where our agreement with them requires it.

11. California privacy rights

If the CCPA, as amended by the CPRA, applies to us, the following applies to California residents.

The categories of personal information we collect through this site are: identifiers, such as name, email address and IP address; professional and employment information, such as your organization and role; internet activity, from server logs; and the contents of the messages you send us. Why we collect each is set out in section 4.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

You may ask to know what we have collected about you, to have it deleted, and to have inaccurate information corrected. You may make a request through an authorized agent, and we may ask that agent for proof of authority. We will not discriminate against you for exercising any of these rights. Requests go to privacy@compassisland.co.

12. Canada

Under applicable Canadian privacy law, including PIPEDA where it applies, you may ask for access to the personal information we hold about you and challenge its accuracy. Write to us at the address in section 15. If you are not satisfied with how we handle your request, a complaint to the Office of the Privacy Commissioner of Canada may be available to you.

13. Children

CI360 is sold to organizations. This site is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, tell us and we will delete it.

14. Changes to this policy

When this policy changes, we update the date at the top of the page. If a change is material and affects data we already hold, we will tell the people it affects directly, where we have a way to reach them.

15. Contact and complaints

Email privacy@compassisland.co, or write to Compass Island, LLC, 808 Lady Street, Suite D #57, Columbia, SC 29201, United States.

Compass Island, LLC is based in the United States. Where applicable law requires us to appoint a representative in the European Economic Area or the United Kingdom, we will appoint one and publish the details here. Until then, requests come directly to the address above.

If you are in the EEA or the UK, you also have the right to complain to a national data protection authority — in the United Kingdom, the Information Commissioner's Office.

Expanded screenshot
Cookies on this site

We use essential storage by default. With your consent we also use Google Analytics and Microsoft Clarity to measure how the site is used. Neither loads, and nothing is sent, until you accept. Read our privacy policy.