Last Updated: March 7, 2026
Version 2026-03-07
Welcome to CredentialFlow ("CredentialFlow", "we", "us", "our"). Your privacy is of utmost importance to us. This Privacy Policy explains how we collect, use, store, and disclose your information when you visit our website and use our services.
By accessing or using our services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.
CredentialFlow, Inc. is the data controller responsible for your personal information.
When you create an account, we collect:
Note: Authentication is managed by WorkOS. We do not collect, store, or have access to your password. All authentication credentials are handled entirely by WorkOS infrastructure, including SSO, MFA, and password-based login flows.
When you subscribe to our services, we collect:
Note: Payment processing is handled entirely by Stripe. When you start a free trial or subscribe, you are redirected to Stripe's hosted checkout page, where Stripe collects your payment method directly. We never receive, transmit, or store credit card numbers, CVVs, or bank account details on our servers. During a free trial, Stripe may collect a payment method for billing at the end of the trial period.
We automatically collect information about how you use our platform:
Our servers automatically record:
Authentication is managed by our provider, WorkOS. When you sign in via SSO or direct login, we may receive:
Note: We do not receive or store OAuth tokens, passwords, or raw authentication secrets. WorkOS handles all authentication flows, token management, and MFA verification directly.
For the purpose of secure credential delivery:
Security: All credentials are encrypted using AES-256-GCM with dual-control split-trust encryption. We never store credentials in plaintext.
Contextless Delivery: When using Contextless mode, credentials are delivered using only a phone number. No recipient name or email is stored. Even a full platform compromise would expose nothing personally identifiable.
You can opt-out of marketing emails by clicking "unsubscribe" in any email or contacting [email protected].
If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Providing services | Performance of contract |
| Payment processing | Performance of contract |
| Marketing communications | Consent (you can withdraw anytime) |
| Security and fraud prevention | Legitimate interests |
| Analytics and improvement | Legitimate interests |
| Legal compliance | Legal obligation |
| Enforcing Terms | Legitimate interests |
We do NOT sell your personal information to third parties.
We only share your information in the following limited circumstances:
We engage third-party companies to provide infrastructure and services. These providers have access to your information only to perform tasks on our behalf.
| Provider | Purpose | Location |
|---|---|---|
| WorkOS | Authentication, SSO, MFA, password management | United States |
| Amazon Web Services (AWS) | Hosting, infrastructure, database | United States |
| Twilio | SMS delivery (routing metadata only, no credential content) | United States |
| SendGrid | Email delivery (routing metadata only, no credential content) | United States |
| Stripe | Payment processing, checkout, and subscription billing (handles all card/bank data directly) | United States |
| PostHog | Product analytics (consent-gated) | United States |
| Google (Analytics, Tag Manager) | Website analytics and conversion measurement (consent-gated) | United States |
| Meta (Facebook Pixel) | Marketing attribution (consent-gated, marketing consent required) | United States |
No third-party secret access. We deliver notifications, not secrets. Messaging providers (Twilio, SendGrid) receive routing metadata only. Credential content never leaves CredentialFlow's encrypted environment until single-use retrieval by the intended recipient.
If CredentialFlow is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your data is transferred and becomes subject to a different Privacy Policy.
We may disclose your information if required by law or if we believe such action is necessary to:
We may share your information with third parties when you give us explicit consent to do so.
We retain your information only as long as necessary for the purposes described in this Privacy Policy.
To comply with data minimization principles:
You can request immediate deletion of your data by contacting [email protected]. We will delete your data within 30 days, except where retention is required by law.
We implement industry-leading security measures to protect your information:
For detailed security documentation, visit our Trust Center.
In the unlikely event of a data breach:
You have the following rights regarding your personal information:
You can request a copy of your personal data by contacting us. We will provide it in a structured, commonly used format within 30 days of your request.
You can update or correct your personal information through your account settings or by contacting us.
You can request deletion of your personal data, subject to legal retention requirements.
You can request that we limit how we use your personal data.
You can request a copy of your data in a portable format and transfer it to another service.
You can object to our processing of your personal data for certain purposes (e.g., marketing).
Where we process your data based on consent, you can withdraw consent at any time.
We will respond to your request within 30 days.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
We do NOT sell your personal information.
We have not sold personal information in the past 12 months.
Email [email protected]with "CCPA Request" in the subject line.
CredentialFlow is based in the United States. All customer data is hosted and processed exclusively within the United States on Amazon Web Services infrastructure. If you access our services from outside the US, your information will be transferred to, stored, and processed in the United States.
For users in the EEA, UK, or Switzerland:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential cookies | Authentication, session management | Session |
| Analytics cookies | Usage tracking, performance monitoring (PostHog, Google Analytics) | Up to 1 year |
| Preference cookies | Remember your settings | Up to 1 year |
| Marketing cookies | Campaign attribution and ad measurement (Facebook Pixel, Google Ads) | Up to 90 days |
We use Google Consent Mode v2 to manage tracking preferences. All non-essential cookies default to denied until you provide explicit consent through our cookie banner. This means:
You can control cookies through your browser settings or by updating your consent preferences via the cookie banner. Note: Disabling essential cookies may affect functionality.
We also use sessionStorage (cleared when your browser tab closes) for campaign attribution parameters such as UTM source, medium, and campaign identifiers. This data is not persistent and is not shared with third parties.
We do NOT use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.
Our services are NOT intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If you believe we have collected information from a child under 18, please contact [email protected] immediately.
Our website does not currently respond to "Do Not Track" (DNT) browser signals. We may implement DNT support in the future.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use of our services after changes constitutes acceptance of the updated Privacy Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy:
Email: [email protected]
Response Time: We will respond to privacy inquiries within 30 days.
If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.
BY USING OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY.