Trade License HQ
  • Tour
  • Pricing
  • Get Early Access
Back to Legal

Privacy Policy

Trade License HQ Effective Date: April 7, 2026 Last Updated: May 1, 2026


1. Introduction

Trade License HQ ("Trade License HQ," "we," "us," or "our") is a B2B SaaS compliance management platform operated by Ritt & Royce, doing business as Ritt & Royce and Trade License HQ, a company headquartered in Michigan, United States. Our platform helps trade businesses — including electricians, plumbers, and general contractors — track employee licences, company certifications, and job-site permits, and receive automated expiry reminders before documents lapse.

This Privacy Policy explains how we collect, use, disclose, and protect information about you and your organization when you use the Trade License HQ website and platform (collectively, the "Service"). It also describes your rights regarding your personal data.

We are committed to handling your data transparently and responsibly. We do not sell your personal information. We collect only what is necessary to operate the Service, and we share data with third parties only as described in this Policy.

Who this Policy covers. This Policy applies to: - Administrators and users who create and maintain a Trade License HQ account ("Account Users"); - Individuals whose information is entered into the platform by Account Users (e.g., employee licence and certification records); - Subcontractors and guests who upload documents via our guest portal without creating an account ("Guest Users"); - Visitors to our website at tradelicensehq.com.

Who this Policy does not cover. This Policy does not govern the data practices of your employees or subcontractors. You, as the Account User, are responsible for ensuring you have appropriate authority to enter third-party employee data into the platform and for providing any required notices to those individuals.

If you have questions about this Policy, please contact us at info@tradelicensehq.com.


2. Information We Collect

We collect information in the following ways:

2.1 Information You Provide Directly

Account Registration. When you create a Trade License HQ account, you provide: - Full name - Email address - Password (stored as a cryptographic hash using Werkzeug/bcrypt — we never store your password in plaintext) - Company or organization name

Employee and Workforce Records. When you add workers to the platform, you enter: - Employee name - Job title - Business unit or department

This information is entered by you on behalf of your organization. We do not collect this information directly from the employees themselves.

Certification and Licence Data. When you track credentials in the platform, you enter: - Licence or certification type (e.g., OSHA 10, journeyman electrician licence, first aid certificate) - Licence number - Issuing authority - Date of issue - Expiry date - Certification status

Uploaded Documents. You may upload scanned or photographed licence and certificate documents in PDF, JPG, or PNG format (up to 16 MB per file). These documents may contain personal information visible on the face of the credential.

OCR Processing. Our platform offers an OCR (optical character recognition) feature to extract data from uploaded documents. This OCR processing is performed entirely within your web browser using the open-source Tesseract.js library. No document data is transmitted to any third-party OCR service. Document content is only transmitted to our servers after you review the extracted data and explicitly confirm the upload.

Project and Permit Data. When you create a project, you enter: - Project name - Job site address - Permit type (e.g., building, electrical, plumbing) - Permit number - Permit expiry date

AI and Automated Processing. Trade License HQ does not currently offer any artificial intelligence (AI)-powered features directly to users through the platform interface. However, Ritt & Royce d/b/a Trade License HQ reserves the right to use AI tools, automated processing systems, or machine learning technologies internally in connection with the processing, review, analysis, storage, or management of data and materials submitted to or through the Service. Such use may include, but is not limited to, internal document review, data quality analysis, system operations, or service improvement activities.

Additionally, we may introduce AI-powered features accessible to users in the future. If and when such features are introduced, we will update these policies and provide appropriate notice.

By using the Service, you acknowledge and consent to the potential use of AI and automated tools in the internal processing of your data and materials as described above. We do not guarantee the accuracy of any AI-generated or automated output. You are solely responsible for reviewing and verifying all results produced by the Service.

Communications with Us. If you contact our support team by email or through the platform, we retain those communications to help resolve your inquiry.


2.2 Information Collected Automatically

Session Cookie. When you log in, we set a session cookie that keeps you authenticated for up to 7 days. This cookie is essential to the operation of the Service. See our separate Cookie Policy for full details.

