Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how Credecia, Inc. ("we," "us," or "our") collects, uses, and protects information when you visit our website or use our services (the "Service").
Credecia, Inc. is based in the United States. We also process personal data of individuals located in the European Economic Area ("EEA") and the United Kingdom, and we describe below how we comply with the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").
This Privacy Policy describes how we collect, use, and protect your information. Where we rely on your consent as a legal basis for processing, we obtain it through specific mechanisms described below, such as form submissions or cookie consent prompts.
1. Information We Collect
We collect the minimum amount of information necessary to operate our Service.
1.1 Email Address
When you submit our form, we collect your email address. We do not collect your name or any other personal identifiers through this form.
1.2 Usage Data
We automatically collect certain information when you visit our website, including pages visited, time spent on pages, device and browser type, IP address, and general usage patterns. This is collected via analytics tools (see Section 4).
1.3 Categories of Personal Information (CCPA)
Under the CCPA, the categories of personal information we collect are:
| CCPA Category | Collected? | Details |
|---|---|---|
| Identifiers (e.g., email address, IP address) | Yes | Email via form; IP address via hosting/analytics logs |
| Personal information under Cal. Civ. Code § 1798.80 (name, SSN, etc.) | No | We do not collect names or government IDs |
| Protected classification characteristics | No | — |
| Commercial information | No | — |
| Biometric information | No | — |
| Internet/network activity (browsing behavior, interaction with our site) | Yes | Via PostHog analytics |
| Geolocation data | No | Only general/approximate location inferable from IP |
| Sensitive personal information | No | — |
In the preceding 12 months, we have not sold or shared (as "share" is defined under the CPRA for cross-context behavioral advertising) any personal information, and we do not use or disclose sensitive personal information.
2. Legal Basis for Processing (GDPR)
If you are located in the EEA or UK, we rely on the following legal bases under Article 6 of the GDPR to process your personal data:
- Consent (Art. 6(1)(a)): Where you voluntarily submit your email address via our form, your submission constitutes consent to be contacted for outreach purposes. You may withdraw this consent at any time (see Section 8).
- Legitimate interests (Art. 6(1)(f)): For website analytics (PostHog in cookieless mode) and maintaining the security and functionality of our Service, we rely on our legitimate interest in measuring aggregate site performance, balanced against your privacy rights. You have the right to object to or opt out of analytics processing at any time by emailing privacy@credecia.com.
We do not process any special categories of personal data (Art. 9 GDPR) and do not knowingly target our form at individuals for purposes requiring a different legal basis.
3. How We Use Your Information
We use the information we collect solely for the following purposes:
- Outreach: To contact you via email regarding our Service, updates, or related communications.
- Analytics: To understand how visitors use our website and improve the Service.
- Operations: To maintain, secure, and operate our website and Service.
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects (Art. 22 GDPR).
4. Third-Party Service Providers
We use the following third-party services (processors/service providers) to operate our Service:
| Provider | Purpose | Data Involved | Location / Transfer Mechanism |
|---|---|---|---|
| Vercel | Website hosting and infrastructure | Standard server/technical logs (e.g., IP address, request data) | US-based; relies on Standard Contractual Clauses (SCCs) for EEA data transfers |
| PostHog | Website analytics (cookieless mode) | Aggregate usage data (pages visited, device/browser info, behavior events). No persistent cookies or device identifiers stored. | US or EU hosting depending on account configuration; SCCs apply for EEA data transfers where applicable |
| Google Cloud | Collection and storage of form submissions | Email address submitted via form | US-based (Google LLC); relies on SCCs for EEA data transfers |
We recommend reviewing each provider's own privacy policy and data processing terms:
- Vercel: https://vercel.com/legal/privacy-policy
- PostHog: https://posthog.com/privacy
- Google Cloud: https://cloud.google.com/terms/cloud-privacy-notice
International transfers: Because we and our service providers are primarily based in the United States, personal data from the EEA/UK is transferred outside the EEA/UK. Where this occurs, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) or equivalent mechanisms offered by our providers, to ensure your data receives an adequate level of protection.
5. Data Sharing and Sale
We do not sell your personal data, and we do not "share" personal data as that term is defined under the CPRA (i.e., for cross-context behavioral advertising). We do not share your email address with third parties for their own marketing or advertising purposes. Your information is only accessible to the service providers listed above, solely to operate our Service as described in this policy.
Because we do not sell or share personal information, no "Do Not Sell or Share My Personal Information" opt-out is required; however, we will honor any such request if submitted.
6. Data Retention
We retain your email address for as long as necessary to fulfill the outreach purposes described in this policy, or until you request deletion (see Sections 8 and 9). Analytics data collected via PostHog in cookieless mode is retained for up to 90 days in aggregated, non-identifying form to evaluate site performance trends, after which it is automatically purged. We do not store persistent user profile logs or multi-day device history.
7. Data Security
We take reasonable technical and organizational measures to protect your information. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
8. Your Rights Under GDPR (EEA/UK Residents)
If you are located in the EEA or UK, you have the following rights regarding your personal data:
- Right to access — obtain confirmation of and access to your personal data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion of your data.
- Right to restrict processing — limit how we use your data in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — withdraw consent at any time, without affecting prior lawful processing.
- Right to lodge a complaint — with your local data protection supervisory authority.
To exercise any of these rights, contact us at privacy@credecia.com. We will respond within one month, as required by the GDPR.
9. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights:
- Right to know — what personal information we collect, use, and disclose.
- Right to delete — request deletion of your personal information.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale/sharing — not applicable, as we do not sell or share personal information.
- Right to limit use of sensitive personal information — not applicable, as we do not collect sensitive personal information.
- Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights.
To exercise these rights, contact us at privacy@credecia.com. We may need to verify your identity (e.g., by confirming the email address on file) before fulfilling your request. You may also designate an authorized agent to submit a request on your behalf.
10. Cookies and Tracking Technologies
We operate our website analytics (PostHog) exclusively in cookieless mode (cookieless_mode: 'always') with persistent user profiling completely disabled (person_profiles: 'never').
Under this configuration, we do not store tracking cookies, local storage tokens, or persistent device identifiers on your browser. Website analytics are processed using transient daily hashes solely to measure aggregate page visits, referrer paths, and general site performance without tracking individual visitors across sessions or days.
EEA and UK Visitors
We process website analytics under our legitimate interest in understanding and improving our Service (Art. 6(1)(f) GDPR). You have the right to object to or opt out of analytics processing at any time by emailing privacy@credecia.com.
Global Privacy Control (GPC)
We honor Global Privacy Control (GPC) and universal opt-out preference signals sent by your browser. When a GPC or Do Not Track (DNT) signal is detected, analytics capturing is automatically suppressed.
Because no non-essential cookies or personal identifiers are stored on your device, no cookie consent prompt is required. You may also manage cookie handling or script execution directly through your browser settings.
11. Children's Privacy
Our Service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at: