Skip to main content

Privacy Policy

Version:
2026-09-05.2.policy.2
Effective Date:
January 01, 2024
Last Updated:
May 20, 2026
Owner / approvers:
Privacy / Privacy, Legal
Review state:
approved

Convenient Licensing is committed to protecting the privacy and confidentiality of your personal, professional, licensing, and application-related information.

This Privacy Policy explains how Convenient Licensing (“Convenient Licensing,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects information when you use our website, services, client portal, forms, communications, or related licensing support services.

By using our services, website, forms, or client portal, you agree to the practices described in this Privacy Policy.

Licensing research tools

Our tools send profession, state and research topic selections to Brave for public-source research and to a model through OpenRouter to organize the findings. They do not ask for names, email addresses, license numbers or documents. Common profession and state results can become public, shareable guides and appear in search engines. Optional personal details from the licensing finder are not published in those guides.

Checklist marks and selected budget items are stored in your browser session. Public source text, research results and retrieval dates are stored to reuse and review the research. When enabled, Diffbot receives selected public official-source URLs to extract page content; it does not receive your identity or licensing documents.

1. Information We Collect

We collect information necessary to provide licensing, renewal, registration, credentialing, application preparation, portal tracking, and related administrative services.

Information may be collected directly from you, from your employer or authorized representative, through our forms or client portal, or from third-party entities when necessary to provide services.

A. Identifiers

We may collect identifying information, including:

  • Name
  • Mailing address
  • Email address
  • Phone number
  • Date of birth
  • Government identification
  • Social Security number or partial Social Security number, when required for licensing applications
  • NPI number
  • Other identifying information required by licensing boards, agencies, or third-party entities

B. Professional and Licensing Information

We may collect professional and licensing-related information, including:

  • Current and prior licenses
  • License numbers
  • License expiration dates
  • Certifications
  • Education history
  • Transcripts
  • Employment history
  • Professional history
  • Specialty or practice area
  • Credentialing information
  • Continuing education information
  • DEA or controlled substance registration information
  • Application details
  • Board correspondence
  • License verification records

C. Sensitive Licensing Information

When required for licensing, renewal, registration, credentialing, or application purposes, we may collect sensitive information, including:

  • Criminal history disclosures
  • Arrest, charge, or conviction information
  • Court records or explanations
  • Disciplinary history
  • Prior board actions
  • Investigations
  • License denials, suspensions, revocations, or restrictions
  • Malpractice history
  • Impairment or substance-related disclosures
  • Immigration or work eligibility information
  • Other sensitive information required by a licensing board, government agency, or third-party entity

D. Documents and Uploaded Files

We may collect and store documents uploaded or provided by you, including:

  • Identification documents
  • Licenses
  • Certifications
  • CE certificates
  • Transcripts
  • Court records
  • Board correspondence
  • Employment records
  • Verification documents
  • Receipts
  • Application forms
  • Signed authorizations
  • Other documents required for licensing-related services

E. Account, Portal, and Login Information

When voluntarily provided by you, we may collect login credentials, verification codes, portal access details, or account information for licensing boards, certification agencies, credentialing platforms, or other application-related systems.

This information is used only to assist with your requested licensing-related services.

F. Payment and Billing Information

We may collect billing information necessary to process payments, subscriptions, invoices, reimbursements, and card-on-file authorizations.

Payment information is processed through secure third-party payment processors. Convenient Licensing does not intentionally store full credit card numbers on its own systems.

G. Website, Portal, and Usage Data

We may collect information about how you interact with our website, forms, and client portal, including:

  • IP address
  • Browser type
  • Device information
  • Pages visited
  • Portal activity
  • Form submissions
  • Cookies and similar tracking technologies

2. How We Use Information

We use collected information to:

  • Provide licensing, renewal, registration, credentialing, and related administrative services
  • Prepare, manage, and track applications
  • Communicate with licensing boards, agencies, vendors, schools, employers, and other third-party entities
  • Request or organize supporting documents
  • Maintain client portal access and application tracking
  • Send updates, reminders, invoices, payment requests, and service communications
  • Process payments and subscriptions
  • Maintain business records
  • Comply with legal, regulatory, accounting, audit, and contractual obligations
  • Improve our website, portal, forms, communications, and services
  • Protect against fraud, unauthorized access, misuse, or security issues

We do not sell your personal information, licensing information, payment information, login credentials, or sensitive application-related information.