Login and Usage Data. We automatically record: - Login timestamps and IP address at the time of login - Plan type and subscription tier - Feature usage events (e.g., which platform features you access, how frequently) - Browser type and operating system (collected by Plausible Analytics — see below)

Web Analytics. We use Plausible Analytics, a privacy-respecting analytics provider, to understand how visitors use our website and platform. Plausible does not use cookies. It does not track individuals across websites. It does not collect any personally identifiable information. The data Plausible collects includes page views, referral source, device type, and country-level location. Plausible is operated in the European Union and is designed to be compliant with GDPR, CCPA, and PECR without requiring cookie consent. For more information, see the Plausible Data Policy.


2.3 Information from Third Parties

Stripe (Payment Confirmation). When you purchase a subscription, payment is processed by Stripe. Stripe provides us with a confirmation of successful payment and your billing address for tax purposes. We do not receive or store your credit card number, CVV, or full bank account details. Stripe handles all payment card data and is PCI-DSS compliant. For more information, see Stripe's Privacy Policy.

We do not receive personal data about you from any other third-party sources.


2.4 Information Collected via the Subcontractor Guest Portal

We offer a guest upload portal that allows subcontractors and third-party workers to submit compliance documents without creating an account. When a Guest User uploads documents through a portal link provided by your organization:

  • We collect the document(s) uploaded (PDF, JPG, or PNG)
  • We record the time and date of the upload
  • We record the unique link identifier associated with the uploading organization's account
  • We do not require or collect the guest's name, email address, or any account credentials

Guest User submissions are associated with the inviting organization's account and are visible to that organization's Account Users.


3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Providing and Operating the Service

We use your account data, employee records, certification data, uploaded documents, and project/permit data to deliver the core features of the platform — including licence tracking dashboards, expiry status reporting, compliance reports, CSV data export, and the subcontractor guest portal.

3.2 Sending Expiry Reminders

The primary operational function of Trade License HQ is to notify your organization when licences, certifications, or permits are approaching their expiry dates. We use your email address and notification preferences to send these automated reminder emails via SendGrid (a Twilio service). These reminders are a core feature of the Service, not marketing communications, and cannot be disabled without impairing the function of the platform.

3.3 Processing Payments

We use your account and billing information to initiate and manage subscription payments through Stripe, to apply plan changes, and to send billing receipts and renewal notices.

3.4 AI and Automated Processing

Trade License HQ does not currently offer any artificial intelligence (AI)-powered features directly to users through the platform interface. However, Ritt & Royce d/b/a Trade License HQ reserves the right to use AI tools, automated processing systems, or machine learning technologies internally in connection with the processing, review, analysis, storage, or management of data and materials submitted to or through the Service. Such use may include, but is not limited to, internal document review, data quality analysis, system operations, or service improvement activities.

Additionally, we may introduce AI-powered features accessible to users in the future. If and when such features are introduced, we will update these policies and provide appropriate notice.

By using the Service, you acknowledge and consent to the potential use of AI and automated tools in the internal processing of your data and materials as described above. We do not guarantee the accuracy of any AI-generated or automated output. You are solely responsible for reviewing and verifying all results produced by the Service.

3.5 Improving the Service

We use anonymized, aggregated usage data and web analytics (via Plausible) to understand which features are used, identify usability issues, and prioritize product improvements. This data does not identify individual users.

3.6 Communicating Service Updates and Security Notices

We use your email address to send you: - Transactional notifications essential to your use of the Service (password resets, account changes) - Security alerts (e.g., notifications of unauthorized access attempts or data breaches) - Product update announcements and material changes to our terms or this Policy

You cannot opt out of transactional and security communications while your account is active, as they are necessary for the operation and security of the Service.

3.7 Complying with Legal Obligations

We may use and retain your data as required to comply with applicable laws, including Michigan's Identity Theft Protection Act (MCL 445.63), tax and accounting record-keeping requirements, and valid legal process (subpoenas, court orders).


