Skip to content
All documents
Privacy PolicyVersion 1.0

PeopleCheck Online LLC

Privacy Policy

Version
1.0
Effective
Reference
PRIVACY-1.0

Privacy Policy

PeopleCheck Online LLC ("PeopleCheck", "we", "us") operates peoplecheck.online. This policy explains what personal information we handle, why, who we share it with, and the rights you have — whether you are a customer using the Service or a subject of a report someone else ran.

This policy takes effect on the date shown at the top of this page in the site footer. It covers the United States, the United Kingdom and Canada. We do not offer the Service in the European Economic Area and we block EEA traffic at the edge.


Not a consumer reporting agency

PeopleCheck is not a consumer reporting agency ("CRA") as that term is defined by the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq. ("FCRA"), and the information we return is not a "consumer report" under the FCRA.

We do not collect or assemble information for the purpose of furnishing consumer reports, and we do not verify the accuracy of the public and third-party data we surface.

You may not use PeopleCheck, in whole or in part, as a factor in establishing any person's eligibility for:

  • employment, promotion, reassignment or retention as an employee;
  • credit, a loan, or any extension of credit;
  • housing, tenancy or tenant screening;
  • insurance underwriting or pricing;
  • a professional or occupational licence;
  • any government benefit or licence granted on applicant financial capacity; or
  • any other purpose that is a "permissible purpose" under 15 U.S.C. § 1681b.

If you need information for any of those purposes, you must obtain it from a properly licensed consumer reporting agency that complies with the FCRA, including its adverse-action and dispute obligations.

You additionally may not use the Service to stalk, harass, intimidate, threaten, defraud or discriminate against any person, or in any way that violates the Driver's Privacy Protection Act, the Gramm-Leach-Bliley Act, any state anti-doxxing or anti-stalking statute, or any equivalent law of the United Kingdom or Canada.

Accounts used for a prohibited purpose are terminated without refund, and we reserve the right to report the activity to the relevant authorities.


1. Notice at collection

The table below is our CCPA/CPRA "notice at collection". It is also the honest summary for everyone else.

Category of personal informationExamples we handleWhyRetention
IdentifiersName, email address, account id, hashed IP addressCreate and secure your account, prevent abuseLife of account + 24 months
Commercial informationPlan, transaction history, refunds, chargebacksBilling, tax, fraud and dispute handling7 years (tax/financial record obligations)
Internet activityPages viewed, searches run, device type, referring URL, countryOperate the funnel, measure conversion, debug14 months in the raw event stream, then rollups only
Geolocation (coarse)Country derived from IP at the edgeGeographic eligibility, fraud scoringCountry stored; IP is never stored raw
Search subject dataName, profile URLs, employment, education, public posts, public contact details of the person searchedProduce the report you requestedPer your plan's retention entitlement; cache expires per provider TTL
InferencesTrust Score, risk band, confidence, match confidenceThe report itselfWith the report
Sensitive personal informationWe do not knowingly collect government identifiers, precise geolocation, health, biometric, racial, religious, union or sexual-orientation data, and we do not use any such data to infer characteristics

We never store a raw IP address. IP addresses are hashed with a keyed SHA-256 digest on receipt and only the digest is written to the database. It is used for rate limiting, duplicate-click detection and abuse investigation.

We do not sell personal information for money. Under the CCPA's broad definitions of "sell" and "share", some analytics and advertising-measurement activity can nevertheless count as a sale or a share. We therefore honour opt-out requests, and Global Privacy Control signals, as if it did. See section 6.

2. Where the information comes from

  • Directly from you — registration, checkout, support messages, opt-out forms.
  • Automatically — cookies, our first-party analytics, and server logs.
  • From payment processors — the outcome of a charge, the card brand and last four digits, and dispute notifications. We never receive or store your full card number.
  • From affiliates — if you arrived through a partner link we record the click identifier and the partner's pass-through parameters so we can pay them.
  • From public sources and licensed suppliers — for report subjects: search engines, public social profiles, and licensed people-data providers.

3. How we use it

To provide and secure the Service; to run and improve the search waterfall and the caching layer; to bill you and to detect payment fraud; to calculate affiliate commission; to answer support requests; to measure conversion; to comply with law; and to enforce our Terms.