3. Communication and SMS Consent

We may use your phone number, email address, and portal contact information to send service-related communications, including:

  • Document requests
  • Application updates
  • Board requests
  • Payment reminders
  • Invoices
  • Portal notifications
  • Renewal reminders
  • Service updates
  • Other licensing-related communications

Text message consent is not a condition of purchase. Message and data rates may apply. Message frequency varies. Carriers are not liable for delayed or undelivered messages. You may opt out of non-essential text messages by replying STOP. Reply HELP for help. Opting out may limit our ability to send time-sensitive service updates.

4. How We Share Information

We may share information only as necessary to provide services, comply with legal obligations, operate our business, protect our rights, or complete licensing-related tasks.

A. Licensing Boards, Agencies, and Third-Party Entities

We may disclose client information to:

  • State boards of nursing
  • Medical boards
  • Licensing boards
  • Certification agencies
  • DEA or controlled substance registration agencies
  • Background check providers
  • Fingerprinting vendors
  • Schools and educational institutions
  • Employers
  • Credentialing organizations
  • Professional organizations
  • Testing agencies
  • Government agencies
  • Other entities necessary to complete or support licensing-related services

B. Service Providers and Technology Vendors

We may share information with trusted service providers that help us operate our business and provide services, including:

  • Client portal platforms
  • Form providers
  • Payment processors
  • Cloud storage providers
  • Email platforms
  • SMS platforms
  • Automation tools
  • Customer support tools
  • Document management tools
  • Website hosting providers
  • Other technology vendors

The technology and service providers we may use include:

  • Porkbun
  • Airtable
  • Softr
  • Jotform
  • Freshdesk
  • Quo
  • Durable
  • OpenAI (ChatGPT)
  • Grok Bot
  • Anthropic (Claude)
  • Keeper
  • 1Password
  • Gmail
  • Vercel
  • Stripe
  • Squarespace
  • Google Analytics
  • Google Workspace
  • Google Ads
  • GitHub
  • xAI
  • Cursor
  • Cloudflare
  • Upstash

Cloudflare includes Turnstile and related edge or CDN services. Gmail is also used as a mailbox alongside Google Workspace. xAI provides Grok Bot. Naming a provider here is a disclosure of parties that may receive information as needed to operate our services. It does not describe a data-processing agreement, legal role, or public activation of every listed tool.

These providers may access information only as needed to perform services on our behalf.

C. Legal or Compliance Disclosures

We may disclose information when required or permitted by law, regulation, subpoena, court order, legal process, audit, investigation, or government request.

We may also disclose information to protect the rights, safety, property, or security of Convenient Licensing, our clients, or others.

5. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal, professional, licensing, payment, and application-related information.

However, no method of electronic transmission, storage, or communication is 100% secure. We cannot guarantee absolute security.

You are responsible for maintaining the confidentiality of your own email accounts, licensing board accounts, portal accounts, usernames, passwords, and verification codes.

You should notify us promptly if you believe your information, account access, or login credentials may have been compromised.

6. Data Retention

We retain information for as long as necessary to:

  • Provide services
  • Maintain licensing and client records
  • Support future renewals or ongoing services
  • Comply with legal, regulatory, accounting, audit, and contractual obligations
  • Resolve disputes
  • Enforce agreements
  • Protect our business and legal rights

We may retain client records after services end when necessary for business records, legal compliance, audit purposes, dispute resolution, licensing history, renewal tracking, or future service needs.

We may not be able to delete certain records if retention is required for legal, regulatory, accounting, security, or legitimate business purposes.

7. Your Rights and Choices

Depending on your jurisdiction, you may have the right to:

  • Request access to personal information we maintain about you
  • Request correction of inaccurate information
  • Request deletion of certain personal information
  • Request restriction of certain processing
  • Opt out of non-essential communications
  • Request information about how your data is used or shared

To exercise these rights, contact us using the information below. We may need to verify your identity before responding.

