Privacy Policy

Last updated: March 2026

1. Introduction

CredLyr ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our credential verification and issuance platform.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Organization name and details
  • Billing information
  • Authentication credentials

Usage Data

We automatically collect:

  • API request logs and metadata
  • Verification and issuance session data
  • Performance and error metrics
  • Device and browser information

Credential Data

When you use our verification services, we process credential presentations on your behalf. This may include personal data about your end users. You are the data controller for this information; we act as a data processor.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve our services
  • Process transactions and send billing information
  • Send technical notices and support messages
  • Monitor and analyze usage patterns
  • Detect, prevent, and address fraud and abuse
  • Comply with legal obligations

4. Data Retention

We retain your account data for as long as your account is active. Verification and issuance records are retained according to your plan's evidence retention period (7 days to 7+ years depending on plan). You may request earlier deletion subject to legal retention requirements.

5. Data Sharing

We may share your information with:

  • Service providers who assist in operating our platform
  • Payment processors for billing purposes
  • Legal authorities when required by law
  • Successors in the event of a merger or acquisition

We do not sell your personal information to third parties.

6. Data Security

We implement industry-leading security measures to protect your data:

Encryption

All sensitive data is encrypted at rest using AES-256-GCM encryption. Data in transit is protected using TLS 1.3. Webhook signing secrets and API credentials are encrypted before storage.

PII Masking

In production environments, personal data from verified credentials is automatically masked. API responses return only the names of verified claims (e.g., "given_name", "birthdate") without exposing actual values. Full claim data is only available in sandbox environments for testing purposes.

PCI Compliance

CredLyr is designed with PCI DSS compliance in mind. We do not store, process, or transmit cardholder data. Payment processing is handled entirely by our PCI-compliant payment processor (Stripe). Our infrastructure follows PCI best practices for access control, monitoring, and security.

Additional Security

Enterprise plans offer additional security features including mTLS, dedicated infrastructure, IP allowlisting, request signing (HMAC), and custom security controls.

7. Data Processing Agreement

For customers processing personal data of EU residents, we offer a Data Processing Agreement (DPA) that complies with GDPR requirements. Enterprise customers may request custom DPAs.

8. International Data Transfers

Our primary infrastructure is located in the United States. Enterprise customers may select data residency in EU, US, or Canada regions. We use Standard Contractual Clauses for international data transfers where required.

9. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent

To exercise these rights, contact us at privacy@credlyr.com.

10. Cookies and Tracking

We use essential cookies for authentication and session management. We may use analytics cookies to understand how our platform is used. You can control cookie preferences through your browser settings.

11. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through our platform. Your continued use of our services after changes constitutes acceptance.

13. Contact Us

For questions about this Privacy Policy or our data practices, please contact:

  • Email: privacy@credlyr.com
  • Data Protection Officer: dpo@credlyr.com

14. California Privacy Rights

California residents have additional rights under the CCPA, including the right to know what personal information we collect and how it's used, the right to delete personal information, and the right to opt-out of sales (we do not sell personal information).