Skip to main content
Generator Privacy Shield

Your customers are yours.
We built that in.

When you submit a manifest to a disposal site or compost yard through ComplyFlo, they get what they need for compliance — and nothing more. Your generator list stays private. We've engineered it that way, and we've locked ourselves out too.

ComplyFlo's security commitment to haulers
"ComplyFlo protects hauler customer relationships by preserving full operational visibility for haulers while preventing generator discovery workflows for disposal operations and internal platform users."
This is not a policy statement — it is enforced in the architecture. Disposal sites and compost yards cannot search, export, or browse your generator list. Neither can we.
Generator data masked from disposal sites
Generator data masked from compost yards
ComplyFlo staff require Break Glass approval to view your data — every access is logged and time-limited
TCEQ audit exports always use original manifests
Full access preserved for haulers — zero friction
What does “Break Glass” mean?

It is an emergency access procedure — like breaking the glass on a fire alarm. If ComplyFlo support ever needs to view your original manifest (for example, to resolve a technical issue), they must request approval, explain why, and get permission from a super admin. The access is limited to 30 minutes, every action is logged, and you can see when it happened. It is not a backdoor — it is a locked door with a camera and a sign-in sheet.

The real risk haulers face

Your manifest is a customer list.
Without protection, it's a liability.

Every manifest you submit contains your generator's name, address, phone number, and contact information. In a paper-based world that information stays in a filing cabinet. In a digital platform, without the right architecture, it becomes searchable, exportable, and mineable — by anyone with access to the system.

Disposal sites can see who your customers are

A disposal site that receives your manifests knows exactly which restaurants, businesses, and municipalities you service — their names, addresses, and contact details — without any restriction in most software platforms.

Generator poaching risk
Compost yards can map your entire route

Every manifest you submit to a compost facility reveals your generator relationships. Over time, a compost yard can build a complete picture of your customer base from nothing but your own compliance submissions.

Customer list exposure
Software platforms have access to everything

Most SaaS platforms give internal staff broad access to customer data for support purposes. That means a support engineer at your software vendor can browse your generator list, export it, and use it. No hauler agreed to that.

Vendor access risk

How Generator Privacy Shield works

Two versions of every manifest. Shown to the right people.

When a manifest is uploaded, ComplyFlo automatically creates two copies: the original — complete and unmodified, used for your workflows — and a protected operational copy with generator-identifying fields masked. The system decides which version to show based on who is viewing it.

Hauler view — original manifest
Manifest #2232 — Hauler ABCFull access
Generator name
Sunrise Diner
Generator address
1420 Main St, Springfield TX 78000
Generator phone
(555) 555-0142
Generator contact
Alex Johnson — Site Manager
Waste type / gallons
Grease · 50 gal · 30% solids
✓ Full generator detail visible. Search, export, and customer copy delivery — all available. No restrictions.
View original manifest with all generator fields
Search and filter by generator name, address, contact
Export full manifest and generator lists
Deliver generator copies — legally required
Full OCR extraction of generator fields
Historical manifest visibility — all records
Disposal site / compost yard view — protected copy
Manifest #2232 — Hauler ABCGenerator protected
Generator name
Protected
Generator address
Protected
Generator phone
Protected
Generator contact
Protected
Waste type / gallons
Grease · 50 gal · 30% solids
✓ Compliance data visible. Generator identity protected. The disposal site has everything they need for TCEQ retention — and nothing more.
Cannot search by generator name, address, or contact
Cannot export generator lists or OCR data
Cannot filter manifests to build a customer profile
Cannot bulk extract generator information
Can retain manifests for TCEQ compliance — required by law
Can export compliance reports, volume data, and hauler activity

Full permission matrix

Exactly who can see what — and why.

Generator privacy rules are enforced at the architecture level — not by policy alone. The system determines what version of a manifest to render based on tenant type before the page ever loads. There is no setting to override it.

