Legal
Privacy notice
Effective August 19, 2026
- Version
- 2026-08-19
- SHA-256
- 7789f00b7e391804972ae239394a11e81c9dd6897c9fd5c488478e901309c6de
BetterDocket is operated by Product Advantage LLC, a Delaware limited liability company doing business as BetterDocket ("we," "us").
This notice is in three parts, because our role is not the same everywhere:
- Part 1 — Our website and marketing. We decide what happens here, so we are the controller. Your privacy choices live in this part.
- Part 2 — The BetterDocket product. The law firm decides what happens here. The firm is the controller and we are its processor.
- Part 3 — People we deal with directly. Account, support, subscription, and feedback records. We are the controller.
If you are a client of a law firm that uses BetterDocket, Part 2 is the part that applies to your case information, and your law firm — not BetterDocket — is the one to contact about it.
Part 1 — Our website and marketing
This part covers betterdocket.com, including the request-access form. We are the controller for everything in this part.
What we collect
- Information you provide. A demo or access request may include your name, work email, firm name, role, firm website, phone number, and anything you include in the optional note.
- Website and performance information. Vercel provides hosting, privacy-oriented website analytics, and performance measurements that help us understand site usage and reliability.
- Product analytics and session replay. PostHog records page paths, selected actions, device and runtime categories, and account identifiers. Session replay records this website's pages as they appeared to you. Those pages are our own published marketing material and contain no case, client, or user information, so they are recorded as themselves. Anything you type into a form on this website is masked in your browser before the recording is sent — replay shows that a field was filled, not what you put in it.
- Who you are, in our analytics. If you submit a demo or access request, we send your name and work email to PostHog so that the visit is attributed to you rather than to an anonymous identifier. Nothing else you type on the form — your phone number, firm website, or note — is sent there.
- Error reports. When the site or application fails, Sentry receives the error message, the stack trace, and the page address with record identifiers replaced by a placeholder. Session replay is not enabled in Sentry, and request bodies, cookies, request headers, query strings, and the text of anything clicked or typed are removed before a report is sent.
How we use it
We use this information to respond to requests, operate and secure the website, understand which firms may be interested in BetterDocket, improve our marketing and product decisions, understand feature adoption and usability, and communicate with people who ask to hear from us. Every marketing email we send includes a working unsubscribe link and our postal address.
Sale and sharing
We do not sell personal information or share it for cross-context behavioral advertising. We do not use information held in the BetterDocket product for advertising.
We do not knowingly sell or share the personal information of anyone under 16.
Who we disclose it to
Vercel, PostHog, Sentry, and our infrastructure providers.
Cookies and choices
PostHog analytics and session replay are enabled by default on BetterDocket's production website and applications. PostHog may use first-party cookies or local storage to maintain a session and connect activity across BetterDocket subdomains; native application sessions are connected after sign-in.
A session is pseudonymous until you identify yourself — by submitting a demo request or by signing in. From that point the session is associated with your name and email address in PostHog, and a session that began before you signed in is connected to that record.
Discontinued visitor identification
BetterDocket stopped using RB2B/Retention.com for website visitor identification on August 12, 2026. We removed its script and no longer collect or disclose website activity through that service. Cookies set by the former integration are no longer used by BetterDocket and may remain in a visitor's browser until they expire naturally.
Removing the integration did not recall records already delivered to BetterDocket, Slack or Teams, RB2B, or other parties. To request suppression or deletion of information RB2B/Retention.com already holds, use Retention.com’s opt-out form. Our privacy-choices page provides additional request links.
Part 2 — The BetterDocket product
This part covers the BetterDocket firm application and the client portal.
The law firm is the controller. We are its processor and service provider. We process case, client, document, and message information only on the firm's instructions under our Terms of Service and our Data Processing Agreement.
If you are a client of a law firm using BetterDocket: that firm — not BetterDocket — decides what information is in your portal and how long it is kept. Direct access, correction, and deletion requests to your law firm. If you contact us, we will refer you to the firm.
What the product holds
Acting for the firm, BetterDocket stores: firm member names, emails, roles, and case assignments; client names, emails, phone numbers, and case relationships; case records including phase, status updates, key dates, tasks, and next steps; messages between firms and clients; documents and draft documents uploaded by firm members or clients, including the contents of those files; document requests and responses; client availability; and activity records of material changes.
What we generate
Authentication and session records; email delivery records (recipient, subject, delivery status); masked product-analytics events, attributed to the firm member or client who caused them; usage snapshots recording daily counts of open and archived cases for invoicing; error and performance logs; and feedback and support requests, which are stored write-only and which the submitter cannot read back.
