1. Overview

The Legal Pass ("we," "us," or "our") operates the website located at hesspass.com (the "Site"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using the Site, you agree to the practices described here. If you do not agree, please discontinue use of the Site.

We are not a law firm and do not provide legal advice. This Privacy Policy does not create an attorney-client relationship.

2. Information We Collect

a. Information You Provide Directly

When you submit a contact form, request a document, or sign up for updates, we may collect:

  • Your name and email address
  • The nature of your inquiry or document request
  • Any other information you voluntarily provide in message fields
  • We collect only what you choose to give us. No form on this Site requires a Social Security number, financial account number, or other sensitive personal data.

    b. Information Collected Automatically

    When you visit the Site, our service providers automatically receive standard browser and device information, including:

  • IP address (anonymized where possible)
  • Browser type and version
  • Operating system
  • Referring URL and pages visited on this Site
  • Date and time of your visit
  • General geographic region (country/state level)
  • This data is collected in aggregate and is used solely for site performance, security, and analytics.

    c. Information Collected via Supabase

    We use Supabase (supabase.com) as our backend database and authentication platform. If you create an account or submit data through the Site, that information is stored securely in a Supabase-hosted database. Supabase processes data in accordance with its own Privacy Policy and employs industry-standard encryption (TLS in transit, AES-256 at rest).

    We do not store payment card data. Any purchases made through affiliated third-party legal platforms are processed entirely by those platforms under their own privacy and security policies.

    3. Cookies & Tracking Technologies

    We use the following types of cookies and similar tracking technologies on the Site:

    Strictly Necessary Cookies

    These cookies are required for the Site to function and cannot be disabled. They include session cookies that keep you logged in and security tokens that protect against cross-site request forgery.

    Analytics Cookies

    We may use analytics services (such as Google Analytics) that set cookies to help us understand how visitors interact with the Site — which pages are most visited, how long users stay, and where they navigate from. This data is aggregated and anonymized. You may opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on.

    Advertising Cookies (Google AdSense)

    This Site participates in the Google AdSense program. Google and its advertising partners may use cookies, web beacons, and similar technologies to serve ads based on your prior visits to this Site and other websites across the internet. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our Site and/or other sites on the internet.

    You may opt out of personalized advertising by visiting Google's Ads Settings at https://adssettings.google.com or by visiting the Network Advertising Initiative opt-out page at https://optout.networkadvertising.org. Opting out does not remove ads from the Site; it means ads you see may be less relevant to your interests.

    For California residents, see Section 8 (Your California Privacy Rights) below.

    Managing Cookies

    Most browsers allow you to refuse or delete cookies through their settings menus. Disabling cookies may affect certain Site functionality. Please refer to your browser's help documentation for instructions.

    4. How We Use Your Information

    We use the information we collect to:

  • Respond to your inquiries and deliver requested documents or services
  • Maintain and improve the technical performance of the Site
  • Detect and prevent fraud, spam, and security threats
  • Display advertisements through Google AdSense (see Section 3)
  • Comply with applicable law and legal process
  • Send you transactional or service-related communications (not marketing, unless you opt in)
  • We do not use your information to build advertising profiles, sell data, or engage in automated decision-making that produces legal or significant effects on you.

    5. Affiliate Relationships & Third-Party Links

    The Legal Pass earns compensation when users click on links to affiliated legal-services platforms and complete a qualifying transaction. These affiliate relationships do not influence the editorial integrity of our content — we only recommend platforms we have independently reviewed.

    When you click an affiliate link, you will leave this Site and be subject to the destination platform's privacy policy, terms of service, and data practices. We are not responsible for the privacy practices of third-party websites. We encourage you to read the privacy policy of any site you visit.

    Current affiliate categories include online legal document platforms, registered agent services, and attorney-matching networks operating in the United States.

    6. Information Sharing & Disclosure

    We do not sell, rent, or trade your personal information. We may share information only in the following limited circumstances:

  • Service Providers: We share data with trusted vendors (e.g., Supabase, Google Analytics, Google AdSense, email delivery providers) that process data on our behalf under contractual obligations to protect your information and use it only for the services they provide to us.
  • Legal Requirements: We may disclose information if required by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, prevent fraud, or protect the safety of users or the public.
  • Business Transfers: In the event of a merger, acquisition, or sale of substantially all of our assets, user data may be transferred as part of that transaction. We will notify you via prominent notice on the Site before your information becomes subject to a different privacy policy.
  • In all cases, we disclose only the minimum information necessary.

    7. Data Retention

    We retain personal information for as long as necessary to fulfill the purposes described in this policy, or as required by law. Form submissions and account data are retained for up to 24 months after your last interaction with the Site. You may request earlier deletion at any time (see Section 9).

    Anonymized, aggregated analytics data (which cannot identify you) may be retained indefinitely to improve the Site.

    8. Your California Privacy Rights (CCPA / CPRA)

    If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You may request a list of the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources of that information, our business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request that we delete personal information we hold about you, subject to certain exceptions (e.g., information we are required to retain by law).
  • Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do share data with advertising partners (Google AdSense) for targeted advertising purposes, which may be treated as "sharing" under the CPRA. To opt out, use the AdSense opt-out link in Section 3 or contact us at the address below.
  • Right to Non-Discrimination: We will not deny you services, charge you different prices, or provide a lower quality of service because you exercised any of the rights listed here.
  • To exercise your rights, submit a request to: [email protected]. We will respond within 45 days. We may need to verify your identity before processing your request.

    9. Your Rights & Choices (All Users)

    Regardless of your location, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal-retention obligations).
  • Portability: Request your data in a structured, machine-readable format.
  • Opt-Out of Marketing: Unsubscribe from any marketing emails at any time using the unsubscribe link in each message.
  • To submit a request, email [email protected] with the subject line "Privacy Request." We will acknowledge your request within 10 business days and respond substantively within 30 days.

    10. Children's Privacy

    This Site is intended for general audiences and is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at [email protected] and we will delete such data.

    11. Data Security

    We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include TLS encryption for all data in transit, AES-256 encryption for data at rest within Supabase, access controls limiting who can view stored data, and regular security reviews.

    No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

    12. Changes to This Policy

    We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. If changes are material, we will provide additional notice (e.g., a banner on the Site). Your continued use of the Site after the effective date of any update constitutes your acceptance of the revised policy.

    13. Contact Us

    If you have questions, concerns, or requests related to this Privacy Policy, please contact us:

    The Legal Pass Privacy Officer Email: [email protected] Website: hesspass.com/contact Phoenix, Arizona, United States

    We will respond to all privacy inquiries within 10 business days.

    Questions or Concerns?

    We take your privacy seriously.

    If you have any questions about this policy, want to exercise your data rights, or need to report a concern, please reach out. We respond within 10 business days.