Privacy Policy
- Version
- 1.6
- Effective
- July 28, 2026
- Last updated
- September 2, 2026
1. Introduction
This Privacy Policy explains how TraIDCred collects, uses, discloses, and protects personal information in connection with the Services, and the choices and rights you have. It applies to Tradespeople, Profile Viewers (including Homeowners), individuals a business identifies as its license qualifier and TraIDCred invites to confirm that relationship (whether or not they hold any account), and others who interact with the Services.
2. Information we collect
2.1 Information you provide.
- Account and profile information: name, email address, business name, trade(s), and contact/profile
details.
- Credentials: documents you submit for Review (business licenses, insurance certificates, W-9,
OSHA and other certificates, and other documents), which may contain Sensitive Credential Data such as government identification numbers or an EIN.
- Automated document reading (OpenAI): to help our reviewers, a submitted credential document
may be read once by an automated extraction service operated by OpenAI. The document file is transmitted to OpenAI for that single reading, together with our reading instructions and nothing else — no account data, no other documents, and no customer history. The output is a set of suggested field values (for example, a license number or an expiration date printed on the document) shown to our reviewer and to you as suggestions; suggestions are never treated as verified facts, and no verification decision is made by the automated reading. Per OpenAI's API-platform terms, API content is not used to train OpenAI's models by default. Verification decisions are made by TraIDCred personnel.
- Payment and billing information: when you purchase a paid plan, our payment processor Stripe
collects and processes your payment-card details directly. TraIDCred receives and stores only limited billing information — such as your subscription plan and status, billing contact, the card brand and last four digits, and Stripe customer/transaction identifiers — and not your full card number.
- Representative photo: if you choose to add one, a photograph of your business's public
representative that you upload and that is displayed publicly on your Public Profile once approved. You represent that you have the right to upload it. We re-encode uploaded images on our servers, which removes embedded metadata including any GPS location before storage. We may remove a photo that is misleading, impersonating, or otherwise inappropriate.
- Identity verification (Stripe Identity): identity verification is performed by Stripe, a
third-party provider, on Stripe-hosted pages. Stripe collects and holds your government photo ID and your verification selfie, and compares them using biometric technology — that is, by measuring distinctive physical characteristics of your face — to assess whether the ID belongs to you. Stripe asks for your consent to that biometric processing on its own pages, as part of its flow. TraIDCred never receives, stores, or displays those images, and performs no facial or biometric comparison anywhere in the Services. From Stripe we receive only: the verification status, timestamps, Stripe's machine-readable error code, and, on success only, your verified first and last name. We use that name for one purpose: to determine whether it reasonably matches the name the verification is for — the representative name on the contractor profile, or, for a license qualifier's verification, the legal name you confirmed as your own and the qualifier named on the licensing authority's public record (see the license-qualifier bullet below). That comparison is automated and is reviewed by TraIDCred personnel when the automated result is not clear-cut. We do not request or store your date of birth, address, identification number, or Stripe's complete verification output, and the verified name is never displayed publicly and is not written to our logs. Stripe retains the images and verification data it collects under Stripe's own terms, privacy policy and retention practices — not under this Policy. Stripe decides how long to keep that data and for what purposes, and TraIDCred cannot delete it from Stripe on your behalf. To have that data deleted, or to withdraw the optional consent Stripe asks for, see the Identity Verification Notice, which explains both the TraIDCred side and the Stripe side. You can read Stripe's privacy policy at https://stripe.com/privacy. TraIDCred's retention schedule and destruction guidelines for verification involving biometric processing — including exactly what TraIDCred never holds — are published in the Biometric Information Policy.
- Document-access requests (Profile Viewers and Homeowners): if you ask a business to share a
specific credential document with you, we collect the name, email address, and optionally the phone number and project description you enter on that form. We use them for one purpose: to pass your request to that business so it can decide, and to email you the time-limited access link if it approves. We share your name and the details you entered with that business — that is the point of the request. We do not use this information for marketing, do not sell it, and do not add you to any mailing list. A record of the request and its outcome is kept in our access audit log as evidence of who was granted access to what (see §6 and the Data Retention Policy). You do not need an account to make a request.