Some requests may be limited if information is needed to provide services, comply with legal obligations, maintain business records, prevent fraud, resolve disputes, or satisfy regulatory requirements.

8. Cookies and Website Tracking

We may use cookies and similar technologies to improve website functionality, understand visitor interactions, improve user experience, and support website performance.

You can manage cookie preferences through your browser settings. Some website or portal features may not function properly if cookies are disabled.

9. Children’s Privacy

Our services are intended for adults age 18 and older and for licensed or licensing-eligible professionals.

We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.

10. Third-Party Links and Platforms

Our website, forms, portal, emails, or communications may contain links to third-party websites, platforms, payment processors, licensing boards, or external services.

We are not responsible for the privacy practices, security, content, or policies of third-party websites or platforms. You should review the privacy policies and terms of any third-party services you use.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, technology, or legal requirements.

The updated policy will be posted on our website with a revised “Last Updated” date. Your continued use of our services after the updated policy is posted means you accept the updated policy.

12. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy, please contact:

Convenient Licensing LLC

Phone/Text: (640) 400-0056

Email: Support@ConvenientLicensing.com

Website: convenientlicensing.com

New Jersey, USA

Service and payment terms are available in our Terms of Service.

Verified Data-Flow Inventory

This inventory describes every browser, local-storage, checkout-service, and vendor boundary found in the repository. “Unverified” is intentional: a configured endpoint or reachable destination does not establish account ownership, a contract, or a legal role.

Google Analytics, Jotform contact and intake, and the online Stripe payment path are enabled in this build. Programmatic SMS and transactional email remain disabled.

License Requirements Finder research

State / direction
active; server-to-third-party
Owner
Engineering
Purpose
Research public professional licensing requirements at the visitor’s request. Common profession and state routes open shareable guides that may be listed on our website and made available to search engines. Optional residence and compact details stay in the individual result and are not published in a public guide.
Data and sensitivity
profession or license type, current and target license states, optional primary residence state and compact-license answers, public research and source snippets sent for structured extraction ; moderate
Controller / processor role
Convenient Licensing provides the finder; Brave provides search-grounded answers or retrieved source passages; OpenRouter routes evidence extraction to the configured OpenAI model. No name, email, license number, or documents are needed to use the finder. Vendor legal classification is not asserted by this feature.
Consent or other basis
User-initiated search; data transfers and guide publication are described in the Privacy Policy.
Retention
Personalized answers and selections are cached in Upstash for up to 24 hours. Published generic guide answers persist until removed, with visit-triggered refresh after 24 hours. For the LLM Context research experiment, the latest public source-evidence packet is retained for up to 30 days and personalized evidence for up to 24 hours. Provider-side retention is not verified here.
Deletion
Personalized cached research expires after 24 hours; published generic guides require deletion from the saved guide store and sitemap index.
Failure behavior
Unavailable or uncited research returns an error; no replacement facts are generated locally.
Logging
Only controlled failure stages, categories, service HTTP statuses, and aggregate source counts are logged; prompts, selections, answers, and credentials are not logged.
Destination
https://api.search.brave.com, https://openrouter.ai, https://openai.com

License finder verification, request limits, and cache

State / direction
active; server-to-third-party
Owner
Engineering
Purpose
Verify browser challenges, limit research usage, and reuse recent source-linked results.
Data and sensitivity
challenge token, hashed request IP, profession and state selections, research answers ; moderate
Controller / processor role
Cloudflare verifies challenges and the configured Upstash service stores counters and cached research.
Consent or other basis
Functional protection and caching for user-requested searches.
Retention
Per-IP counters expire after one hour; daily counters and personalized answers expire after 24 hours; published generic guides persist until removed; research locks expire after 150 seconds.
Deletion
Application-managed records expire automatically at their stated limits.
Failure behavior
Research is unavailable when verification or shared request limiting is unavailable.
Logging
Application code sends a hashed IP to the counter service and does not log it. Raw IPs are not sent to Brave.
Destination
https://challenges.cloudflare.com, https://upstash.com

