Credential Register
Change region — currently Canada
Appearance — System

Appearance

Light Dark System

Remembered across the whole site.

Sign in Get started

Privacy Policy

This Privacy Policy describes how Credential Register handles personal information.

1. What we collect. Account details (name, email), documents and details uploaded by customers and their vendors, and usage information needed to operate the Service.

2. How we use it. Solely to provide and improve the Service: storing documents, computing checklist status, sending reminder and notification emails, and supporting your account. We do not sell personal information.

3. Vendor and contractor data. Vendors appear here in one of two ways. Some are invited by a customer organization and upload documents at that organization's request; that organization controls who on their team can see them. Others hold their own free account, where the credentials are the vendor's own: they decide which customers to connect with, which credentials each one receives, and who is sent a share link. A share link is readable by anyone holding it until the vendor revokes it or it expires, so vendors should send links only to people they intend to have them. Once a credential has been disclosed to a customer it forms part of that customer's records; ending a connection stops further disclosure but does not retract what was already provided. Vendors who belong to a management group are visible to that group's managers.

4. Storage & security. Files are stored on private storage and served only to authenticated, authorized users, with each request checked as it is made. Access is logged. The single exception is a share link, where possession of the link is the authorization the vendor chose to grant.

5. Retention. Data is retained while the account is active and deleted on verified request when an account closes. Because a compliance register is a record of what an organization held and when, documents a customer received remain in that customer's register until that customer deletes them.

6. Approximate location. To suggest the right regional version of our site, we estimate which country your IP address is in. This is approximate, country-level only, and never used to identify you. Depending on how this platform is configured, the estimate is made either on our own server or by a specialist provider named in section 7; where a provider is used, your IP address is sent to them for that lookup and for nothing else. The country itself is remembered against a one-way hash of your address rather than the address itself, so repeat visits do not need a fresh lookup. We do keep a short operational log of these estimates — the address, the country returned, which regional page you were shown, and whether you were offered a different one — so that we can check the feature is working and is not being called more often than it should be. Those entries are deleted automatically after 30 days and are used for nothing else. A suggestion is only ever an offer: it can be dismissed, it never redirects you on its own, and your choice of regional site is remembered in a cookie.

7. Service providers. We use providers for hosting, email delivery, payment processing, and — where the estimate in section 6 is enabled — location lookup, currently MaxMind. Each handles only what its function requires. A current list of these providers is available on request.

8. Contact. Privacy questions can be sent via the contact details on our website.