Version 2026-08-05 · Effective Aug 5, 2026

Knowledge ERP Privacy Policy

Effective Date: August 5, 2026 Last Updated: August 5, 2026


1. Introduction

This Privacy Policy describes how Pelton Solutions LLC, a Michigan limited liability company doing business as Knowledge ERP ("Knowledge ERP," "we," "us," or "our"), collects, uses, and discloses information when you use our website, our multi-tenant software-as-a-service ERP platform (inventory, sales, purchasing, manufacturing, rentals and equipment loans, appointments, CRM, and surveys), our mobile companion app, our REST API, and related services (collectively, the "Service").

This Policy is incorporated into our Terms of Service. Defined terms have the meanings given in the Terms.

The Service is offered only to businesses and business users in the United States who are at least 18 years old. If you are accessing the Service from outside the United States, please do not provide us with personal information.


2. Scope of This Policy

There are two very different kinds of data in the Service, and we play a different role for each. This Policy keeps them separate throughout.

Data we control. We act as the "controller" (or "business" under U.S. state privacy laws) for information about you as a Knowledge ERP Customer — your Account, the individual Users at your organization who sign in, your billing relationship with us, your sessions and policy acceptances, and your support interactions. Sections 3.1, 3.2, and 3.4 describe this data.

Data we process on your behalf. We act only as a "processor" / "service provider" for the business records you and your Users put into the Service — your customers, vendors, contacts, borrowers, transactions, CRM notes, captured e-signatures, uploaded files, synced email, survey responses, and public-form submissions (collectively, "Tenant Data"). The people described in Tenant Data are your customers and contacts, not ours; you are the controller of Tenant Data, and your own privacy notices govern how it is handled. Section 3.3 describes the categories, and Section 7 and our Data Processing Addendum describe our processor role.

This Policy also covers visitors to our marketing and public documentation pages.


3. Information We Collect

3.1 Information You Provide Directly (Data We Control)

3.2 Information We Collect Automatically (Data We Control)

When you and your Users use the Service, we collect:

We do not use third-party advertising cookies or cross-site tracking technologies anywhere in the Service.

3.3 Tenant Data We Process on Your Behalf

The following categories are entered into the Service by you, your Users, your connected integrations, or members of the public interacting with your public-facing pages. We process this data only to provide the Service to you — we do not use it for our own marketing, profiling, advertising, or any other independent purpose.

3.4 Information from Third Parties

We may receive information about you from third parties, including:

3.5 What We Do Not Collect


4. How We Use Information

We use the information described in Section 3 to:

We do not sell your personal information for monetary consideration, and we do not use Tenant Data for any purpose other than providing the Service. See Section 11 for state-specific definitions and rights.


5. Connected Mailboxes — Google and Microsoft Limited Use

The optional mailbox-sync feature reads a connected mailbox and files matched customer correspondence onto the relevant customer record. Because this is the most sensitive data flow in the Service, the following specific commitments apply.

5.1 Google API Services — Limited Use Statement

Knowledge ERP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, for data obtained through Google Workspace APIs (including Gmail data accessed under the read-only Gmail scope):

5.2 Microsoft Graph — Parallel Statement

The same commitments apply to mailbox data obtained through the Microsoft Graph API (read-only mail access for connected Outlook / Microsoft 365 mailboxes): we use it only to provide the mailbox-sync feature, we do not use it for advertising, we do not sell it, and human access is limited to the same narrow circumstances listed in Section 5.1. Our use of Microsoft Graph data complies with the Microsoft APIs Terms of Use.

5.3 What the Sync Stores, and Your Controls


6. How We Share Information

We disclose your information in the following situations.

6.1 Service Providers and Sub-Processors

We use third-party vendors to operate the Service. These vendors process information only on our instructions and under contractual obligations to protect it. Our principal sub-processors are:

A current, detailed list is maintained in our Sub-Processor List, which we update as our vendors change.

6.2 Tenant-Directed Integrations (At Your Direction)

The optional integrations described in Section 7.2 (QuickBooks Online, Shopify, WooCommerce, ShipStation, Gmail, Outlook, Twilio, your own Stripe or Square account, outbound webhooks, and the REST API) are not our sub-processors. When you connect one, you are directing us to exchange your Tenant Data with a service of your own choosing, under your own agreement with that provider. Those disclosures are made at your direction and are governed by the destination service's terms and privacy policy.

6.3 Legal Process and Safety

We may disclose information when we believe in good faith that disclosure is required or appropriate to (a) comply with applicable law or legal process; (b) protect the rights, property, or safety of Knowledge ERP, our Customers, or the public; (c) detect, prevent, or investigate fraud, security, or technical issues; or (d) enforce our Terms or other agreements.

6.4 Business Transfers

If Pelton Solutions LLC is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

6.5 With Your Direction

We share information with third parties when you otherwise instruct us to.

