Skip to policy content

Legal

Privacy Policy

This policy explains what Laudes needs to operate verified achievement, profile, company, sharing, and account services—and what the service is designed not to collect.

Effective and last updated: August 6, 2026

1. Scope and our role

This Privacy Policy applies to Laudes websites and services that link to it, including www.laudes.app, verify.laudes.app, app.laudes.app, associated application programming interfaces, public verification pages, public profile and company pages, and related communications (collectively, the “Service”). “Laudes,” “we,” “us,” and “our” refer to the operator of the Service.

Employers and other business customers often provide professional and achievement information to Laudes. When we process information only on a customer’s instructions, that customer is responsible for its own privacy notice and Laudes acts as its service provider or processor. For information connected with your employer’s recognition program, you may need to contact the employer first. We will assist the customer with valid requests as required by law and contract.

Laudes may separately determine how information is used for account security, public verification integrity, direct support, and operation of our own websites. This policy describes those activities as well.

2. Information we collect

Account and identity information

We may collect your name, work email address, username or profile key, employer-provided user identifiers, profile or avatar URL, LinkedIn profile URL, account status, and the organization and team associated with your account. Current website access uses one-time links or codes and limited-life session identifiers rather than asking website users to create a password.

Organization and professional information

We may receive organization name, stable source-system identifiers, industry, website, company-size band, time zone, subscription status, employer branding, team name and type, role family, leadership status, current or historical organization and team associations, and related program configuration.

Achievement and verification information

Depending on the recognition program and publication approval, we may process the recipient’s approved display name; issuer and team; achievement title and description; metric, cohort, role, rank, percentile, score or score band, or benchmark label; period and issue dates; source and calculation version; approval, consent, dispute, correction, publication, and revocation status; stable attestation and source-record identifiers; and cryptographic hashes or signatures used to detect changes and duplicates.

We may preserve the submitted achievement payload and processing errors to validate, retry, investigate, correct, or audit issuance. A public page shows only the display-safe fields approved for publication, not every field used internally to operate the verification record.

Authentication, device, and security information

We process one-time claim or magic-link tokens, signed session cookies, authorization state, token-expiration and replay-prevention records, request identifiers, IP address, browser and device information available in standard web requests, timestamps, requested URLs, response status, and security or diagnostic logs. We use IP addresses for abuse prevention and rate limiting as well as ordinary hosting and security operations.

Integration and sharing information

If you connect LinkedIn, we may process your LinkedIn member identifier, member URN, display name, approved scopes, encrypted access token, token expiry, connection status, and non-secret connection and sharing events. When you choose to publish a post or video, we process the selected public achievement, post text, media choice, and campaign parameters needed to complete that request.

If you use share-video tools, we may store the selected layout, theme, animation direction, format, dimensions, duration, rendering recipe, associated achievement and organization, and the account that made the choice. The durable recipe allows media to be regenerated without retaining every rendered file indefinitely.

Communications and support

We process the email address used for secure sign-in or achievement-ready notices, delivery status and errors, support messages, privacy or accessibility requests, dispute details, and any information you choose to include in correspondence with us.

Information the achievement export is designed not to collect

The current achievement-export contract is designed not to send Laudes raw opportunity rows, customer or opportunity names, exact revenue or pipeline totals, compensation, full employee rankings, Social Security or government identification numbers, financial-account details, health information, biometric identifiers, or arbitrary CRM metadata. Please do not submit those categories to the Service. Narrow bands or indexes may be processed when an approved recognition program requires privacy-preserving context.

3. Sources of information

We obtain information from:

  • you, when you sign in, connect an integration, share content, or contact us;
  • your employer, team leader, program administrator, or another organization that is authorized to issue or manage recognition;
  • connected systems such as Salesforce and, if enabled for your organization, other customer relationship management providers;
  • LinkedIn, when you choose to connect or use LinkedIn features; and
  • your browser, device, and our hosting or security systems when you use the Service.