- License qualifier confirmation (invited individuals): if a business identifies you as its
license qualifier, the business gives us your name and email address, and we use that email address for one purpose: to invite you to review the request and confirm or decline the relationship. You do not need to be, and do not become, a TraIDCred customer. If you choose to proceed, we collect: your confirmation of your own full legal name; your acceptance of the License Qualifier Authorization Terms and related consents (recorded as described in §2.3); your written biometric release — before any verification session is created you are shown a separate Biometric Information Notice and asked for an affirmative release on its own dedicated control, and we record the exact notice text, its version, and your release as immutable consent evidence (see the Biometric Information Policy); the result of your own identity verification (the bullet above applies — Stripe collects the ID and selfie, and we receive only your verified first and last name and the result); and, if you sign it, your final electronic authorization — its exact text, your verified legal name, and the time of signing, kept as an immutable record. We compare your verified name against the qualifier named on the licensing authority's public record as transcribed by our reviewers. Everything in this bullet is internal to TraIDCred's review: none of it appears publicly, and the business is told only the status of the process — never your identity details. A minimal secure sign-in (your email and a password you choose) is created to bind these records to you permanently; it carries no business membership or authority. If you decline, we record the decline and take no further action; no identity verification occurs. You may exercise every right in §8 without holding an ordinary account — email privacy@traidcred.com from the address the invitation was sent to. We retain acceptance, decline, and signed-authorization records as legal evidence (see §2.3 and §6) even if other information is deleted.
- Communications: information in your messages to us (for example, support requests).
Data-minimization note on Social Security Numbers. A W-9 is optional, and we ask that you not include a Social Security Number — use an EIN where possible, or redact an SSN before uploading. If a document you submit nonetheless contains an SSN or other Sensitive Credential Data, we restrict access to it, never display it publicly, do not use it to validate your tax status, and retain it only as long as reasonably necessary (see §6 and the Data Retention Policy).
2.2 Information collected automatically.
- Referral program. If you join a business through a referral link or code, we record the referral
code, the fact of the referral, and the milestones that determine whether a reward is earned. This is used only to administer the program.
- Privacy-minimal analytics. For a limited set of events (a profile view and a QR scan), the
Services record the event using a salted, per-day, one-way hash derived from a first-party cookie solely to avoid double-counting within a short window. The Services do not store IP addresses, user-agent strings, device fingerprints, raw cookie values, or precise location for analytics.
- Acquisition attribution. So we can tell which of our own efforts actually reach tradespeople,
the Services record how a visit arrived: the utm_source, utm_medium, utm_campaign, utm_term and utm_content labels in the link followed, the domain only of the referring website, the page landed on, and the time. Two first-party cookies hold this (traidcred_attr_first, traidcred_attr_last, 90 days — see the Cookie Policy §3), keeping the first visit separate from the most recent one; the first is never overwritten. If you create an account these values are copied onto your account record, and from that point they are personal information under this Policy, covered by the access and deletion rights in §8 and removed with your account. If — and only if — you accepted advertising cookies, we also record the fbclid advertising click identifier from a Meta ad you clicked. We do not collect Google's gclid or LinkedIn's li_fat_id. The campaign labels themselves are never shared with an advertising platform.
- Advertising measurement (only if you accept). If you accept advertising cookies, we use the Meta
Pixel and the Meta Conversions API to measure our advertising and to show our ads to people who have visited (see Cookie Policy §5). For that purpose only, the following is shared with Meta: the Meta browser identifiers _fbp and _fbc; your IP address and browser user agent at the moment of the event, which Meta requires in order to match a web event — we read these from your request and do not store them; the address of the page the event happened on; the name of the step reached — a page was viewed, an account was created, a business profile was created, identity verification completed, or a membership was paid for — and, for the last of these, the amount paid and currency; and a unique event identifier, so the same event is not counted twice. We do not send Meta your name, email address, phone number, postal address, or any TraIDCred account or business identifier — hashed or otherwise. We never send anything from a credential, an uploaded document, an identity verification, a homeowner document-access request, a representative's identity details, internal notes, or payment card information. If you decline, or have not chosen, none of this happens. Meta processes the information it receives in accordance with its own terms and privacy policies.