Static website delivery

State / direction
active; browser-to-first-party
Owner
Engineering
Purpose
Deliver public pages and first-party assets.
Data and sensitivity
IP address, request metadata, user agent, requested URL ; moderate
Controller / processor role
Convenient Licensing is the site controller; the production hosting/CDN processor is not yet verified.
Consent or other basis
Necessary to provide a user-requested page; final legal basis and production host approval remain Privacy/Legal decisions.
Retention
Production host/CDN retention is unverified and must be approved before deployment.
Deletion
Host/CDN deletion controls and request routing are unverified.
Failure behavior
The page or asset fails closed and no alternate third-party host is contacted.
Logging
No application telemetry is emitted; infrastructure access logging is unverified.
Destination
https://convenientlicensing.com

Guided-checkout session storage

State / direction
active; browser-local
Owner
Engineering
Purpose
Restore an unfinished guided-checkout selection in the current browser tab.
Data and sensitivity
profession, license states, plan selections, workflow step, service preferences ; moderate
Controller / processor role
First-party browser-local processing; no third-party processor.
Consent or other basis
Strictly functional storage used only after the user interacts with the guide.
Retention
Browser session only; sessionStorage is cleared when the tab session ends.
Deletion
Removed on explicit reset or browser session close.
Failure behavior
Storage errors are ignored and the guide continues without persistence.
Logging
Values are not logged or transmitted by the static site.
Destination
None configured

Google Analytics 4

State / direction
active; browser-to-third-party
Owner
Analytics
Purpose
Measure site usage and non-PII checkout funnel events.
Data and sensitivity
IP-derived metadata, device/browser metadata, page path, event data ; moderate
Controller / processor role
Google measures events as a processor; checkout payloads and contact fields are not sent as analytics parameters.
Consent or other basis
Owner-approved measurement of non-PII website and checkout-funnel events. Retention follows the GA4 property configuration.
Retention
Google Analytics retention follows the GA4 property configuration; no PII is intentionally sent.
Deletion
GA4 deletion and retention remain a Privacy operations concern for the property.
Failure behavior
A blocked analytics script does not stop checkout POSTs or Stripe redirect.
Logging
Funnel event names only; no name, email, phone, or document content.
Destination
https://www.googletagmanager.com, https://www.google-analytics.com, https://analytics.google.com, https://region1.google-analytics.com

Jotform contact form

State / direction
active; browser-to-third-party
Owner
Operations
Purpose
Collect general inquiries through the approved public contact form.
Data and sensitivity
contact details, message content, communication preferences ; variable
Controller / processor role
Jotform is a processor for general inquiries. This is not a DPA. Subprocessors remain Jotform-controlled.
Consent or other basis
User-initiated inquiry submission through the owner-approved Jotform contact form.
Retention
Jotform retains submissions under the Convenient Licensing Jotform account configuration.
Deletion
Jotform export and deletion are handled in the Jotform account, not this static site.
Failure behavior
Show phone, email, and user-initiated SMS alternatives with a sensitive-data warning.
Logging
The site emits no form submission logs.
Destination
https://form.jotform.com, https://submit.jotform.com

Jotform application intake and embed

State / direction
active; browser-to-third-party
Owner
Operations
Purpose
Collect licensing application information through the approved public intake form.
Data and sensitivity
identity, contact details, professional licensing records, uploaded documents ; high
Controller / processor role
Jotform is a processor for licensing application intake. This is not a DPA. Subprocessors remain Jotform-controlled.
Consent or other basis
User-initiated application submission through the owner-approved Jotform intake form.
Retention
Jotform retains submissions under the Convenient Licensing Jotform account configuration.
Deletion
Jotform export and deletion are handled in the Jotform account, not this static site.
Failure behavior
Show a fail-closed unavailable notice and direct users to confirm an approved channel.
Logging
The site emits no intake or iframe logs.
Destination
https://form.jotform.com

