MiraPact
Privacy Notice
Effective August 5, 2026
This notice explains how MiraPact handles information when you use the website, upload a contract, request a review, pay, recover a case, or contact us.
Who controls your information
MiraPact is currently in a non-payment pilot. The legal operator and controller will be identified here before checkout is enabled.
Information we collect
We collect the intake details you provide, such as company, signing location and date, interface language, document mode, and consent records; contact and recovery email when you provide one; technical and security information needed to operate and protect the service; and payment status and provider identifiers. Stripe, not MiraPact, receives your complete card details.
Contracts and review data
Uploaded contracts may contain names, addresses, signatures, contract numbers, financial terms, and other sensitive information. We also create page previews, extracted facts, user corrections, calculations, results, reports, source references, and audit records. Please hide full card, bank, passport, and Social Security numbers when practical. Do not upload documents unless you have permission.
How we use information
We use information to classify supported cases, store and display documents privately, extract and confirm facts, calculate conditional candidate dates and financial scenarios through deterministic rules, prepare and deliver requested reviews, process payments and refunds, recover access, respond to support, prevent abuse, secure the service, comply with law, and improve reliability using de-identified or low-risk operational measurements.
Service providers and disclosures
We disclose only what is reasonably needed to providers that operate the service, including Vercel for hosting and private file storage, Neon for the database, OpenAI when AI analysis is enabled, Stripe for payment, and Resend for recovery or status email. We may also disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards. Providers process information under their own terms and our configuration.
AI processing
When AI analysis is enabled, MiraPact sends only selected relevant pages or derived content to the OpenAI API, uses server-side access, requests non-persistent response storage where supported, and deletes provider files when technically available. OpenAI states that API data is not used to train its models unless the API customer opts in. Standard abuse-monitoring logs may retain customer content for up to 30 days, subject to OpenAI's policies, legal requirements, and available data controls. AI output can be wrong and is reviewed against cited evidence.
No sale of information or leads
MiraPact does not sell customer documents, personal information, or customer leads, and does not disclose them for cross-context behavioral advertising. We do not send your contract or contact details to HGV, a timeshare seller, an exit company, a courier, or a lawyer unless you separately and explicitly authorize a future service that identifies the recipient and purpose.
Retention and deletion
Raw documents for unfinished and free cases are scheduled for deletion seven days after the last relevant activity or result, unless you delete sooner. For a paid case, raw documents are scheduled for deletion seven days after report publication or any included support period, whichever is later, with a 30-day maximum unless you explicitly approve a longer period for a specific service. Reports and structured case data are retained for up to 90 days by default. Limited payment, fraud-prevention, security, deletion-receipt, and legal records may be kept longer when reasonably required. Provider backups or abuse-monitoring records may follow the provider's separate deletion cycle.
Your choices and requests
You can view source documents and saved results through your secure case, correct displayed facts, delete documents and case data through the visible deletion control, or ask us to review, correct, or delete information by email. We verify control of the case or email before revealing or changing sensitive information. Some limited records may remain where law, payment reconciliation, security, or fraud prevention requires them.
Colombian data-subject rights
When Colombian data-protection law applies, the data subject may ask to know, update, correct, or delete personal data; request proof of authorization; obtain information about use; complain to the Superintendence of Industry and Commerce after completing the applicable direct-request process; and revoke authorization when legally permitted. Use privacy@getmirapact.com. We will verify identity or control of the case and respond under the applicable procedure and time limits.
Cookies, analytics, and browser signals
MiraPact uses first-party cookies or similar tokens for language choice, secure case access, authentication, and abuse prevention. We do not use advertising cookies or invasive third-party device fingerprinting. If product analytics is enabled, sensitive case pages exclude document text, names, addresses, contract numbers, case identifiers, and secret file URLs. We do not currently respond differently to Do Not Track signals because we do not use cross-site advertising tracking.
International users
The service is operated using providers that may process information in the United States and other countries. Those locations may have different privacy laws from your home country. By using the service, you understand that information will be processed where MiraPact and its providers operate, subject to this notice and applicable law.
Security
We use private file access, scoped upload authorization, encrypted HTTPS transport, access controls, secret management, file validation, retention limits, and audit events designed to protect sensitive information. No internet service can guarantee absolute security. Contact us immediately if you believe a case or recovery link has been exposed.
Age requirement
MiraPact is not directed to children. You must be at least 18 to create a case or upload documents. We do not knowingly collect information from children under 13.
Changes to this notice
We may update this notice as the service or law changes. We will post the revised effective date and provide additional notice when a change materially affects how existing sensitive information is used.
Contact and Nevada privacy requests
Email us to ask what covered information we hold, request correction or deletion, or raise a privacy concern. MiraPact does not sell covered information, so there is no sale to opt out of at launch.