Back to home

Privacy Policy

Last updated July 8, 2026

This is a draft pending review by counsel, not legal advice. Have counsel review and tailor it before relying on it in production.

Contents

  1. 1. Summary
  2. 2. Scope of this policy
  3. 3. Our role: business customers vs. their people
  4. 4. Categories of information we collect
  5. 5. Where we get information
  6. 6. Sensitive personal information
  7. 7. How and why we use information
  8. 8. Cookies and tracking signals
  9. 9. How we disclose information
  10. 10. No sale or targeted advertising
  11. 11. How long we keep information
  12. 12. How we protect information
  13. 13. Your privacy rights
  14. 14. How to exercise your rights
  15. 15. Other US state privacy rights
  16. 16. If your employer uses Credplot
  17. 17. Children
  18. 18. Third-party links and services
  19. 19. Where information is stored
  20. 20. Changes to this policy
  21. 21. Contact us

Credplot (“Credplot,” “we,” “us,” “our”) helps companies manage their employees’ and vehicles’ credentials and share them with the organizations that review them. This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, how long we keep it, how we protect it, and the rights and choices available to you. It applies to our website, application, and related services (together, the “Service”) and to residents of the United States. Credplot is operated by ⟦ENTITY⟧.

Summary

The short version, with detail in the sections that follow:

  • We are a business-to-business service. Our customers are companies; much of the data we hold is about their employees and is processed on the company’s behalf.
  • We collect account data, the credential and employee records a customer adds (including some sensitive information such as date of birth and the last four digits of a Social Security number), and usage and security data.
  • We use it to provide, secure, and improve the Service — nothing more.
  • We do not sell personal information and we do not share it for targeted advertising.
  • We encrypt sensitive fields, scope access per account, and keep an audit trail. You can request access, correction, or deletion.

Scope of this policy

This policy covers personal information we handle through the Service in the United States. It does not cover the practices of our customers, the organizations a customer shares credentials with, or third-party websites and services that we link to but do not operate. Our processing of a customer’s data on its behalf is also governed by our Data Processing Addendum and the Terms of Service.

Our role: business customers vs. their people

Credplot plays two roles depending on the data. For the account information of the people who sign in and administer an account, we act as a business that determines how that data is used. For the credential and employee data a customer uploads, we act as a service provider (a processor) that handles the data only on the customer’s documented instructions and for the purposes described here. In that role, the customer — the employer — is responsible for having the appropriate legal basis and notices for the data it places in the Service.

Categories of information we collect

The table below lists the categories of personal information we have collected in the past twelve months, using the categories defined by the California Consumer Privacy Act (CCPA), along with examples, sources, and the categories of parties we disclose each to for a business purpose.

CategoryExamplesCollectedSourcesDisclosed to
IdentifiersName, email address, account ID, IP addressYesYou; your employer (Customer); authentication providerSubprocessors
Records under Cal. Civ. Code § 1798.80Employee name, date of birth, last four digits of a Social Security numberYesThe CustomerSubprocessors; organizations the Customer shares with
Professional or employment informationJob role, credentials, licenses, issuing authorities, dates, uploaded documentsYesThe CustomerSubprocessors; organizations the Customer shares with
Commercial informationSubscription plan, billing recordsYesYou; payment processingSubprocessors
Internet or network activityLog data, audit-trail events, user agentYesAutomatically, as you use the ServiceSubprocessors
Sensitive personal informationSocial Security number (last four), and health-related information that may appear in uploaded credential documentsYesThe CustomerSubprocessors; organizations the Customer shares with
Geolocation, biometric, sensory, education, inferences—No——

We do not knowingly collect the categories marked “No,” and we do not use personal information to build profiles or infer characteristics about individuals.

Where we get information

We obtain personal information from three sources:

  • From you — when you create or administer an account. Our authentication provider (Clerk) supplies your name and email; we store a mirrored copy to operate the account.
  • From our customers — the employee and credential records a customer enters or uploads about its workforce, including documents that our automated pipeline reads.
  • Automatically — usage, log, and security data generated as the Service is used, such as IP address, user agent, and audit-trail events.

To let a customer screen its workforce, the Service also checks names against public government exclusion datasets (the HHS-OIG LEIE and GSA SAM.gov lists). Those are public data sources, not sources of personal information about you.

Sensitive personal information

Some information we process is “sensitive personal information” under California law — in particular, a Social Security number (we store only the last four digits) and any health-related information that may appear in an uploaded credential document (for example, an immunization or physical-exam record). We collect and use sensitive personal information only as necessary to provide the Service the customer has asked for — storing, organizing, extracting from, and sharing credentials at the customer’s direction — and not to infer characteristics about any individual. We encrypt these fields at rest. Because our use is already limited to providing the Service, California’s right to limit the use of sensitive personal information has limited practical effect here, but you may still contact us with a request.

How and why we use information

We use personal information for the following business purposes:

  • Provide the Service — create and operate accounts; store and organize credentials; run automated document extraction; let a customer screen employees against public exclusion lists; check license status; compute compliance; and share records with organizations a customer chooses.
  • Secure the Service — authenticate users, enforce access controls, maintain an audit trail, detect and prevent abuse, and apply rate limits.
  • Support and communicate — respond to requests and send service-related email such as notifications and administrative messages.
  • Improve the Service — diagnose errors and understand usage, using de-identified or aggregated data where practical.
  • Comply with law — meet legal obligations, respond to lawful requests, and enforce our agreements.