Stripe-hosted checkout navigation

State / direction
active; browser-to-third-party
Owner
Finance
Purpose
Collect billing and payment details after the Vercel API returns a Checkout Session URL.
Data and sensitivity
contact details, billing details, payment details, order identifiers ; high
Controller / processor role
Stripe hosts Checkout as a processor. The website never loads Stripe.js or collects card data. This is not a DPA.
Consent or other basis
User-initiated payment after GuidedCheckout creates a Stripe Checkout Session. A Stripe redirect is not proof of payment.
Retention
Stripe retains Checkout and payment records under the Stripe account configuration.
Deletion
Stripe customer/payment deletion is handled in the Stripe account, not this site.
Failure behavior
A missing Session URL keeps the user on /checkout with an on-page error.
Logging
No browser payment data or Stripe response is logged by this static site.
Destination
https://checkout.stripe.com

Guided checkout to Vercel checkout APIs

State / direction
active; browser-to-third-party
Owner
Engineering
Purpose
Submit a pay or quote request from GuidedCheckout to the environment-matched checkout API.
Data and sensitivity
profession and service selections, contact details on submit, Turnstile token, quote reference identifiers ; high
Controller / processor role
The Vercel checkout project is the existing production API. Secrets stay server-side there.
Consent or other basis
User-initiated review submit. Each website environment posts to its matching checkout API origin.
Retention
Checkout-service retention is controlled by the stripe-checkout repository.
Deletion
Deletion follows the checkout-service and Stripe account procedures.
Failure behavior
Failed POSTs stay on /checkout. Localhost and raw preview hosts need PUBLIC_CHECKOUT_API_ORIGIN.
Logging
The static site does not log request bodies or secrets.
Destination
https://api.dev.convenientlicensing.com, https://api.staging.convenientlicensing.com, https://api.convenientlicensing.com

Cloudflare Turnstile challenge

State / direction
active; browser-to-third-party
Owner
Security
Purpose
Bot challenge before checkout or quote submit.
Data and sensitivity
challenge token, browser/environment signals used by Turnstile ; moderate
Controller / processor role
Cloudflare evaluates the challenge; the site key is public.
Consent or other basis
Functional anti-abuse on the review submit step.
Retention
Cloudflare Turnstile retention follows Cloudflare’s service terms.
Deletion
Challenge tokens are short-lived and not stored by this static site.
Failure behavior
A failed or missing challenge blocks submit and keeps the user on /checkout.
Logging
The site does not log Turnstile tokens.
Destination
https://challenges.cloudflare.com

Checkout service to Stripe API

State / direction
active; server-to-third-party
Owner
Finance
Purpose
Verify Prices and create/reconcile Checkout Sessions.
Data and sensitivity
order identifiers, catalog metadata, customer reference, payment status ; high
Controller / processor role
Stripe is the payment processor for Checkout Sessions created by the checkout service. This is not a DPA.
Consent or other basis
Server-side Price verification and Checkout Session creation for the owner-approved public pay path.
Retention
Stripe retains payment records under the Stripe account configuration.
Deletion
Stripe customer/payment deletion is handled in the Stripe account, not this site.
Failure behavior
Timeouts and provider errors return stable non-sensitive errors; retries are bounded.
Logging
Safe event metadata only; secrets, provider bodies, and payment data are excluded.
Destination
https://api.stripe.com

Stripe webhook to checkout service

State / direction
active; third-party-to-server
Owner
Engineering
Purpose
Reconcile signed payment events with durable pending orders.
Data and sensitivity
Stripe event ID, session/order identifiers, payment status, amount ; high
Controller / processor role
Stripe sends signed webhook events to the checkout service. The success URL is not payment proof. This is not a DPA.
Consent or other basis
Signed Stripe webhook events reconcile payment status for the owner-approved public pay path.
Retention
Checkout-service and Stripe account retention apply to reconciled payment events.
Deletion
Webhook payloads are not stored by this static site; deletion follows checkout-service procedures.
Failure behavior
Reject invalid signatures, stale events, duplicates, and mismatched orders.
Logging
Security outcomes and opaque identifiers only; raw webhook bodies are not logged.
Destination
None configured