4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, the following legal bases apply to our processing of your personal data under the General Data Protection Regulation (GDPR) and applicable UK data protection law:

Processing Activity Legal Basis
Creating and maintaining your account Contractual necessity — processing is required to perform the contract for the Service you have entered into with us
Delivering core platform features (licence tracking, reminders, reporting) Contractual necessity
Processing subscription payments via Stripe Contractual necessity
Sending expiry reminder emails Contractual necessity — reminders are a core contractual feature, not optional marketing
AI and automated processing of submitted data and documents Contractual necessity and Legitimate interests
Security monitoring, fraud prevention, abuse detection Legitimate interests — we have a legitimate interest in keeping the Service and your data secure
Web analytics via Plausible (no personal data collected) Legitimate interests — Plausible collects no personal data; analytics are used to improve the Service
Retaining billing records Legal obligation — tax and accounting laws require retention of financial records
Responding to legal process or regulatory inquiries Legal obligation
Sending optional marketing communications (if any) Consent — you may withdraw consent at any time
Breach notification Legal obligation — Michigan Identity Theft Protection Act and applicable EU supervisory authority requirements

Where we rely on legitimate interests, you have the right to object to that processing. See Section 9 for how to exercise your rights.


5. How We Share Your Information

We do not sell your personal information. We do not rent, trade, or broker access to your personal data to third parties for their own commercial purposes.

We share your information only in the following circumstances:

5.1 Service Providers and Sub-Processors

We share data with a limited number of third-party vendors who process data on our behalf to help us operate the Service. These vendors are contractually bound to use your data only for the purposes we specify and to maintain appropriate security. See Section 6 for the full sub-processor table.

5.2 Stripe — Payment Processing

We share your billing information (name, email, billing address) with Stripe to process subscription payments. Stripe processes payment card data directly; we do not receive or store card numbers.

5.3 SendGrid / Twilio — Email Delivery

We share your email address and the content of automated notifications (expiry reminders, account alerts) with SendGrid, a Twilio service, to deliver transactional emails on our behalf.

5.4 AI Processing Service Providers

We may share data with AI tool providers or automated processing services that assist in processing uploaded documents and platform data on our behalf. Any such providers are bound by appropriate data processing agreements and may not use your data for their own purposes.

5.5 Hosting Infrastructure

Your account data, employee records, certification data, documents, and usage data are stored on servers operated by [Hosting Provider] in the United States. [Hosting Provider] provides the underlying database and server infrastructure on which Trade License HQ runs.

5.6 Legal Requirements and Law Enforcement

We may disclose your information if we believe disclosure is required by applicable law, regulation, valid legal process (e.g., a subpoena, court order, or government request), or to protect the rights, property, or safety of Trade License HQ, our users, or the public. Where permitted by law, we will notify you of such a request.

5.7 Business Transfers

If Trade License HQ is involved in a merger, acquisition, asset sale, bankruptcy, or similar transaction, your information may be transferred to the successor entity. We will provide you with at least 30 days' notice by email before your data becomes subject to a materially different privacy policy.

5.8 With Your Consent

We may share your information in other ways if you specifically direct us to or give your explicit consent.


6. Sub-Processors

The following third-party sub-processors may access or process personal data in connection with the Service:

Sub-Processor Location Data Accessed Purpose Privacy Policy
Stripe, Inc. San Francisco, CA, USA Name, email address, billing address, payment card details Subscription payment processing stripe.com/privacy
Twilio / SendGrid San Francisco, CA, USA Email address, email content (notification body) Transactional email delivery (expiry reminders, system alerts) twilio.com/en-us/legal/privacy
AI/Automated Processing Providers United States Uploaded document content and compliance data (as applicable) Internal AI-assisted data processing and analysis (no AI features currently exposed to users; future user-facing AI features may be introduced) Subject to applicable DPAs
[Hosting Provider] United States All account, employee, certification, document, and project data Server and database infrastructure hosting TBD
Plausible Analytics European Union Page views, referral source, device type, country (no personal data) Privacy-friendly web analytics plausible.io/data-policy

Tesseract.js is an open-source OCR library that runs entirely within your web browser. It does not transmit data to any third party and is therefore not a sub-processor.

We maintain this list and update it when sub-processors change. If we add a new sub-processor that will access personal data, we will update this Policy and, where required, provide advance notice.


