1. Agreement
By creating an organization, accepting an invitation or using the service, you agree to these terms, the privacy notice and — where you have signed one — a Business Associate Agreement. Where a signed order form or BAA conflicts with these terms, the signed document wins for the topic it covers. See the legal overview for how the documents fit together.
You may accept on behalf of an organization only if you are authorized to bind it. If you are not, do not use the service.
2. What the service is
credentracker is a credential-tracking system of record for employers: it stores the credentials you enter, calculates whether each one is valid, expiring or expired in your organization's timezone, scans uploaded documents, sends reminders and produces reports and audit logs. It is not an electronic health record, and it is not a source of legal, medical, licensing or accreditation advice.
3. Accounts, roles and seats
- Sign-in is passwordless. People sign in with a one-time code sent to the email address or phone number on their record. Keep that inbox and handset secure; anyone with access to them can reach the account.
- One account per person. Do not share credentials between people — the audit log is only meaningful if the actor named in it is the person who acted.
- Your admins control access. Organization Admins — and HR users, who can manage the workforce — invite people, assign roles, suspend accounts and remove them. As the customer, you are responsible for who you let in and for the permissions you grant.
- Seats. Every user record that has not been deleted counts as a billable seat — including invited people who have not yet signed in, and suspended accounts whose history must stay intact. Deleting the user is what stops the charge.
- Accurate information. Keep your organization name, timezone, billing contact and roster accurate. The timezone decides which credentials count as expiring, and the roster decides your invoice.
4. Text messages
- What we send. credentracker texts account messages only: sign-in codes you request, an invitation when a clinic adds you, and reminders when one of your credentials is about to expire. No marketing. Message frequency varies with your credentials and sign-ins. Msg & data rates may apply.
- Opting out and help. Reply STOP to stop receiving texts and HELP for help, or email support@credentracker.com. After STOP you can still sign in with your email address. Carriers are not liable for delayed or undelivered messages.
- Numbers you add. When an admin adds someone's mobile number, the admin confirms that person agreed to receive these texts. How we handle phone numbers is covered in the Privacy notice.
5. How your subscription starts
There is no free trial. Signing up takes two steps: first you verify your email address with a one-time code, which creates your organization and its first Organization Admin account; then that admin pays the first billing period of the chosen plan — a month, or a year on annual billing — through Stripe Checkout. Until that first payment completes, the organization is read-only — you can sign in, but changes that would add or alter records are blocked, and staff cannot be invited. Paying the first period starts the subscription, which then renews for the same period (monthly or yearly) as described in section 6.
We may decline a sign-up, or cancel one before it is paid, if it is being used to avoid paying, or to attack, overload or probe the service.
6. Fees
- Plan fees. Your fees are those of the plan you choose, as shown on our pricing page and in Stripe Checkout when you subscribe: a base fee for the organization, regardless of size, plus a fee for each billable user as defined in section 3, for each billing period.
- Billed in advance through Stripe, against the payment method on file, either monthly or — where your plan offers it — yearly. An annual subscription is paid for the whole year up front and renews for another year unless you cancel before the renewal date. Fees are stated in US dollars and exclude taxes, which are your responsibility where applicable.
- Seat changes. When you add people, the additional seats are charged immediately, pro rata for the rest of the current billing period. When you remove people, the seat stays paid until the end of the period (so a replacement fills it at no extra cost) and later invoices are smaller. We do not issue credits or refunds for a period already billed, so removing a user is not a way to reverse a charge.
- Unpaid invoices and chargebacks. If a payment fails, or is disputed with your card issuer, your organization becomes read-only until the balance is settled or the dispute is resolved. A chargeback decided against us ends the subscription.
- Price changes. We may change the fees. A change takes effect at your next billing period, never retroactively, and we tell Organization Admins before it applies.
7. Cancellation and refunds
Cancellation is self-serve: use the Stripe billing portal in billing settings, and the subscription stops renewing while access continues to the end of the period you have already paid for. Deleting an organization outright is a platform-side action — ask us from a verified Organization Admin account. It cancels the subscription and does not trigger a refund. If you want your data, export it first: reports and exports are available in the application while your subscription is current.
We do not issue refunds. If your organization is ever charged for a second subscription it already has — for example by paying twice at the same moment — we cancel the duplicate and keep that payment as credit on your account, applied automatically to your next invoices.
8. Billing problems
If an automatic payment fails, Stripe retries on its own schedule and we email the billing contact. While a subscription is past due, unpaid, canceled or incomplete, the organization is restricted: everything stays readable and exportable, but changes that would add or alter records are blocked until billing is current. Billing, your own profile and sign-out-everywhere keep working, because those are the actions that fix the problem. This is deliberate: we would rather freeze edits than delete data or hand you a surprise invoice later.