Managed customer portal navigation

State / direction
active; browser-to-third-party
Owner
Operations
Purpose
Allow existing Limited and Full Service customers to access their external portal.
Data and sensitivity
destination request metadata; portal data is entered after navigation ; high
Controller / processor role
The existing managed customer portal is an owner-approved destination for current Limited and Full Service clients. This is not a new portal integration or a DPA.
Consent or other basis
User-initiated navigation for existing customers under the owner-approved portal disclosure.
Retention
Portal-side retention is controlled by the existing portal operator.
Deletion
Portal export and deletion follow the existing customer-portal process.
Failure behavior
The portal opens in a separate tab; failure does not expose a fallback destination.
Logging
The static site does not log clicks; portal-side logging is unverified.
Destination
https://customerportal.convenientlicensing.com

Softr self-service portal navigation

State / direction
active; browser-to-third-party
Owner
Operations
Purpose
Allow existing self-service customers to access license tracking.
Data and sensitivity
destination request metadata; account and licensing data are entered after navigation ; high
Controller / processor role
The existing Softr self-service portal is an owner-approved destination for current self-service clients. This is not a new portal integration or a DPA.
Consent or other basis
User-initiated navigation for existing customers under the owner-approved portal disclosure.
Retention
Softr workspace retention is controlled by the existing Softr workspace.
Deletion
Softr export and deletion follow the existing self-service portal process.
Failure behavior
The portal opens in a separate tab; failure does not expose a fallback destination.
Logging
The static site does not log clicks; Softr-side logging is unverified.
Destination
https://myclportal.softr.app

User-initiated email

State / direction
active; browser-to-third-party
Owner
Operations
Purpose
Open the user’s configured email client for general support.
Data and sensitivity
email address, message content, mail transport metadata ; variable
Controller / processor role
Mailbox and transport providers are unverified; the user chooses their email provider.
Consent or other basis
User-initiated communication; users are warned not to email sensitive records.
Retention
Mailbox and sender-provider retention are unverified.
Deletion
Mailbox deletion and privacy-request routing are not yet verified.
Failure behavior
If no email client is configured, no message is sent.
Logging
The static site does not log or receive the draft.
Destination
mailto:Support@ConvenientLicensing.com

User-initiated SMS

State / direction
active; browser-to-third-party
Owner
Operations
Purpose
Open the user’s messaging application for a general question.
Data and sensitivity
phone number, message content, carrier metadata ; variable
Controller / processor role
Carrier/platform roles are unverified; no Twilio integration is active.
Consent or other basis
User-initiated communication; no automated marketing consent is inferred.
Retention
Device, carrier, and recipient retention are unverified.
Deletion
Carrier/device deletion is outside this site; business-side deletion handling is unverified.
Failure behavior
If SMS is unavailable, no message is sent and phone/email alternatives remain.
Logging
The static site does not log or receive the draft.
Destination
sms:

Programmatic SMS / Twilio

State / direction
disabled; server-to-third-party
Owner
Operations
Purpose
No approved automated SMS purpose or provider exists.
Data and sensitivity
No data transferred ; variable
Controller / processor role
No provider or role is approved.
Consent or other basis
No consent workflow is approved; automated SMS is disabled.
Retention
No production transfer or vendor-side retention occurs from this build while the flow is disabled.
Deletion
No production vendor record is created by this build; test data must be removed in the test system that created it.
Failure behavior
No API client, credential, request, or fallback vendor exists.
Logging
No automated SMS logs exist.
Destination
None configured

Obsolete automated form and email placeholders

State / direction
obsolete-removed; server-to-third-party
Owner
Operations
Purpose
No approved automated email or Formspree workflow exists.
Data and sensitivity
No data transferred ; variable
Controller / processor role
No provider or role is approved.
Consent or other basis
No production basis is approved; placeholder integrations are removed.
Retention
No production transfer or vendor-side retention occurs from this build while the flow is disabled.
Deletion
No production vendor record is created by this build; test data must be removed in the test system that created it.
Failure behavior
No API client, credential, submission, or fallback vendor exists.
Logging
No automated email or Formspree logs exist.
Destination
None configured