4. How we use information

We use personal information to:

  • create, authenticate, secure, and administer accounts and sessions;
  • receive employer-approved recognition data and create verifiable achievement records;
  • apply publication, consent, dispute, correction, supersession, and revocation controls;
  • display approved public achievement, profile, company, embed, and social preview pages;
  • generate share links, images, and videos and complete user-requested LinkedIn posts;
  • send secure sign-in links, achievement-ready notices, service messages, and requested support;
  • prevent fraud, replay, forgery, scraping, abuse, unauthorized access, and other security incidents;
  • diagnose failures, measure reliability, improve the Service, and enforce our agreements; and
  • comply with law and establish, exercise, or defend legal claims.

Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests in providing and securing the Service, consent for optional connections or public sharing where required, and compliance with legal obligations. We do not use public achievement records to make automated employment, credit, housing, insurance, or similar eligibility decisions.

5. Public achievements and profiles

A public achievement, profile, or company page can be viewed by anyone with the link and may be indexed, cached, copied, or reshared by search engines, social networks, archival services, and other people. Public fields may include a display name, employer, current team, profile image, public professional link, company branding, and approved achievement, metric, cohort, period, and status details.

Onboarding creates a private professional account. A signed-in professional must separately authorize publication before Laudes makes the profile page or person preview available. The publication notice identifies the fields that may appear, and the professional can make the profile private again from the dashboard. Profile publication does not itself publish or revoke an individual achievement; achievement publication and company-page visibility remain subject to their separate program and publication controls.

Public authorization does not make the record permanent or unchangeable inside Laudes. An issuer or authorized account holder may dispute, correct, supersede, make private, or revoke a record. To preserve verification integrity and avoid presenting an outdated credential as current, we may retain a limited record and display a revoked or superseded status instead of silently deleting every reference. We cannot control copies already made by unaffiliated third parties.

To report an incorrect, unauthorized, or disputed public record, email support@laudes.app with the page URL and a description of the issue. Do not email sensitive CRM records unless we ask for a secure method to provide them.

6. How we disclose information

We may disclose personal information to the following recipients:

  • Employers and business customers. We provide account, program, issuance, publication, and support information to the organization that administers the applicable recognition program, subject to its access rights.
  • The public. We publish only the approved fields associated with an authorized public achievement, profile, company page, embed, or share asset.
  • Service providers. Hosting, database, content-delivery, security, email-delivery, media-rendering, and professional-service providers process information for us under contractual or professional obligations. The current Service uses Google Cloud infrastructure and may use Resend for transactional email.
  • Connected services. We exchange information with Salesforce and other integrations selected by a customer, and with LinkedIn when you connect or direct us to share content there. Their own terms and privacy policies apply to their independent processing.
  • Legal and safety recipients. We may disclose information to comply with law or valid legal process; protect rights, safety, and security; investigate misuse; or establish, exercise, or defend legal claims.
  • Business transaction recipients. Information may be reviewed or transferred as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate confidentiality protections where practicable.
  • At your direction. We disclose information when you or an authorized business customer directs us to do so.

We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. We do not use third-party advertising networks on the Service.

7. Cookies and online activity

Laudes uses first-party cookies that are necessary to authenticate users, maintain a secure session, route requests, and protect the Service. These include a signed application-session cookie and a protected backend-session cookie. They are configured as HTTP-only, use secure transport in production, use a limited same-site setting, and expire after a limited session period. Blocking these cookies may prevent account features from working. Public verification pages do not require an account session.

We do not currently use advertising cookies or cross-site behavioral analytics. Some public profile pages offer an optional official LinkedIn badge, and sharing actions can take you to LinkedIn. The badge is not loaded until you select the load action. LinkedIn may then receive network, browser, device, referrer, and cookie information under its own privacy and cookie policies.

We recognize legally required opt-out preference signals for activities that are subject to such signals. Because we do not sell personal information or use it for cross-context behavioral advertising, an opt-out signal does not currently change those practices.