Where the law requires it, or where an account has been suspended for abuse, illegal activity or a security risk, access may instead be blocked entirely.
9. Your data and ours
- Your clinic owns the content. Credential records, uploaded documents and the audit trail belong to your organization, not to us.
- You instruct us, we process on instruction. We store, display, scan, back up and report that content to run the service for you — nothing more. Details are in the privacy notice and, if we have signed one with you, in your BAA.
- You are responsible for what you upload. Confirm you have the right to hold each document and that you have given your workforce whatever notice your jurisdiction requires for employee records.
- We own the platform. The software, interface, documentation and any aggregated operational metrics that contain no personal data remain ours. You receive a non-exclusive, non-transferable right to use the service while your subscription is active.
- Feedback. If you send us a suggestion, we may act on it without obligation to you.
- Confidentiality. Each side keeps the other's non-public information confidential and uses it only to run or use the service, except where disclosure is required by law — and if it is, we tell the affected organization first where we are allowed to.
10. Acceptable use
You agree not to:
- upload content you have no right to hold, or any patient information;
- give anyone access they are not entitled to, or impersonate another person;
- probe, scan, overload or attempt to bypass the service's authentication, permissions, rate limits or storage access, or use it to attack anything else;
- upload malware, or content that is unlawful, defamatory or infringing — uploads are scanned and anything suspicious is quarantined;
- scrape, resell, white-label or provide the service to third parties without a written agreement with us;
- use the service to send unsolicited messages, or to break export, tax or sanctions law.
We may remove content or suspend an account that breaks these rules, and we will tell you what happened unless the law stops us.
11. Availability, support and changes
We work to keep the service available and to give notice of planned maintenance, but this plan does not include a written service-level commitment. Support is by email and in-app; we answer in the order requests arrive, with outages and data-access problems first. If you need a contractual SLA, uptime target or priority support, ask us before you sign up — we will quote it separately.
We improve the product continuously and may add, change or retire a feature. We will not remove a capability you rely on for compliance (reminders, exports, the audit log) without telling Organization Admins first.
12. Suspension and termination
- You can leave at any time. Cancel from the billing portal in billing settings. To delete the organization outright, ask us from a verified Organization Admin account: deletion soft-deletes its members and cancels the subscription.
- We can suspend or end access for non-payment, a breach of these terms, illegal or abusive use, a security risk, or where the law requires it.
- Rebuilding a clinic after deletion is your job, not a restore request. Records are soft-deleted rather than destroyed, but they are archived — treat deletion as final and export first.
- After termination we retain records for the audit trail and wind the organization down: pending reminders are canceled and invitations revoked. Billing records are kept for tax and accounting.
- Surviving terms. Fees already due, data ownership, confidentiality, disclaimers, liability and governing law continue to apply after termination.
13. Compliance is yours to confirm
credentracker records what you enter. It does not verify a license with the issuing body, and it cannot know whether a document satisfies a regulator, payer or accreditation standard. A status of “valid” means the expiration date you recorded has not passed — nothing more. You are responsible for confirming credentials with the source, for the accuracy of dates and documents, and for meeting your own reporting obligations.
14. Disclaimers
The service is provided “as is”. To the extent the law allows, we disclaim implied warranties of merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the service will be uninterrupted or error-free, that reminders will always be delivered (email and SMS can fail), or that a survey or audit will go a particular way.
15. Limitation of liability
To the extent the law allows, neither party is liable for indirect, incidental, special or consequential losses, lost profits or lost goodwill. Our total liability arising out of or relating to the service is limited to the fees you paid us in the twelve months before the event giving rise to the claim. Nothing here limits liability that cannot be limited by law, including for fraud or wilful misconduct.
16. Law and disputes
These terms are governed by the laws that apply where Haven Technologies is established, without regard to conflict-of-law rules, and the courts there have exclusive jurisdiction — unless your order form names a different governing law or forum, in which case that applies. Before filing anything, email us: most disputes here are a data question or a billing mistake, and both are faster to fix directly.
17. Changes to these terms
We update the date at the top when these terms change. For a material change we notify Organization Admins by email or in-app in advance; using the service after the change takes effect means you accept it. If you do not accept it, cancel before it applies — we will not change the terms you already paid under mid-period.
18. Contact
Questions about these terms, procurement paperwork, compliance documentation and invoices go to support@credentracker.com. For a security issue, see the security page.