We do not use your data to train machine-learning models, and no large language model is involved in generating your report.

4. Who we share it with

Recipient typePurposeNotes
Payment processorsTake payment, handle disputesThey are independent controllers for card data
Data suppliersFulfil a search you requestedThey receive the query, not your identity
Cloud hosting and email deliveryRun the ServiceBound by written processing terms
Affiliate partnersConfirm that a conversion occurredThey receive their own click id, the event type, the sale amount and the commission — never your name, email or report content
Professional advisers, authoritiesLegal claims, lawful requestsOnly where legally required or permitted

We do not disclose report content to advertisers.

5. International transfers

We host in the United States. If you are in the United Kingdom or Canada, your information is transferred to and processed in the US. For UK data we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses with our processors. For Canadian personal information we remain accountable under PIPEDA for the protection provided by our service providers.

6. Your rights

If you are in California (CCPA/CPRA), you may request to know the categories and specific pieces of personal information we hold, to delete it, to correct it, and to opt out of sale/sharing and of targeted advertising. You may also limit the use of sensitive personal information — although as noted we do not collect it. We will not discriminate against you for exercising a right.

If you are in another US state with a comprehensive privacy law — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana — you have substantially the same rights, plus a right to appeal a refusal. We apply the same process to everyone, wherever you live.

If you are in the United Kingdom (UK GDPR / Data Protection Act 2018), you have rights of access, rectification, erasure, restriction, portability and objection, and you may complain to the Information Commissioner's Office.

If you are in Canada (PIPEDA and provincial equivalents, including Quebec's Law 25), you have rights of access and correction, a right to withdraw consent, and a right to complain to the Office of the Privacy Commissioner of Canada.

How to exercise a right

  • Use the "Do Not Sell or Share My Personal Information" link in the footer of every page, or the Privacy Requests form; or
  • email privacy@peoplecheck.online from the address on your account.

We verify a request before acting on it, by emailing a one-time link to the address in the request. An authorised agent may submit on your behalf with written permission that we can verify.

Timing. We acknowledge within 10 business days and respond substantively within 45 calendar days, extendable once by a further 45 days where the request is complex — we will tell you if that happens. UK requests are answered within one month.

If you are the subject of a report

You do not need an account. Submit an opt-out with your name and, if you have one, the report reference. Verified subjects are added to a permanent suppression list: the canonical record is excluded from every future search result and the cached data is purged. Suppression is stored as a one-way key so that honouring it does not require us to keep a profile of you.

7. Retention and deletion

Retention periods appear in the notice-at-collection table. In addition:

  • Provider responses are cached only for the TTL configured per provider — between 5 minutes and 30 days — and are keyed on the normalised query.
  • Raw funnel events are retained for 14 months, then only daily rollups remain.
  • Financial records are retained for 7 years to satisfy tax and chargeback rules; a deletion request does not remove them, and we will tell you that.
  • Deleted accounts are soft-deleted immediately (removed from every interface) and hard-deleted on the next scheduled purge.

8. Security

Passwords are stored as salted scrypt digests — never in plaintext and never recoverable. Provider and payment-gateway credentials are encrypted at rest with AES-256-GCM and are decrypted only inside the server-side domain layer; they are never returned to a browser. Sessions are signed, httpOnly cookies. Locked report fields are removed on the server before the response is sent — they are not merely visually hidden. Every privileged administrative action is written to an immutable audit log.

No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and the relevant regulators as required by applicable law.

9. Children

The Service is not directed to anyone under 18 and we do not knowingly collect personal information from children. If you believe a child has given us information, contact privacy@peoplecheck.online and we will delete it.

10. Changes

We will post any change here and update the version. Material changes are emailed to account holders at least 14 days in advance.

11. Contact

PeopleCheck Online LLC PeopleCheck Online LLC, Legal Department, 8 The Green, Suite 17337, Dover, DE 19901, United States Privacy: privacy@peoplecheck.online · Support: support@peoplecheck.online

Source PeopleCheck Online LLCv1.0
CookiesYour choice

We use essential cookies to keep you signed in, and analytics cookies to see which parts of the funnel work. You can decline the second kind and nothing else changes.

Cookie policy