8. How long we retain information

We retain each category only for as long as reasonably necessary for the purposes described in this policy, including the life of an account or customer relationship, the verification and dispute lifecycle of an achievement, security and fraud prevention, contractual commitments, legal requirements, and the establishment or defense of claims. The criteria differ by record:

  • account, organization, and achievement records are generally kept while the related account, customer relationship, or verification record remains active and for a limited period afterward where needed for support, audit, disputes, legal compliance, or reliable revocation and correction history;
  • public achievements may retain a verification record or status record after revocation or supersession so an old link does not misleadingly appear valid;
  • one-time authentication and replay-prevention records expire automatically and are cleaned up after their security window;
  • LinkedIn token material is deleted when you disconnect, when LinkedIn rejects the authorization, or shortly after expiry; the current scheduled cleanup removes expired token rows after a 24-hour grace period;
  • generated share-video assets are normally temporary; the current default is 24 hours, while the selected rendering recipe may be retained to reproduce the asset and understand product use; and
  • backups and security logs are deleted or overwritten on their ordinary cycles unless preservation is required for an incident, dispute, or law.

When retention is no longer necessary, we delete, de-identify, or securely isolate the information, subject to technical and legal limitations.

9. Your choices and privacy rights

Depending on where you live and subject to applicable exceptions, you may have the right to request access to, a copy of, correction of, or deletion of your personal information; to learn about its sources, purposes, and recipients; to withdraw consent; to object to or restrict certain processing; and to appeal a denied request. You also may have a right not to receive discriminatory treatment for exercising a privacy right.

Submit a request to support@laudes.app with the subject “Privacy request.” Describe the right you want to exercise and the account, employer, profile, or public URL involved. We may request limited additional information to verify your identity and authority. Do not send a password, one-time sign-in link, government identifier, or sensitive CRM data.

If an employer or other customer controls the information, we may direct your request to that organization or act on its instructions. Authorized agents may submit requests where permitted by law, but we may require proof of authority and direct identity confirmation. Some information may be exempt from a request, including information needed to secure the Service, complete a requested transaction, comply with law, protect others, or maintain an accurate revocation and correction record.

You can disconnect LinkedIn through the available account control or by contacting us. You may stop transactional email only where the message is not necessary for authentication, security, or an active service request.

10. U.S. state privacy notices

California notice at collection

In the preceding 12 months, we may have collected the categories described above: identifiers and contact information; customer-record and account information; professional or employment-related information; Internet or electronic-network activity; approximate location derived from IP address; authentication information; and limited inferences or classifications such as a role family, benchmark cohort, score band, or achievement context. The sources, purposes, recipient categories, and retention criteria for those categories are described in Sections 2 through 8.

Account authentication information may qualify as sensitive personal information under California law. We use and disclose it only for expected Service, authentication, security, and legal purposes—not to infer characteristics about you. We do not use or disclose sensitive personal information for purposes that require a “Limit the Use of My Sensitive Personal Information” link.

We have not sold personal information or shared it for cross-context behavioral advertising in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. We do not offer a financial incentive in exchange for personal information.

Colorado and other state rights

Residents of Colorado and other states with comprehensive privacy laws may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal data, and to opt out of sale, targeted advertising, or certain profiling. Laudes does not currently engage in those opt-out activities. If we deny a request and your law provides an appeal right, email support@laudes.app with the subject “Privacy appeal” and explain why you believe the decision should be reconsidered.

11. Security

We use administrative, technical, and organizational safeguards designed to protect personal information in light of its nature and the risks of processing. Measures used by the current Service include encrypted transport, restricted server-side credentials, signed and HTTP-only session cookies, limited-life authentication tokens, replay prevention, rate limiting, security headers, access controls, and encryption of LinkedIn access tokens at rest.

No method of transmission or storage is completely secure. You are responsible for keeping one-time links and account access confidential and for promptly reporting suspected unauthorized access to support@laudes.app.

12. Children

The Service is intended for businesses and working professionals and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information to us, contact support@laudes.app so we can investigate and take appropriate action. Users must also meet the eligibility requirements in our Terms.

13. International users

Laudes and its service providers may process information in the United States and other countries where privacy laws may differ from those where you live. When applicable law requires a transfer mechanism or additional protection, we use an appropriate contractual or legal mechanism. Contact us to ask about the mechanism relevant to your information.

14. Changes and contact

We may update this policy to reflect changes in the Service, our practices, or the law. We will update the date at the top and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.

For privacy questions, requests, or complaints, contact Laudes at support@laudes.app.