Checkout-service hosting on Vercel custom domains

State / direction
active; browser-to-first-party
Owner
Engineering
Purpose
Host the first-party checkout-service APIs and webhook boundary on owner-approved Vercel custom domains. Same-origin leftover handlers in this static repo are unused.
Data and sensitivity
request metadata, order identifiers, authorization state ; high
Controller / processor role
Convenient Licensing controls the checkout service; Vercel hosts it on api.dev, api.staging, and api.convenientlicensing.com.
Consent or other basis
Owner-approved production checkout-service deployment used by GuidedCheckout pay and quote requests.
Retention
Checkout-service retention is controlled by the stripe-checkout repository.
Deletion
Deletion follows the checkout-service and Stripe account procedures.
Failure behavior
A missing or failed checkout-service host keeps the user on /checkout; this static site does not fall back to same-origin /api/checkout routes.
Logging
The static site does not log checkout-host request bodies or secrets.
Destination
https://api.dev.convenientlicensing.com, https://api.staging.convenientlicensing.com, https://api.convenientlicensing.com

Obsolete Jotform API placeholder

State / direction
obsolete-removed; server-to-third-party
Owner
Engineering
Purpose
Record removal of an unused API-key example; no server-side Jotform client exists.
Data and sensitivity
No data transferred ; variable
Controller / processor role
No provider role was approved for this unused placeholder.
Consent or other basis
No processing basis existed; the placeholder was removed.
Retention
No production transfer or vendor-side retention occurs from this build while the flow is disabled.
Deletion
No production vendor record is created by this build; test data must be removed in the test system that created it.
Failure behavior
No API client, credential lookup, or request exists.
Logging
No server-side Jotform logs exist.
Destination
None configured

Obsolete Sentry monitoring placeholder

State / direction
obsolete-removed; server-to-third-party
Owner
Engineering
Purpose
Record removal of an unused DSN example; no Sentry SDK or telemetry client exists.
Data and sensitivity
No data transferred ; variable
Controller / processor role
No provider role was approved for this unused placeholder.
Consent or other basis
No processing basis existed; the placeholder was removed.
Retention
No production transfer or vendor-side retention occurs from this build while the flow is disabled.
Deletion
No production vendor record is created by this build; test data must be removed in the test system that created it.
Failure behavior
No SDK, DSN lookup, event capture, or request exists.
Logging
No Sentry logging exists.
Destination
None configured

Named providers are disclosed for Privacy publication. Google Analytics, Jotform contact and intake, Stripe Checkout, the first-party checkout APIs, and Cloudflare Turnstile are approved for the public website workflows recorded in the vendor inventory. Existing customer portals are disclosed for current clients. Programmatic SMS and transactional email remain disabled. This is not a DPA.

This build loads the governed analytics integration for page views and non-PII checkout funnel events. The guided checkout may POST quote or pay requests to the existing Vercel checkout APIs after Turnstile verification. Eligible selections may continue to Stripe Checkout. A browser return from Stripe is not a receipt. Preview and localhost origins cannot call that API under the current CORS allowlist unless PUBLIC_CHECKOUT_API_ORIGIN is set. The guided checkout uses session-only browser storage for licensing and service selections; it does not use cookies or persistent local storage.

Material Policy Register

The numbered sections above match the live combined legal page. “Approval-required” identifies an open internal decision. Naming an approver does not mean that person or function has signed off.

Privacy document dates

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal
Review state:
approved
Last reviewed:
2026-09-04

Privacy notice scope

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal, Operations, Security
Review state:
approved
Last reviewed:
2026-09-04

Privacy contact and retention

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal, Operations, Security
Review state:
approved
Last reviewed:
2026-09-04

Named vendor processor roles

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal, Operations, Security
Review state:
approved
Last reviewed:
2026-09-04

Google Analytics vendor approval

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal, Security, Analytics, Marketing
Review state:
approved
Last reviewed:
2026-09-04

JotForm vendor approval

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal, Security, Operations
Review state:
approved
Last reviewed:
2026-09-04

Checkout vendor approval

Version:
2026-09-05.2.policy.2
Effective date:
2026-09-04
Owner:
Privacy
Approvers:
Privacy, Legal, Security, Engineering, Operations, Finance
Review state:
approved
Last reviewed:
2026-09-04