Michigan dealer compliance, all in one side panel.
Scan a driver's license or state ID with a phone, then run OFAC, Repeat Offender, and Title/Lien checks without leaving the deal screen.
- 1Open the phone scannerScan the pairing code shown in the side panel.
- 2Aim at the wide barcodeIt is second from the top on the back of the ID.
- 3Review the filled fieldsThe license image stays on the phone.
Privacy Policy
How Compliance Central handles customer and dealership data.
Effective: July 22, 2026
Data Use at a Glance
- OFAC screening stays on your device. No customer information is transmitted for an OFAC-only check.
- Repeat Offender and Title/Lien checks use our HTTPS service. The entered name, date of birth, license/ID number, and VIN when used are sent only to request the selected MDOS portal response.
- Phone scan images stay on the phone. Only the text fields you approve are sent to your computer in an encrypted, single-use package.
- Persistent history is anonymous and limited. Up to 50 outcome-only audit records are kept on your device for no more than 30 days. Customer identity, VINs, and portal screenshots are excluded from persistent history.
1. Overview
Compliance Central ("we", "our", or "the extension") is a Chrome extension that helps Michigan automotive dealers run compliance screenings — OFAC sanctions, Repeat Offender (MDOS), and Title/Lien checks — from a browser side panel. We are committed to protecting the personal information you enter. This policy explains exactly what data the extension handles, where it goes, and what is and is not retained.
2. What Data the Extension Handles
To run a compliance check, you enter buyer and (optionally) co-buyer details: first / middle / last name, suffix, date of birth, and Michigan DLN/PID, plus an optional trade-in VIN. This information is used only to perform the screenings you request. We do not sell it, share it with advertisers, or use it for any purpose unrelated to the compliance checks.
- Current-run data stays in the browser session: customer fields, results, and portal screenshots are available only for the active working session and are not written to persistent extension storage.
- Persistent audit history is anonymous: each record contains an anonymous reference, timestamp, overall decision, individual check outcomes, and whether the run included a co-buyer or trade-in. It does not contain customer names, dates of birth, license/ID numbers, VINs, screenshots, or full report payloads. Audit history is limited to 50 records and 30 days and can be cleared at any time.
- Files you choose to download: a PDF or CSV is saved only when you request it. Downloaded files may contain the details shown in the report and remain wherever you save them until you delete them.
- No tracking or analytics: the extension does not track your browsing, and does not use Google Analytics or any third-party advertising or analytics network.
3. Data Transmitted for MDOS Checks
The Repeat Offender and Title/Lien checks are performed by our secure backend service hosted on Fly.io, which queries the Michigan Department of State (MDOS) portal on your behalf using automated browsing.
- For these two checks only, the buyer/co-buyer name, date of birth, and DLN/PID (and the VIN for a title check) are transmitted to our backend over an encrypted HTTPS connection.
- The backend processes this data in memory to request the MDOS portal response and current-run screenshot. Submitted customer data is not intentionally retained after the request completes and is not written to a database or application log. The returned portal screenshot is current-run evidence and is not added to persistent history.
- Like any hosted web service, Fly.io receives ordinary network request metadata. Compliance Central uses the request IP address transiently in memory for rate limiting and abuse prevention; the app does not write it to its database or application log.
- The extension includes built-in access to the backend, so these checks work without an account, API key, or setup.
4. License Scan (Optional)
The optional "Scan license with phone" feature lets you capture a customer's Michigan driver's license or state ID with your phone instead of typing. It is designed to be private:
- Scanning and parsing happen on your phone — the barcode on the back of the license is read and decoded in your phone's browser. The license image is never uploaded or transmitted.
- Only the parsed text fields (name, date of birth, and license/ID number) travel to your computer, and they are end-to-end encrypted: the desktop extension generates a one-time key that exists only inside the QR code, your phone encrypts the fields with it, and our backend merely relays an encrypted package it cannot read.
- That encrypted package is single-use, expires in about two minutes, and is deleted the moment your computer retrieves it. It is never written to a database or log.
- Once the fields autofill, they are handled exactly like manually typed data: used only for the checks you request and kept in the current browser session. Persistent audit history records outcomes without the scanned identity fields.
5. OFAC Screening (Local Only)
OFAC sanctions screening is performed entirely on your device. The extension downloads the official SDN list directly from the U.S. Treasury OFAC Sanctions List Service and matches names locally. No customer information is sent anywhere for an OFAC check.
6. Third-Party Services
- U.S. Treasury OFAC Sanctions List Service (
sanctionslistservice.ofac.treas.gov): provides the official SDN list the extension downloads for local screening. Treasury redirects the file download to its dedicated AWS GovCloud storage host. Only the public list is downloaded — no customer data is sent. - Michigan Department of State (MDOS): the official source queried (via our backend) for Repeat Offender and Title/Lien results.
- Fly.io: hosts our backend service. Customer data is processed in memory and is not intentionally retained after each request; ordinary network metadata is handled as described above. For the optional license scan, the service relays only an encrypted, single-use package it cannot read.
- GitHub Pages (
techsavvyjoe.github.io): serves the static phone scan page (and this policy). The scan page performs the barcode decoding on your phone; the license image is not sent to it.
7. Permissions
The extension requests only the permissions it needs:
sidePanel— to show the compliance interface in Chrome's side panel.storage— to save preferences and bounded, anonymous audit history.unlimitedStorage— to hold the downloaded OFAC sanctions dataset and bounded, anonymous audit history. Customer identity, VINs, and portal screenshots remain session-only.alarms— to refresh the OFAC sanctions list automatically about once per day.- Host access to
sanctionslistservice.ofac.treas.govand its dedicated AWS GovCloud file host (official OFAC list download), pluscompliance-central-api.fly.dev(MDOS backend).
8. Chrome Web Store Limited Use
Compliance Central's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. See the official Limited Use requirements.
Information is used only to provide the compliance checks, phone-to-computer transfer, local preferences, and audit records described in this policy. It is not used for advertising, market research, credit scoring, or any purpose unrelated to the extension's single purpose. Human access is limited to a user's explicit support request, security investigation, legal requirement, or aggregated operations that cannot identify a person.
9. Your Rights and Choices
- Clear your compliance history at any time with the in-app "Clear All History" button.
- Delete any reports you downloaded from the location where you saved them.
- Uninstalling the extension removes all locally stored data.
10. No Account Needed
All checks — OFAC, Repeat Offender, and Title/Lien — are included free, with no account, sign-up, or API key. Just install and use.
11. Contact Us
Questions about this policy, the extension, or backend access? Email joejgallant@gmail.com or use the Chrome Web Store support page for this listing.