Last updated July 8, 2026
Credplot (“Credplot,” “we,” “us,” “our”) helps companies manage their employees’ and vehicles’ credentials and share them with the organizations that review them. This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, how long we keep it, how we protect it, and the rights and choices available to you. It applies to our website, application, and related services (together, the “Service”) and to residents of the United States. Credplot is operated by ⟦ENTITY⟧.
The short version, with detail in the sections that follow:
This policy covers personal information we handle through the Service in the United States. It does not cover the practices of our customers, the organizations a customer shares credentials with, or third-party websites and services that we link to but do not operate. Our processing of a customer’s data on its behalf is also governed by our Data Processing Addendum and the Terms of Service.
Credplot plays two roles depending on the data. For the account information of the people who sign in and administer an account, we act as a business that determines how that data is used. For the credential and employee data a customer uploads, we act as a service provider (a processor) that handles the data only on the customer’s documented instructions and for the purposes described here. In that role, the customer — the employer — is responsible for having the appropriate legal basis and notices for the data it places in the Service.
The table below lists the categories of personal information we have collected in the past twelve months, using the categories defined by the California Consumer Privacy Act (CCPA), along with examples, sources, and the categories of parties we disclose each to for a business purpose.
| Category | Examples | Collected | Sources | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email address, account ID, IP address | Yes | You; your employer (Customer); authentication provider | Subprocessors |
| Records under Cal. Civ. Code § 1798.80 | Employee name, date of birth, last four digits of a Social Security number | Yes | The Customer | Subprocessors; organizations the Customer shares with |
| Professional or employment information | Job role, credentials, licenses, issuing authorities, dates, uploaded documents | Yes | The Customer | Subprocessors; organizations the Customer shares with |
| Commercial information | Subscription plan, billing records | Yes | You; payment processing | Subprocessors |
| Internet or network activity | Log data, audit-trail events, user agent | Yes | Automatically, as you use the Service | Subprocessors |
| Sensitive personal information | Social Security number (last four), and health-related information that may appear in uploaded credential documents | Yes | The Customer | Subprocessors; organizations the Customer shares with |
| Geolocation, biometric, sensory, education, inferences | — | No | — | — |
We do not knowingly collect the categories marked “No,” and we do not use personal information to build profiles or infer characteristics about individuals.
We obtain personal information from three sources:
To let a customer screen its workforce, the Service also checks names against public government exclusion datasets (the HHS-OIG LEIE and GSA SAM.gov lists). Those are public data sources, not sources of personal information about you.
Some information we process is “sensitive personal information” under California law — in particular, a Social Security number (we store only the last four digits) and any health-related information that may appear in an uploaded credential document (for example, an immunization or physical-exam record). We collect and use sensitive personal information only as necessary to provide the Service the customer has asked for — storing, organizing, extracting from, and sharing credentials at the customer’s direction — and not to infer characteristics about any individual. We encrypt these fields at rest. Because our use is already limited to providing the Service, California’s right to limit the use of sensitive personal information has limited practical effect here, but you may still contact us with a request.
We use personal information for the following business purposes:
We use automated processing to read and extract information from the documents that are uploaded. This extraction assists a customer’s review; it does not make legal or eligibility decisions about any individual on its own.
We use only essential cookies: a session cookie from our authentication provider to keep you signed in, and a cookie from our bot-protection provider on public forms. We do not use advertising cookies, analytics cookies that track you across sites, or other cross-context tracking technologies, so no consent banner is required. Because we do not sell or share personal information for advertising, browser signals such as Global Privacy Control (GPC) or “Do Not Track” have no targeted advertising to opt out of; where such a signal is legally treated as an opt-out request, we honor it to the extent it applies.
We disclose personal information only in these ways:
We do not disclose personal information to third parties for their own independent purposes.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We do not serve ads, and we have not sold or shared personal information in the preceding twelve months. We do not use or disclose sensitive personal information for purposes to which the right to limit would apply.
We retain personal information for as long as it is needed for the purposes described in this policy. In practice:
When we no longer need personal information, we delete it or de-identify it. Residual copies may persist briefly in routine backups before they expire.
Security is built into the Service by design. Sensitive fields are encrypted with AES-256-GCM at rest, and searchable sensitive fields use keyed blind indexes rather than plaintext. Data is transmitted over encrypted connections. Access is scoped so that each request reaches only the owning account or an organization the customer has shared with. Error reports are scrubbed of personal information, uploads are validated server-side, and every meaningful action is written to an append-only audit log. No method of transmission or storage is perfectly secure, but we work to protect personal information using appropriate technical and organizational measures.
Depending on where you live and your relationship with us, you may have some or all of the following rights regarding personal information we hold as a business:
To make a request, email [email protected] with the nature of your request. We will take steps to verify your identity before responding — typically by confirming information associated with your account — and we will not use the information you provide for verification for any other purpose. You may use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may still ask you to verify your identity directly.
We aim to respond to verifiable requests within 45 days. If we need more time, we will let you know and may take up to an additional 45 days as permitted by law. There is no fee for a reasonable request. If you are an employee or contractor of a customer, please also read the section below — the customer usually controls the underlying records.
Residents of US states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and others) may have rights comparable to those described above, including the rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sale, or certain profiling — none of which we conduct. If we decline a request, you may have the right to appeal; to appeal, reply to our decision or email [email protected] with “Appeal” in the subject line, and we will respond within the time your state’s law allows.
If your employer or a company you contract with uses Credplot to manage your credentials, that company controls your records, and we process them on its behalf as a service provider. To access, correct, or delete records held about you, please contact your employer first — they can act directly within the Service. If you contact us, we will refer you to the relevant customer and assist that customer in responding, consistent with our agreement with them.
The Service is a workplace tool intended for business use. It is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
The Service may link to third-party websites or rely on third-party services (for example, our authentication provider’s sign-in pages). We are not responsible for the privacy practices of parties we do not operate. Review their privacy notices before providing them personal information.
Credplot is operated from and stores personal information in the United States. We do not offer the Service to, or target it at, residents of the European Economic Area or the United Kingdom, and this policy does not address the GDPR or international data-transfer mechanisms.
We may update this policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, notify customers by email or through the Service. Your continued use of the Service after an update takes effect means you have read the revised policy.
For questions about this policy, to exercise a right, or to reach our privacy contact, email [email protected] or write to ⟦ENTITY⟧, ⟦ADDRESS⟧.