6.6 Aggregated and De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you for any purpose.


7. Tenant Data, Public Forms, and Integrations

7.1 Our Role as Processor

For all Tenant Data (Section 3.3), we act only as your service provider / processor: we process it to provide the Service, on your instructions, and for no independent purpose. Specifically:

Data Processing Addendum. For Customers who require one, our Data Processing Addendum governs our processing of Tenant Data on your behalf and incorporates our Sub-Processor List.

7.2 Tenant-Directed Integrations

All integrations are optional, connected by you per Account, and disconnectable at any time. When connected, Tenant Data flows to (and, for two-way integrations, from) the destination as follows:

Integration Data exchanged at your direction
QuickBooks Online Customers, vendors, invoices, bills, payments, inventory adjustments (two-way)
Shopify / WooCommerce Products, inventory levels, orders including buyer names and addresses, fulfillments (two-way)
ShipStation Orders, shipping addresses, tracking numbers (two-way)
Gmail / Microsoft Outlook Read-only mailbox sync; see Section 5
Twilio Recipient phone numbers and message bodies for SMS sent by your automation rules through your own Twilio account
Your own Stripe / Square Payment collection from your customers into your own account; we record amount, method, and date — never card data
Outbound webhooks Record payloads POSTed to any URL you nominate; you are solely responsible for the security and appropriateness of the destination
REST API Full read/write access to your data by any application you issue an API token to

Integration credentials you supply are protected by encryption in transit, encryption at rest at the infrastructure layer, and strict access controls.

7.3 Staff Administrative Access

Pelton Solutions staff have an administrative capability that can access Customer Accounts across tenants. Using it to view Tenant Data requires the Customer's approval.

How approval works. A staff member requests access to a specific Account and states a reason. We notify the Users in that Account who hold account-administration permission, by email and by a notice in the product. One of them reviews the reason and either approves the request — choosing its duration, from one hour up to seven days — or declines it. Access granted this way is limited to that staff member, that Account, and that period; it expires on its own; the Customer can revoke it at any time; and while it is active, every User in the Account can see that it is active, not only administrators.

Without an approval, staff can see Account-level and subscription information — plan, billing and subscription status, seat and storage usage, and email delivery health — and cannot use the administrative interface to view Tenant Data.

Emergency access. Where an Account is inoperable or the Service is materially impaired and the Users who could approve a request cannot respond, a senior engineer may take access without prior approval in order to restore the Service. When this happens, the Account's administrators are emailed at the time it occurs with the reason; the session is permanently identified as emergency access in the record the Customer can see; it is time-limited; and the Customer can revoke it. It exists so that a support team facing an outage has a path that leaves a record, rather than an undocumented one.

Throughout, least access still applies. Staff access Tenant Data only for support (at your request or to resolve your issue), maintenance, security, and legal-compliance purposes; administrative actions are attributable and logged; and staff are bound by confidentiality obligations. Staff do not browse Tenant Data for any other purpose. Changes staff make while in your Account appear in your own change history, attributed to the staff member rather than to one of your Users.

This Section describes access through the Service's administrative interface. It does not limit our rights to preserve, review, remove, or disclose Customer Data as described in the Terms of Service (Sections 8.5 and 17) and in Section 6 of this Policy, nor does it describe the access that personnel administering the underlying infrastructure necessarily have in the course of operating, securing, and backing up that infrastructure.


8. Cookies, Tracking, and Similar Technologies

Knowledge ERP uses a minimal set of first-party technologies and does not use third-party advertising or cross-site tracking cookies anywhere in the Service.

Because we do not engage in cross-context behavioral advertising and do not "sell" or "share" personal information in the advertising sense, a consent banner is generally not required for our own technologies. You can manage cookies through your browser settings, though disabling strictly necessary cookies will prevent the Service from working. Where any applicable law treats a browser Global Privacy Control (GPC) signal as a valid opt-out request, we will honor it.


9. Data Retention

We retain personal information for as long as we need it to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific practices:

Data Retention
Account, User, and Tenant Data Retained for the life of your Account. On cancellation or termination, access ends and you have an approximately 30-day grace period to export your data in-app; after that period we permanently delete your Account and Tenant Data from active systems. Residual copies in routine backups age out on their normal rotation cycle.
Audit / change history While your Account is active, correcting or deleting a record does not remove its prior values from your Account's change history, which we keep for integrity, security, and fraud-prevention purposes. The entire audit trail is deleted together with your Account.
Deleted attachments Files your Users delete are purged from storage approximately 30 days after deletion.
Billing and tax records Retained for the period required by applicable tax and financial regulations (typically about seven years in the U.S.), even after Account closure.
Policy acceptance records Retained as evidence of assent for as long as reasonably necessary to enforce our agreements.
Sessions and tokens Sessions expire after a period of inactivity; portal magic links, mobile pairing tokens, and survey invitation tokens carry explicit expiry dates.
Email deliverability events Bounce, complaint, and suppression-list records are retained to protect ongoing deliverability.
Infrastructure and diagnostic logs Server, network, and error logs (which can include IP addresses and request details) are retained for a limited period.