We use automated processing to read and extract information from the documents that are uploaded. This extraction assists a customer’s review; it does not make legal or eligibility decisions about any individual on its own.

Cookies and tracking signals

We use only essential cookies: a session cookie from our authentication provider to keep you signed in, and a cookie from our bot-protection provider on public forms. We do not use advertising cookies, analytics cookies that track you across sites, or other cross-context tracking technologies, so no consent banner is required. Because we do not sell or share personal information for advertising, browser signals such as Global Privacy Control (GPC) or “Do Not Track” have no targeted advertising to opt out of; where such a signal is legally treated as an opt-out request, we honor it to the extent it applies.

How we disclose information

We disclose personal information only in these ways:

  • Subprocessors — vendors that operate the Service on our behalf under contract, such as our hosting, authentication, email, and error-monitoring providers. They may process personal information only to provide their function. We maintain a current list of our subprocessors and provide it to customers on request.
  • Organizations a customer shares with — when a customer explicitly shares a credential with an organization for the purpose of that organization’s review.
  • Legal and safety — when required by law or legal process, to enforce our agreements, or to protect the rights, safety, and security of our users, the public, or Credplot.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not disclose personal information to third parties for their own independent purposes.

No sale or targeted advertising

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We do not serve ads, and we have not sold or shared personal information in the preceding twelve months. We do not use or disclose sensitive personal information for purposes to which the right to limit would apply.

How long we keep information

We retain personal information for as long as it is needed for the purposes described in this policy. In practice:

  • Account and customer data — while the account is active and for a reasonable period afterward, unless the customer deletes it sooner or a longer period is required by law.
  • Credential records and documents — until the customer deletes the employee or the record, or closes the account; deletion purges stored documents from object storage and cascades through the associated records, subject to any active legal hold.
  • Audit and security logs — retained for a limited period to support security, integrity, and compliance, then removed or de-identified.
  • Demo data — sandboxed and expires automatically.

When we no longer need personal information, we delete it or de-identify it. Residual copies may persist briefly in routine backups before they expire.

How we protect information

Security is built into the Service by design. Sensitive fields are encrypted with AES-256-GCM at rest, and searchable sensitive fields use keyed blind indexes rather than plaintext. Data is transmitted over encrypted connections. Access is scoped so that each request reaches only the owning account or an organization the customer has shared with. Error reports are scrubbed of personal information, uploads are validated server-side, and every meaningful action is written to an append-only audit log. No method of transmission or storage is perfectly secure, but we work to protect personal information using appropriate technical and organizational measures.

Your privacy rights

Depending on where you live and your relationship with us, you may have some or all of the following rights regarding personal information we hold as a business:

  • Know / access — to learn what personal information we have collected, used, and disclosed, and to receive a copy.
  • Delete — to request deletion of personal information we have collected, subject to legal exceptions.
  • Correct — to request correction of inaccurate personal information.
  • Portability — to receive a copy in a portable format where applicable.
  • Opt out of sale/sharing and limit sensitive data — we do not sell or share personal information or use sensitive personal information for such purposes, so no opt-out is necessary; you may still contact us.
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

How to exercise your rights

To make a request, email [email protected] with the nature of your request. We will take steps to verify your identity before responding — typically by confirming information associated with your account — and we will not use the information you provide for verification for any other purpose. You may use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may still ask you to verify your identity directly.

We aim to respond to verifiable requests within 45 days. If we need more time, we will let you know and may take up to an additional 45 days as permitted by law. There is no fee for a reasonable request. If you are an employee or contractor of a customer, please also read the section below — the customer usually controls the underlying records.

Other US state privacy rights

Residents of US states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and others) may have rights comparable to those described above, including the rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sale, or certain profiling — none of which we conduct. If we decline a request, you may have the right to appeal; to appeal, reply to our decision or email [email protected] with “Appeal” in the subject line, and we will respond within the time your state’s law allows.

If your employer uses Credplot

If your employer or a company you contract with uses Credplot to manage your credentials, that company controls your records, and we process them on its behalf as a service provider. To access, correct, or delete records held about you, please contact your employer first — they can act directly within the Service. If you contact us, we will refer you to the relevant customer and assist that customer in responding, consistent with our agreement with them.

Children

The Service is a workplace tool intended for business use. It is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

Third-party links and services

The Service may link to third-party websites or rely on third-party services (for example, our authentication provider’s sign-in pages). We are not responsible for the privacy practices of parties we do not operate. Review their privacy notices before providing them personal information.

Where information is stored

Credplot is operated from and stores personal information in the United States. We do not offer the Service to, or target it at, residents of the European Economic Area or the United Kingdom, and this policy does not address the GDPR or international data-transfer mechanisms.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, notify customers by email or through the Service. Your continued use of the Service after an update takes effect means you have read the revised policy.

Contact us

For questions about this policy, to exercise a right, or to reach our privacy contact, email [email protected] or write to ⟦ENTITY⟧, ⟦ADDRESS⟧.