Your customers are yours.
We built that in.
When you submit a manifest to a disposal site or compost yard through ComplyFlo, they get what they need for compliance — and nothing more. Your generator list stays private. We've engineered it that way, and we've locked ourselves out too.
It is an emergency access procedure — like breaking the glass on a fire alarm. If ComplyFlo support ever needs to view your original manifest (for example, to resolve a technical issue), they must request approval, explain why, and get permission from a super admin. The access is limited to 30 minutes, every action is logged, and you can see when it happened. It is not a backdoor — it is a locked door with a camera and a sign-in sheet.
The real risk haulers face
Your manifest is a customer list.
Without protection, it's a liability.
Every manifest you submit contains your generator's name, address, phone number, and contact information. In a paper-based world that information stays in a filing cabinet. In a digital platform, without the right architecture, it becomes searchable, exportable, and mineable — by anyone with access to the system.
A disposal site that receives your manifests knows exactly which restaurants, businesses, and municipalities you service — their names, addresses, and contact details — without any restriction in most software platforms.
Generator poaching riskEvery manifest you submit to a compost facility reveals your generator relationships. Over time, a compost yard can build a complete picture of your customer base from nothing but your own compliance submissions.
Customer list exposureMost SaaS platforms give internal staff broad access to customer data for support purposes. That means a support engineer at your software vendor can browse your generator list, export it, and use it. No hauler agreed to that.
Vendor access riskHow Generator Privacy Shield works
Two versions of every manifest. Shown to the right people.
When a manifest is uploaded, ComplyFlo automatically creates two copies: the original — complete and unmodified, used for your workflows — and a protected operational copy with generator-identifying fields masked. The system decides which version to show based on who is viewing it.
Full permission matrix
Exactly who can see what — and why.
Generator privacy rules are enforced at the architecture level — not by policy alone. The system determines what version of a manifest to render based on tenant type before the page ever loads. There is no setting to override it.
Break Glass workflow
Even ComplyFlo staff can't browse your data by default.
Our internal support team does not have default access to original manifests, generator vaults, or OCR data. When a support engineer genuinely needs to access a manifest to resolve an issue, they must go through a formal Break Glass process — approved, logged, time-limited, and auditable.
What this means for your business
Use compliance software without putting your customer relationships at risk.
Generator Privacy Shield means you can submit to disposal sites and compost yards through ComplyFlo with confidence — the compliance data they need is visible, and your customer relationships are protected by architecture, not by trust.
When you submit an MSW manifest to a disposal site through ComplyFlo, they see the waste type, volume, transporter info, and manifest number — everything needed for TCEQ compliance. The generator's name, address, phone, and contact are masked. They cannot search for your generators. They cannot export them. They cannot use your compliance submissions to build a competitor pitch list.
UCO haulers don't file TCEQ manifests — but they still deliver to compost and processing sites. The same generator privacy protections apply: compost yards and disposal sites cannot search, export, or mine the generator data from any records they receive through ComplyFlo.
The original manifest — complete and unredacted — is always stored, encrypted, and available for TCEQ audit exports. Privacy protection applies to operational browsing and exports by disposal sites. It never applies to authorized regulatory audit workflows. You remain fully compliant.
Generator Privacy Shield only restricts what disposal sites and internal staff can see. As a hauler, you have full access to everything — original manifests, generator search, export, OCR fields, customer copy delivery, and historical records. No watermarks on your daily workflow. No extra steps. No restrictions.
This is not a permission setting that an admin can toggle off. The manifest rendering engine determines which version to display based on tenant type before the page loads. There is no configuration that allows a disposal site to view generator data. The protection is in the architecture.
Every Break Glass event, every TCEQ audit export, and every internal staff access to original manifests is permanently logged with timestamp, user identity, scope, and approval chain. Platform admins can view the full access log at any time.
Built to protect the business you've worked to build.
See Generator Privacy Shield in action — and how the rest of ComplyFlo's hauler platform fits around it.