- Product lifecycle events. The Services keep an internal, append-only record of significant
account milestones — for example that an account was created, or that the activation page was viewed — with the time, the business it relates to, and how far through setup the account was. It is used to understand where people get stuck and to operate the product. It records no document contents, payment details, identity-verification details, file names, or message contents, and it is removed with your account.
- Essential technical data: limited data necessary to operate, secure, and troubleshoot the
Services (for example, authentication/session data).
2.3 Acceptance and consent records. When you accept the Terms or provide a consent, the Services record the fact, the document version, and the timestamp of your acceptance. For legal-evidence purposes only, TraIDCred also records limited technical metadata — the date and time, and the IP address and browser user agent associated with the acceptance — with the acceptance record to evidence the agreement. This metadata is used solely to prove acceptance and is not used for analytics, tracking, profiling, or advertising, and is kept separate from the privacy-minimal analytics described in §2.2.
3. How we use information
We use personal information to: (a) provide and operate the Services, including reviewing Credentials and displaying non-sensitive status on Public Profiles; (b) provide Document Access you or the Services authorize; (c) communicate with you (including transactional and Service messages); (d) secure the Services and prevent fraud and misuse; (e) maintain audit and evidence records; and (f) comply with law. We do not sell personal information. With your consent, and using only the limited information described in §2.2, we use Meta advertising technologies to measure our advertising and to show our ads to people who have visited TraIDCred — which is "cross-context behavioral advertising" as some state laws define it. Declining, or withdrawing your consent, stops this entirely.
4. What appears publicly
Public Profiles display only non-sensitive status and metadata — such as business name, trade(s), credential status, license label, listed expiration, and Last-Reviewed Date — and, where a contractor has provided them and they have been approved, the representative's name, title and photograph together with an "Identity Verified" indicator and its date — consistent with the Verification Standard's public-display invariant. The Services never publicly display Credential files, their contents, filenames, storage paths, reviewer notes, reviewer identity, or Sensitive Credential Data. Rejected Credentials are not shown publicly.
Identity verification and the representative photo. The Services never publicly display a government-ID image, a verification selfie, a date of birth, an address, an identification number, or the name Stripe verified. The publicly displayed representative photo is supplied by the contractor and is not compared, biometrically or otherwise, against Stripe's ID or selfie images — no such comparison is performed. The representative section appears only while every condition holds (identity verified, verified name matched, photo approved, not hidden by the contractor, profile publicly eligible) and disappears if any condition stops holding.
5. How we disclose information
We disclose personal information only as follows:
- Service providers (sub-processors): vendors that host and operate the Services under contractual
confidentiality and security obligations — currently Vercel (application hosting), Supabase (database, authentication, and document storage), Cloudflare (encrypted off-site backup storage, used solely for disaster recovery — see §6 and the Data Retention Policy §3.3), Resend (transactional email), and Google (business email: messages you send to our published @traidcred.com addresses — including privacy@, support@, security@ and legal@ — are delivered to and stored in mailboxes we operate on Google Workspace, together with anything you choose to attach), and OpenAI (automated reading of submitted credential documents to produce suggested field values for our reviewers — see §2.1; the document is transmitted for a single reading and API content is not used to train OpenAI's models by default). We maintain a current sub-processor list and will update it as our providers change; contact privacy@traidcred.com for the latest list. Payment processing is performed by Stripe, and identity verification is performed by Stripe Identity — a separate use of the same provider, in which Stripe (not TraIDCred) collects and holds your ID and selfie images (see the Subscription & Billing Terms and the Identity Verification Notice); TraIDCred does not receive your full payment-card number.
- Meta Platforms, Inc. (advertising measurement) — only if you accept advertising cookies. We share
the limited data listed in §2.2: the Meta browser identifiers, your IP address and browser user agent at the moment of the event, the page address, the name of the step reached, and — for a paid membership — the amount and currency. Meta processes the information it receives in accordance with its own terms and privacy policies. We share nothing with Meta about anyone who declines or has not chosen.
- Document Access: when you or the Services authorize a time-limited Access Grant, the specific
Credential document is made available to the specified Profile Viewer for the access period.
