Legal
Last updated August 2, 2026
Privacy Policy
Effective date: August 2, 2026
This Privacy Policy explains how Corkboard Software Inc. (“Corkboard”, “we”, “us”), an Ontario, Canada corporation, collects, uses, stores, and shares information when you use our websites, including corkboardhq.com, and our employee onboarding, document, training, and mentorship platform (together, the “Service”).
Corkboard is built for businesses. Our customers are employers (“Customers”) who invite their staff (“Team Members”) to use the Service. When we process Team Member information inside a Customer’s workspace, we do so on behalf of and at the direction of that Customer. Team Members should direct questions about their employer’s practices to their employer; questions about our practices can come to us directly at support@corkboardhq.com.
1. Information we collect
Account information. Name, email address, phone number, password or authentication credentials, role, and workspace membership.
Customer content. Content that Customers and Team Members add to the Service, including handbooks, policies, training materials, videos, quizzes and quiz responses, tasks, mentor feedback, welcome wall posts, and documents uploaded for review or signature.
Electronic signature records. When a document is signed through the Service, we record the signer’s name, drawn or typed signature, the date and time, IP address, device and browser information, and a cryptographic hash of the signed document. These records exist to provide a reliable audit trail and are retained as part of the signed document.
Verification media. Photos or videos that Team Members submit to demonstrate completion of training or tasks, where a Customer enables this feature.
Billing information. Payment details are collected and processed by our payment processor, Stripe. We store subscription status and invoice history, not full payment card numbers.
Usage and device information. Log data, pages viewed, features used, approximate location derived from IP address, and diagnostic information, collected directly and through analytics providers.
Support communications. Messages you send us, including email to support@corkboardhq.com.
2. Google Workspace data
This section describes our handling of information received from Google APIs. It applies when a Customer’s Google Workspace administrator chooses to connect Google Workspace to Corkboard.
What we access. With the administrator’s explicit OAuth consent, Corkboard accesses the Google Admin SDK Directory API and, where applicable, the Enterprise License Manager API, limited to the scopes the administrator grants. We use this access solely to: (a) create Google Workspace user accounts for new Team Members at the direction of the Customer; (b) check license availability before account creation; (c) deliver initial sign-in credentials with a required password reset; and (d) suspend accounts when a Customer initiates offboarding.
What we do not do. We do not read email or calendar content, access files in Google Drive, or collect Google Workspace data beyond what is required for the account provisioning features described above. We do not sell Google user data, use it for advertising, or use it for any purpose other than providing and improving the provisioning features that the Customer has requested.
AI/ML. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
Storage and security. OAuth tokens are encrypted at rest using industry-standard encryption and are accessible only to the systems that perform provisioning. Provisioning actions are recorded in an audit log available to the Customer.
Revoking access. A Customer administrator can disconnect Google Workspace at any time in Corkboard settings, or revoke Corkboard’s access from their Google Admin console or Google Account security settings. On disconnection, we delete the associated tokens.
Limited Use disclosure. Corkboard’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use information
We use information to: provide, operate, and secure the Service; create and manage workspaces, onboarding flows, and Team Member accounts; generate and retain electronic signature records; deliver notifications, reminders, and credential emails; provide customer support; process payments; monitor performance and fix problems; understand how the Service is used so we can improve it; and comply with legal obligations.
AI features. Where a Customer uses AI-assisted features (for example, converting an uploaded handbook into structured onboarding content), the relevant Customer content is processed by our AI service providers to generate draft output for the Customer’s review. We do not permit our AI providers to use Customer content to train their general-purpose models, and AI-generated output is always presented as a draft for human review before publication.
We do not sell personal information, and we do not use Customer content or Team Member personal information for third-party advertising.
4. How we share information
We share information only with:
Service providers (subprocessors). Vendors that host and support the Service under contractual confidentiality and data protection obligations, currently including: Vercel (application hosting), Neon (database), Cloudflare (file and video storage and delivery), Stripe (payments), Resend (transactional email), Google (Workspace provisioning, where connected by the Customer), AI model providers (AI-assisted features), Inngest (background job processing), Sentry (error monitoring), and PostHog (product analytics).
Within a workspace. Content is visible to other members of a Customer’s workspace according to the roles and visibility rules the Customer configures. For example, mentor feedback marked manager-only is not shown to the Team Member, and welcome wall posts are visible to the workspace.
Legal and safety. Where required by law, legal process, or to protect the rights, safety, and property of Corkboard, our Customers, or others.
Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy’s commitments.
5. Where information is stored
Our Service is hosted in the United States. If you use the Service from Canada or elsewhere, your information will be transferred to, stored, and processed in the United States, where it may be subject to access by U.S. authorities under applicable law. We use contractual and technical safeguards with our service providers to protect information wherever it is processed.
6. Retention
We retain information for as long as the Customer’s account is active or as needed to provide the Service. Signed documents and their audit trails are retained as part of the Customer’s records for as long as the Customer maintains them or as required by law. When a Customer account is closed, we delete or de-identify Customer content within 30 days, except where retention is required by law, needed to resolve disputes, or preserved in routine backups that expire on a defined schedule.
7. Security
We protect information using encryption in transit and at rest, role-based access controls, tenant isolation, audit logging, and least-privilege access for our systems and personnel. No method of transmission or storage is completely secure; if we become aware of a breach affecting your information, we will notify affected Customers and regulators as required by applicable law, including PIPEDA’s breach reporting requirements.
8. Your rights and choices
Subject to applicable law, you may request access to, correction of, or deletion of your personal information. Team Members’ information within a workspace is controlled by their employer, so we may refer requests about workspace content to the relevant Customer and act on the Customer’s instructions. To make a request, contact support@corkboardhq.com. We will respond within the timelines required by applicable law.
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. If you are unsatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
You can opt out of non-essential product emails using the unsubscribe link in those emails. Transactional messages (such as signature requests and credential delivery) are necessary to the Service and cannot be opted out of while your account is active.
9. Children and minor employees
The Service is not directed to children, and we do not knowingly collect personal information from anyone under 13. Some Customers lawfully employ workers under the age of majority (for example, sports officials or performers). Where a Customer invites a minor Team Member, the Customer is responsible for ensuring the employment is lawful and that any required parental or guardian consent has been obtained before the minor uses the Service.
10. Cookies and analytics
We use cookies and similar technologies for authentication, security, preferences, and product analytics. Our marketing site uses privacy-respecting analytics to understand aggregate traffic. You can control cookies through your browser settings; disabling essential cookies may prevent sign-in.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version at corkboardhq.com/privacy and update the effective date. For material changes, we will notify Customers by email or in-product notice before the changes take effect.
12. Contact us
Corkboard Software Inc. Ontario, Canada support@corkboardhq.com