Privacy Policy
Last updated 2026-08-11
CredScape is a market-intelligence data product for higher education, operated by CredScape Market Intelligence Inc. We aggregate and structure publicly available information about non-credit and micro-credential programs offered by Canadian and US post-secondary institutions and platform providers. Our customers are continuing and professional education units inside universities and colleges. They purchase annual subscriptions billed by invoice and purchase order, with access allocated through assigned seats.
This policy explains how we collect, use, disclose, retain and protect personal information. We are the controller of our own account data, not a processor acting on a customer's behalf. Questions about this policy can be sent to privacy@credscape.io.
CredScape Market Intelligence Inc. is incorporated federally under the Canada Business Corporations Act and registered extraprovincially in British Columbia. British Columbia's Personal Information Protection Act governs our collection, use and disclosure of personal information in British Columbia. Alberta's Personal Information Protection Act applies if the customer is in Alberta. The Personal Information Protection and Electronic Documents Act applies to personal information transferred across borders, including through Resend, Google Analytics and Cloudflare. Quebec Law 25 applies to personal information of Quebec residents.
Account and customer data
We collect each user's name, email address, organization, role and seat assignment. We also record saved searches, comparable sets and export actions. We use this information to operate the service and meter usage against subscription entitlements.
We collect and use this information to perform the customer's subscription agreement, and with consent where required. Account data is kept for the life of the subscription and deleted or anonymized within 90 days after termination. Product event records are retained for usage accounting.
We do not sell personal information. We do not use it for advertising. We do not disclose it to data brokers.
Website visitors, prospects and cookies
We collect contact details submitted through demo requests, access requests and the launch notification list. We automatically collect IP address, browser type, pages visited and session duration.
The site uses these cookies:
| Cookie | Purpose | Retention |
|---|---|---|
sb-ljetjuxexqxwaafufdrg-auth-token |
Authentication session, strictly necessary | Session |
_ga, _ga_1JL43K5NKV |
Google Analytics, understanding site usage | 2 years |
__cf_bm |
Cloudflare bot management, strictly necessary | 30 minutes |
Google Analytics 4 is the only tracker on the site. Non-essential cookies are off until accepted: we use Cookiebot (Usercentrics A/S) to ask for consent and to record your choice, and nothing beyond strictly necessary cookies is set until you accept. You can change or withdraw consent at any time through the "Cookie settings" link in the footer, and the full list is in our Cookie Policy. You can use your browser settings to manage or disable cookies. The site does not currently respond to Do Not Track signals.
We send marketing email only with express or implied consent. Every message includes our mailing address and a working unsubscribe link. We honour unsubscribe requests within 10 business days.
Our data sources
Our program corpus consists of institution-level and program-level information published publicly by post-secondary institutions and platform providers. It is not personal information.
We do not retain instructor names or contact details. Information of that kind was removed from the corpus in July 2026, and our ingestion process excludes it.
If you believe personal information appears in the corpus, the data requests page explains how to have it corrected or removed.
Security
- Passwords are stored only as bcrypt hashes by our authentication provider and are never accessible to our code or our team.
- Passwords must contain at least twelve characters. Passwords appearing in known breach corpora are rejected, and changing a password requires reauthentication.
- Time-based one-time password, or TOTP, multi-factor authentication is available.
- Sessions expire after seven days of inactivity or thirty days in total, whichever comes first. Refresh tokens rotate on use.
- Row Level Security is enabled on every table in the application schema, so a user from one institution cannot read another institution's data.
- All traffic is encrypted with TLS. Databases and storage are encrypted at rest.
- Service-role credentials are held server-side and never exposed to browser code.
- Automated database backups run daily and are retained for seven days. Independent weekly backups are held off-platform for ninety days. Restores are tested quarterly.
Account records, the program corpus and vector indexes are stored in Canada using Supabase and AWS ca-central-1. Semantic search ranking runs on a server in Beauharnois, Quebec. That server performs computation only and stores nothing.
Transactional email through Resend in the United States, product analytics through Google Analytics in the United States, and application delivery through Cloudflare's global edge involve processing outside Canada.
Subprocessors
Every subprocessor with access to personal information is bound by a written data processing agreement with protections no less than those in our customer agreements. We provide thirty days' advance written notice before a new subprocessor begins processing personal information and allow a thirty-day objection window. See the full subprocessor table.
Your rights and how to exercise them
You may request access to, correction of, deletion of or portability of your personal information, or withdraw your consent. Send your request to privacy@credscape.io. We answer requests within 30 days.
To verify your identity, we need your full name, the email address on your account, your organization and the specific right you are exercising.
Depending on which law applies, you may complain to the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information du Québec.
Breach notification
We maintain a register of confidentiality incidents and record every breach of security safeguards, whether or not it presents a real risk of significant harm. We retain each entry for five years.
Where a breach presents a real risk of significant harm, we notify affected individuals, affected customer organizations and the applicable regulator without delay.
Changes to this policy
We notify you of material changes by email or a prominent notice on the site at least thirty days before they take effect.
Contact and privacy officer
François Lachapelle is our designated Privacy Officer. Contact him at privacy@credscape.io or by mail:
CredScape Market Intelligence Inc.
Attention: Privacy Officer
214-1111 Frost Road
Kelowna, British Columbia V1W 0G8
Canada
For general support, contact support@credscape.io. Our website is credscape.io.