Deletion requests. Verified deletion requests (Section 14) are honored within 45 days, with one 45-day extension where the law allows. If you ask us to delete Tenant Data mid-subscription, we act on your instruction as processor.

When we no longer need information, we delete or de-identify it, except where law or contractual obligation requires continued retention.


10. Security

We use reasonable administrative, technical, and physical safeguards to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include:

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects your personal information in a way that triggers a notification obligation under applicable law, we will notify you and the appropriate regulators in accordance with that law. You are responsible for the security of your Users' credentials, for the permissions you grant within your Account, and for promptly notifying us of any suspected compromise.


11. State Privacy Rights

Several U.S. states grant residents specific rights with respect to their personal information. The rights below apply where you are a resident of the applicable state and relate to data for which we are the controller (Sections 3.1, 3.2, and 3.4). For Tenant Data, your rights run against the Customer that collected your information; if you contact us about Tenant Data, we will redirect you to the responsible Customer and assist them as their processor. To exercise rights against us, see Section 14.

11.1 California (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; access a copy of it; correct inaccuracies; delete it (subject to exceptions); limit the use of sensitive personal information; opt out of any "sale" or "sharing" for cross-context behavioral advertising; and not be discriminated against for exercising these rights.

Sale and sharing. Knowledge ERP does not sell personal information for monetary consideration and does not "share" personal information for cross-context behavioral advertising. We engage our vendors as service providers under contracts that restrict their use of personal information to providing services to us.

Categories collected. See Section 3. For data we control, categories include: identifiers (name, email, IP address); commercial information (subscription and billing); internet/usage activity (sessions, user-agent, diagnostic data); and professional information (work email, organization, role). We do not collect the sensitive categories listed in Section 3.5.

Authorized agents. California residents may use an authorized agent to submit a request; we may require verification of the agent's authority.

11.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Similar States

Residents of these states (and other states with comparable privacy laws) generally have the right to access their personal information, correct inaccuracies, delete it, obtain a portable copy, opt out of targeted advertising / sale / certain profiling, and appeal a denied request. The exact scope depends on your state of residence. Because we do not engage in targeted advertising, sale, or profiling with legal or similarly significant effects, the opt-out rights generally have no application to our processing. To submit a request, see Section 14.

11.3 General

We will verify your identity before fulfilling a request and may decline requests that are unverifiable, manifestly unfounded, excessive, or that conflict with our legal obligations. We will not retaliate against you for exercising a privacy right.


12. Marketing Communications

We may send you marketing emails (about new features, tips, or promotions) if you have opted in or where applicable law permits a "soft opt-in" based on your Customer relationship with us. You can unsubscribe at any time using the link in any marketing email or by emailing hello@knowledgeerp.com. We will still send you operational messages (about your Account, billing, and security), which are not marketing.

Messages the Service sends to your customers and contacts on your behalf are your communications, not ours; opt-out requests for those belong to you (Section 7.1).


13. Children's Privacy

The Service is intended for business use by adults and is not directed to minors. You must be at least 18 years old to create an Account or be a User, and we do not knowingly collect personal information from anyone under 18. If you believe we may have collected personal information from a minor, please contact us at legal@peltonsolutions.com and we will take appropriate steps to delete it.

If your business serves minors, you are solely responsible for complying with the Children's Online Privacy Protection Act ("COPPA") and any similar laws with respect to the Tenant Data you collect through the Service.


14. How to Exercise Your Rights

You may submit a privacy request (access, correction, deletion, portability, opt-out, or appeal) by emailing legal@peltonsolutions.com with the subject line "Privacy Request — [your state]", or through any privacy-request option we make available in your Account settings.

Include enough information to identify your Account (or your relationship to a Customer's Account) and the right you wish to exercise. We will respond within the timeframe required by applicable law (generally within 45 days, with one possible 45-day extension). If we deny your request, we will explain why and how to appeal.

If your request concerns Tenant Data held in a Customer's Account, we will refer the request to that Customer and assist them in responding.


15. International Users and Data Location

The Service is intended only for users in the United States, and all information is processed and stored in the United States on AWS infrastructure. By using the Service from any other location, you understand that your information will be transferred to and processed in the United States, which may have data-protection laws that differ from those of your country.

We do not currently offer the Service to residents of the European Economic Area, the United Kingdom, or Switzerland, and we do not provide GDPR-style data subject rights or Standard Contractual Clauses for international transfers. The Data Processing Addendum referenced in Section 7 governs our role as a service provider/processor for Tenant Data under U.S. law; it is not a GDPR transfer mechanism. If you are located in the EEA, UK, or Switzerland, please do not create an Account, and do not use the Service to collect data from individuals located there.


16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will give you reasonable advance notice (by email and/or in-product notice). The "Last Updated" date at the top reflects the most recent revision.


17. Contact

Pelton Solutions LLC Attn: Knowledge ERP — Privacy 101 Rainbow Drive PMB 1624 Livingston, TX 77399

Privacy questions and requests: legal@peltonsolutions.com General support: hello@knowledgeerp.com