Where it goes
Supabase (database, authentication, storage), Vercel (hosting), Amazon Web Services (cold storage of archived and deleted cases), Resend (transactional email), PostHog (masked analytics — in the applications, session replay is configured to mask every form input and all case, client, and user content, and to block images, video, canvas, and embedded content; only the application's own navigation and screen labels, which contain no case, client, or user information, are recorded as themselves; it receives the name, email address, and firm roles of firm members and portal clients, and the firm's name, country, and number of members, so that usage can be attributed to an account rather than to an anonymous identifier; it does not receive case, document, message, or task identifiers or their contents), Sentry (error monitoring — error messages, stack traces, and page addresses with record identifiers replaced by a placeholder; no session replay, and request bodies, cookies, headers, query strings, and typed or clicked text are removed before a report is sent), OpenAI (only when an AI-assisted feature is invoked), and Stripe (subscription and payment data; Stripe acts as its own controller for payment data).
The full subprocessor list, with purposes and locations, is in our Data Processing Agreement.
AI-assisted features
BetterDocket includes assistant features that draft suggested text for firm members and clients, such as case summaries, message drafts, and "what changed" notes in the draft review workflow. To generate a suggestion, BetterDocket sends limited case information — and, for draft reviews, a computed text comparison between two versions of a firm's draft document or the opening excerpt of a newly uploaded draft — to OpenAI's API. Suggestions are always shown to a person for review and editing; the assistant never sends messages or changes case records on its own.
- BetterDocket has executed OpenAI's Data Processing Addendum, and our OpenAI organization is enrolled in Zero Data Retention. Under that arrangement OpenAI does not retain request or response content, including for abuse and misuse monitoring.
- BetterDocket also sets the no-retention flag on every individual API call, so the protection does not depend on one organization-level setting alone.
- OpenAI states that it does not use data submitted through its API to train its models.
- Case information is still transmitted to and processed by OpenAI in order to produce the suggestion the user asked for. These are the controls we have put in place and the commitments OpenAI has made to us; we do not warrant a third party's conduct. A firm that would rather not use these features at all can ask us to disable them for its account.
How long it is kept
Deleted cases are permanently destroyed after 30 days in cold storage. Deleted documents and folders are destroyed after 90 days in the case Trash. Archived cases are retained in cold storage while the subscription is active. After termination, customer data is available for export for 30 days and may then be deleted. Backups and logs cycle on their own schedules.
We do not publish a fixed retention schedule covering every category of product data. The timelines above, and the ones in our Data Processing Agreement, are what we commit to.
Part 3 — People we deal with directly
This part covers our own records regardless of who provided them: account and authentication records, support and feedback submissions, subscription and billing contacts, and correspondence with us. We are the controller for these.
We keep them to operate the business, provide support, bill correctly, maintain security, and meet legal obligations. Feedback and support requests are stored write-only; the submitter cannot read them back through the product.
Your rights
Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information, to opt out of certain uses and disclosures, to limit the use of sensitive personal information, to appeal a refusal, and not to be discriminated against for exercising a right.
We offer these choices to everyone, regardless of residence. You may also use an authorized agent, in which case we will ask for proof of authorization.
To make a request, email privacy@betterdocket.com or use Your privacy choices. We will acknowledge and respond within 45 days, and may extend once by a further 45 days with notice. We may need to verify your request, and we may retain limited information to record and honor an opt-out.
For information inside the BetterDocket product, contact the law firm that invited you. We will refer product requests to the firm, because the firm — not BetterDocket — decides what that information is and how long it is kept.
Security
We use reasonable administrative and technical safeguards, but no internet transmission or storage system is completely secure. See our security practices and current limitations for what we do today and what we do not yet offer.
The public website is intended for business audiences and is not directed to children under 13.
Florida
BetterDocket is operated from Orange County, Florida. We maintain reasonable measures to protect and to dispose of records containing personal information as required by the Florida Information Protection Act, Fla. Stat. § 501.171. Where we act as a third-party agent for a law firm customer, we will notify that firm of a breach of security within the time required by that statute and by our Data Processing Agreement.
The Florida Digital Bill of Rights applies to controllers meeting revenue thresholds we do not meet. We nonetheless offer the access, correction, deletion, and opt-out choices described above to everyone.
International
We store and process information in the United States. The Service is offered to law firms established in and operating from the United States. We do not offer Standard Contractual Clauses, data residency, or GDPR-specific commitments — see our Data Processing Agreement.
Changes and contact
We may update this notice as our practices change. The effective date above identifies the latest version, and every published version remains available at its own permanent address together with the SHA-256 hash of its text.
Privacy requests: privacy@betterdocket.com. General questions: hello@betterdocket.com.