7. Data Retention

We retain your data for as long as necessary to provide the Service and fulfill the purposes described in this Policy. The following retention periods apply:

Data Category Retention Period
Account data (name, email, company, password hash) Retained while your account is active
Employee records, certification data, uploaded documents Retained while your account is active
Project and permit data (active) Retained while your account is active
Archived projects Retained indefinitely while your account is active (read-only, preserved for compliance audit history)
Internal AI/automated processing logs (if applicable) 90 days, then permanently deleted
Email and notification delivery logs 12 months
Login timestamps and session records 12 months
Subcontractor guest portal submissions Retained as long as the inviting organization's account remains active
Billing records and invoices 7 years (required by applicable tax and accounting law)
Data following account cancellation Available for export for 30 days after cancellation; permanently deleted within 60 days of cancellation

Account Cancellation. Upon cancellation of your subscription, your account enters a 30-day export window during which you may download your data using the platform's CSV export feature. After 60 days from cancellation, all account data, employee records, certification data, documents, and project data are permanently deleted from our systems, with the exceptions noted above (billing records, which are retained for legal compliance).

We may retain data for longer periods if required by applicable law or to resolve disputes, enforce agreements, or comply with legal obligations.


8. Data Security

We take reasonable and appropriate technical and organizational measures to protect your information against unauthorized access, disclosure, alteration, and destruction. These measures include:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
  • Password Hashing: User passwords are never stored in plaintext. We use Werkzeug's password hashing functions (based on bcrypt) to store passwords as irreversible cryptographic hashes.
  • Database Access Controls: Access to our production database is restricted to authorized personnel and systems. Database access is not exposed to the public internet.
  • CSRF Protection: Our platform implements Cross-Site Request Forgery (CSRF) protection to prevent unauthorized actions on authenticated sessions.
  • Principle of Least Privilege: Internal access to user data is restricted to personnel who require access to perform their job functions.
  • Session Management: Authentication sessions expire after 7 days. Sessions are invalidated upon logout.

No system is 100% secure. Despite our efforts, no method of data transmission or electronic storage is completely secure. We cannot guarantee absolute security of your data.

Breach Notification. In the event of a security breach involving your personal information, we will notify affected users as required by Michigan's Identity Theft Protection Act (MCL 445.63) within 30 days of discovering the breach. If the breach affects 100 or more Michigan residents, we will also notify the Michigan Attorney General. Where GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.


9. Your Rights and Choices

9.1 All Users

Regardless of your location, you have the following rights with respect to your personal data:

  • Access: You may request a copy of the personal data we hold about your account.
  • Correction: You may update or correct inaccurate account information at any time through your account settings, or by contacting us.
  • Deletion: You may request deletion of your account and associated personal data. See Section 7 for applicable retention periods that may apply notwithstanding a deletion request.
  • Data Export: The platform includes a built-in CSV export feature. You may export your employee records, certification data, and project data at any time from within the platform.
  • Account Closure: You may close your account at any time from your account settings. Upon closure, the retention schedule in Section 7 applies.
  • Notification Preferences: You may update your email notification preferences from within your account settings.

9.2 California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with additional rights:

  • Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purpose for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions (e.g., legal compliance, completion of a transaction).
  • Right to Correct: You have the right to request correction of inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. You therefore do not need to submit an opt-out request. If our practices change, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" link.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond those necessary to provide the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights — we will not deny you service, charge you a different price, or provide a lower quality of service.

Note on B2B Data. The CCPA applies primarily to personal information collected from consumers. Our Service is designed for businesses, and much of the data we collect is provided by businesses in a B2B context. Certain CCPA rights may not apply to all categories of data we process.

9.3 EEA and UK Residents (GDPR / UK GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR and UK GDPR:

  • Right of Access (Article 15): You have the right to obtain confirmation that we process your personal data and to receive a copy of that data.
  • Right to Rectification (Article 16): You have the right to have inaccurate personal data corrected and incomplete data completed.
  • Right to Erasure (Article 17): You have the right to request deletion of your personal data ("the right to be forgotten"), where applicable grounds exist (e.g., the data is no longer necessary for the purpose it was collected).
  • Right to Restriction of Processing (Article 18): You have the right to request that we restrict processing of your personal data in certain circumstances (e.g., while accuracy is contested).
  • Right to Data Portability (Article 20): Where processing is based on consent or contractual necessity and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Article 21): You have the right to object to processing based on legitimate interests, including for direct marketing purposes.
  • Right to Withdraw Consent: Where we process your data on the basis of consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority. In the EU, you may contact the supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. In the UK, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.