- Legal, safety, and protection: to comply with law, respond to lawful requests, enforce the Terms,
and protect the rights, safety, and integrity of the Services and Users.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets,
subject to this Policy.
We do not sell personal information. The only sharing for cross-context behavioral advertising is the Meta measurement described above, which happens only with your consent and stops when you withdraw it.
6. Data retention
We retain personal information only as long as necessary for the purposes described here or as required by law, in accordance with the Data Retention Policy, which sets the specific retention periods for each category. In summary: account and Credential data are retained while your Account is active and for a limited period after closure; Sensitive Credential Data is minimized and kept for the shortest period reasonably necessary; privacy-minimal analytics are kept on a short rolling basis; and minimal acceptance/verification records are retained as evidence for the applicable limitations period. See the Data Retention Policy for the specific periods.
⚠️ Backups are the one exception you should know about without reading another document. We keep an encrypted, private, off-site backup of the Services for disaster recovery. Database backup copies roll off after approximately two months. Backup copies of uploaded files — credential documents, representative photographs, business logos — are append-only and are not deleted when the live file is deleted. Deleting a file removes it from the live Services immediately; a copy may remain in that backup indefinitely, encrypted, reachable only by TraIDCred operations personnel, and used only to restore the Services after data loss. Data Retention Policy §3.3 explains why and how to ask us to handle a backup copy individually.
7. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit and at rest, private document storage, and least-privilege access. See the Security Overview for a plain-language description of these controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your privacy rights
8.1 Rights we honor for all U.S. users. As a conservative, single standard, TraIDCred extends the following rights to all U.S. users, regardless of your state of residence: to (a) access the personal information we hold about you; (b) correct inaccurate information; (c) delete your personal information; (d) obtain a portable copy; and (e) appeal a denied request. To exercise a right, contact privacy@traidcred.com. We will verify your request and respond within the timeframes required by applicable law (and, where none applies, within a reasonable time). These requests are handled manually today — there is no self-service deletion or export control in the product, and emailing us is the way to exercise any of these rights. These rights do not require an ordinary account: an invited license qualifier (or anyone else whose information we hold without an account) may exercise them by emailing from the address our communication was sent to; we verify the request before acting on it.
Two honest limits on deletion. First, we retain the minimal evidence records described in §6 and the Data Retention Policy §4. Second, deletion removes your information from the live Services; a copy of an uploaded file may remain in our disaster-recovery backup as described in §6 and Data Retention Policy §3.3. Tell us if you need a backup copy destroyed as well and we will handle it individually.
8.2 Selling and sharing; your opt-out. TraIDCred does not sell your personal information. We do share limited information with Meta for advertising measurement and retargeting, but only if you accept advertising cookies — this may be "sharing for cross-context behavioral advertising" or "targeted advertising" under California and similar state laws. You control it directly: decline the banner, or use Cookie preferences in the footer at any time to withdraw your consent. Withdrawing stops the sharing going forward; it does not remove information Meta already received, which you can address through Meta's own settings. We also honor Global Privacy Control signals: if your browser sends one, we do not share anything with Meta unless you later opt in deliberately. You may also contact us at privacy@traidcred.com with questions or requests concerning these choices.
8.3 No discrimination. We will not discriminate against you for exercising your rights.
8.4 State-specific rights. Residents of states with comprehensive privacy laws (for example, California under the CCPA/CPRA, and Utah, Virginia, Colorado, and Connecticut) may have additional or more specific rights; we honor the rights above for everyone and will accommodate any additional state-specific mechanisms required by law. (State-specific disclosure language should be reviewed before scale.)
9. Children
The Services are not directed to individuals under 18, and we do not knowingly collect personal information from them.
10. Third-party links
The Services may link to third-party sites we do not control; their privacy practices govern their services.
11. International users
The Services are intended for users in the United States, and personal information is processed in the United States. The Services are not directed to individuals outside the United States.
12. Changes to this Policy
We may update this Policy; material changes will be notified and versioned consistent with the Electronic Communications & E-Sign Consent.
13. Contact
Questions or privacy requests: privacy@traidcred.com, or by mail to TraIDCred LLC, Attn: Privacy, 826 Expressway Ln Unit #688, Spanish Fork, UT 84660.