Permission
MSW Hauler
UCO Hauler
Disposal Site
Compost Site
ComplyFlo Staff
Manifest access
View original manifest
Break Glass
View protected manifest copy
Historical manifest visibility
✓ Protected
✓ Protected
Break Glass
Generator data
Search by generator name / address
Export generator list
Access generator OCR fields
Break Glass
Deliver generator copy (legal requirement)
Exports & compliance
Export full manifests
Break Glass
Export compliance reports & volume data
TCEQ audit export (always original manifest)
Break Glass

Break Glass workflow

Even ComplyFlo staff can't browse your data by default.

Our internal support team does not have default access to original manifests, generator vaults, or OCR data. When a support engineer genuinely needs to access a manifest to resolve an issue, they must go through a formal Break Glass process — approved, logged, time-limited, and auditable.

1
Staff submits a request— must specify the reason, the tenant, and the exact manifest scope they need access to.
2
A platform super admin reviews and approves— or denies — the request. No self-approval.
3
Access is time-limited to 30 minutes. After expiration, access is automatically revoked without any manual action required.
4
Every page viewed is watermarked and logged — who accessed what, at what time, and under which approved request. Permanent audit trail.
5
Break Glass events are visible to platform admins — you can see if and when your data was accessed internally and by whom.
Break Glass Access RequestRequires approval
Staff member
support@complyflowaste.com
Tenant
Hauler ABC — Hauler account
Manifest scope
Manifest #2232 only
Reason for access
Customer reported OCR extraction issue — requires investigation of original document
Approved by
Platform Super Admin — pending
30-minute access window
Access auto-revokes at expiration · All views watermarked and logged

What this means for your business

Use compliance software without putting your customer relationships at risk.

Generator Privacy Shield means you can submit to disposal sites and compost yards through ComplyFlo with confidence — the compliance data they need is visible, and your customer relationships are protected by architecture, not by trust.

For MSW haulers
Submit manifests to disposal sites — without handing over your customer list

When you submit an MSW manifest to a disposal site through ComplyFlo, they see the waste type, volume, transporter info, and manifest number — everything needed for TCEQ compliance. The generator's name, address, phone, and contact are masked. They cannot search for your generators. They cannot export them. They cannot use your compliance submissions to build a competitor pitch list.

Your customers stay yours.
For UCO haulers
Submit to compost yards without exposing the restaurants you service

UCO haulers don't file TCEQ manifests — but they still deliver to compost and processing sites. The same generator privacy protections apply: compost yards and disposal sites cannot search, export, or mine the generator data from any records they receive through ComplyFlo.

Generator relationships protected across all hauler types.
TCEQ audit compliance preserved
Full, unmodified manifests always available for regulatory audits

The original manifest — complete and unredacted — is always stored, encrypted, and available for TCEQ audit exports. Privacy protection applies to operational browsing and exports by disposal sites. It never applies to authorized regulatory audit workflows. You remain fully compliant.

Compliance and privacy. Not a tradeoff.
No friction for haulers
Your daily workflow is completely unchanged

Generator Privacy Shield only restricts what disposal sites and internal staff can see. As a hauler, you have full access to everything — original manifests, generator search, export, OCR fields, customer copy delivery, and historical records. No watermarks on your daily workflow. No extra steps. No restrictions.

Full access. Zero friction. Built in by default.
Architecture-level enforcement
Protected by code, not by policy

This is not a permission setting that an admin can toggle off. The manifest rendering engine determines which version to display based on tenant type before the page loads. There is no configuration that allows a disposal site to view generator data. The protection is in the architecture.

Permanent audit trail
Every access to original manifests is logged

Every Break Glass event, every TCEQ audit export, and every internal staff access to original manifests is permanently logged with timestamp, user identity, scope, and approval chain. Platform admins can view the full access log at any time.

Built to protect the business you've worked to build.

See Generator Privacy Shield in action — and how the rest of ComplyFlo's hauler platform fits around it.