9.4 How to Exercise Your Rights

To exercise any of the rights described in this Section, please contact us at:

Email: info@tradelicensehq.com Subject line: "Privacy Rights Request"

We may need to verify your identity before processing your request. For Account Users, verification will be performed by confirming your identity against the registered account email address. We will respond to your request within 30 days. If we need additional time (up to 60 days for complex requests), we will notify you within the initial 30-day period.


10. Cookies and Tracking Technologies

We use a minimal set of cookies. Below is a summary; please see our separate [Cookie Policy] for complete details.

10.1 Authentication Session Cookie

We use a single first-party session cookie to keep you logged in to your account. This cookie is set when you authenticate and expires after 7 days (or when you log out). This cookie is essential to the operation of the Service — the platform cannot authenticate your requests without it. Disabling this cookie in your browser will prevent you from logging in.

10.2 Plausible Analytics — No Cookies

We use Plausible Analytics to understand aggregate usage of our website and platform. Plausible is specifically designed to be privacy-respecting: it does not use cookies, does not collect personally identifiable information, does not track users across websites, and does not build individual user profiles. The data collected (page views, referral source, device type, country) is entirely anonymous. No cookie consent banner is required for Plausible because no cookies are used and no personal data is collected.

10.3 What We Do Not Use

We do not use: - Third-party tracking cookies - Advertising or retargeting pixels (e.g., Google Ads, Facebook Pixel, LinkedIn Insight Tag) - Social media tracking scripts - Cross-site behavioral tracking of any kind


11. Children's Privacy

The Trade License HQ Service is designed for use by businesses and their adult employees and contractors. The Service is not directed at children under the age of 18 and is not intended for use by minors.

We do not knowingly collect personal information from any person under the age of 18. If you are a parent or guardian and believe that a minor has provided us with personal information, please contact us at info@tradelicensehq.com, and we will take steps to delete that information promptly.


12. International Data Transfers

Trade License HQ is operated by a Michigan-based company. Your data is stored and processed in the United States, on servers operated by [Hosting Provider].

For users outside the United States: If you access our Service from outside the United States, please be aware that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For EEA and UK residents: The United States does not have an adequacy decision from the European Commission for all transfers. Where we transfer personal data from the EEA or UK to the United States (specifically, when using sub-processors such as Stripe, SendGrid/Twilio, and AI/automated processing providers), we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), to ensure your data is protected to a standard equivalent to that required within the EEA. You may request a copy of the relevant SCCs by contacting us at info@tradelicensehq.com.


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, applicable law, or regulatory requirements.

Material changes — those that significantly affect how we process your personal data or reduce your rights — will be communicated to you by email to your registered address at least 30 days before they take effect. For non-material changes (such as clarifications, corrections, or additions of new sub-processors with equivalent protections), we will update the "Last Updated" date at the top of this Policy and, where appropriate, post a notice within the platform.

Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you may close your account before the new Policy takes effect.

We will maintain prior versions of this Policy and make them available upon request.


14. Contact Us

If you have questions, concerns, or complaints about this Privacy Policy, or wish to exercise your rights as described in Section 9, please contact us:

Email: info@tradelicensehq.com Company: Ritt & Royce d/b/a Ritt & Royce / Trade License HQ Address: Michigan, United States

For formal data protection inquiries, please use the subject line "Privacy Rights Request" or "Data Protection Inquiry" so we can route your message appropriately.

If you are an EEA resident and believe we have not addressed your concern satisfactorily, you have the right to lodge a complaint with your local supervisory authority. If you are a UK resident, you may contact the Information Commissioner's Office at ico.org.uk.


This Privacy Policy was prepared for Trade License HQ and is effective as of April 7, 2026. Last updated May 1, 2026.

Back to Legal
Product
Tour Pricing FAQ Try Demo
Company
About Contact Early Access
Legal
Legal Hub Privacy Policy Terms of Service Cookie Policy
Account
Login Register
Trade License HQ © 2026  ·  Ritt & Royce info@tradelicensehq.com

We use a single session cookie to keep you signed in. No tracking or advertising cookies are used. Cookie Policy

Plan Limit Reached

You've reached the limit on your current plan.

Upgrade to Pro to unlock up to 15 employees, unlimited certifications, and 10 active projects.

Upgrade to Pro

Send us feedback

Thanks for your feedback!