Knowledge ERP Privacy Policy
Effective Date: August 5, 2026 Last Updated: August 5, 2026
1. Introduction
This Privacy Policy describes how Pelton Solutions LLC, a Michigan limited liability company doing business as Knowledge ERP ("Knowledge ERP," "we," "us," or "our"), collects, uses, and discloses information when you use our website, our multi-tenant software-as-a-service ERP platform (inventory, sales, purchasing, manufacturing, rentals and equipment loans, appointments, CRM, and surveys), our mobile companion app, our REST API, and related services (collectively, the "Service").
This Policy is incorporated into our Terms of Service. Defined terms have the meanings given in the Terms.
The Service is offered only to businesses and business users in the United States who are at least 18 years old. If you are accessing the Service from outside the United States, please do not provide us with personal information.
2. Scope of This Policy
There are two very different kinds of data in the Service, and we play a different role for each. This Policy keeps them separate throughout.
Data we control. We act as the "controller" (or "business" under U.S. state privacy laws) for information about you as a Knowledge ERP Customer — your Account, the individual Users at your organization who sign in, your billing relationship with us, your sessions and policy acceptances, and your support interactions. Sections 3.1, 3.2, and 3.4 describe this data.
Data we process on your behalf. We act only as a "processor" / "service provider" for the business records you and your Users put into the Service — your customers, vendors, contacts, borrowers, transactions, CRM notes, captured e-signatures, uploaded files, synced email, survey responses, and public-form submissions (collectively, "Tenant Data"). The people described in Tenant Data are your customers and contacts, not ours; you are the controller of Tenant Data, and your own privacy notices govern how it is handled. Section 3.3 describes the categories, and Section 7 and our Data Processing Addendum describe our processor role.
This Policy also covers visitors to our marketing and public documentation pages.
3. Information We Collect
3.1 Information You Provide Directly (Data We Control)
- Account information. Your company name, chosen subdomain, timezone, locale, billing email, portal branding, and module/tier settings.
- User information. Each User's name, email address, and a password (which we store only in hashed form), plus an email-verification timestamp, role and location assignments, and any per-user spend or approval limits your administrators configure.
- Billing information. Your billing name and email. Payment card details are collected and stored by our payment processor, Stripe; Knowledge ERP does not receive or store your full card number — only the card brand, the last four digits, and Stripe customer, subscription, and price identifiers.
- Support and feedback. Information you submit when you contact support, request features, or otherwise interact with us.
3.2 Information We Collect Automatically (Data We Control)
When you and your Users use the Service, we collect:
- Authentication and session data. Session cookies, "remember me" tokens, API tokens, and mobile pairing tokens used to keep you signed in and to authenticate requests. Session records include the signed-in User, IP address, browser user-agent string, and last-activity time.
- Policy acceptance records. When your organization accepts our Terms, this Policy, or the Acceptable Use Policy, we record the document, version, timestamp, IP address, and user-agent of the accepting User as evidence of assent.
- Import/export history. A record of CSV imports and exports run by your Users, including uploaded file references and per-row failure details.
- Diagnostic and error data. When the Service encounters an error, we capture diagnostic information through our error-monitoring provider, Sentry, and our deployment/source-control tooling, GitHub. This diagnostic data may incidentally include request details such as an IP address or other request data associated with the error. We use it only to detect, investigate, and fix problems — not for advertising or cross-site tracking.
We do not use third-party advertising cookies or cross-site tracking technologies anywhere in the Service.
3.3 Tenant Data We Process on Your Behalf
The following categories are entered into the Service by you, your Users, your connected integrations, or members of the public interacting with your public-facing pages. We process this data only to provide the Service to you — we do not use it for our own marketing, profiling, advertising, or any other independent purpose.
- Customer, vendor, and contact records. Names, job titles, email addresses, phone numbers, billing and shipping addresses, websites, payment terms, and free-text notes about your customers, vendors, and their contacts.
- Transactional records. Quotes, sales orders, invoices, credit memos, customer payments (amount, method, date — never card numbers), returns, purchase orders, vendor bills and payments, rental and loan agreements, and appointment records.
- CRM history. Opportunities and pipeline history, activity timelines, tasks, notes with @mentions, and customer segments.
- Captured e-signatures. When your staff check equipment out to a named person, the Service can capture that person's signature image on the checkout record. We store the signature as part of the checkout record and use it solely to document the checkout for you; we do not analyze it, use it for identification or verification purposes of our own, or disclose it except as described in this Policy.
- Uploaded files. Attachments and media your Users upload against records (file name, type, size, and content).
- Synced email content. If a User connects a Gmail or Microsoft Outlook mailbox, we ingest matched messages — including subject, participants, and the full message body — and file them on the relevant customer record. See Section 5 for the specific commitments that apply to this data.
- Correspondence we send for you. Messages the Service sends on your behalf — invoices, quotes, appointment confirmations, portal links, reminders and automation-rule emails — are also filed against the relevant customer record, with their subject, recipients and content, so your team can see what was sent. Your Users can delete individual logged messages.
- Survey responses and questionnaires. Free-text and multiple-choice answers submitted by your survey recipients and appointment questionnaire respondents, together with invitation delivery, open, and answer timestamps (see Section 8 on open tracking).
- Public-form submissions. Data typed in by members of the public on your public booking pages, questionnaires, surveys, and customer-portal sign-in (typically name, email, phone, and free-text notes). These individuals interact with your pages; you are responsible for giving them any legally required privacy notice.
- Custom fields. You can define custom fields on many records and store values of your choosing in them. You control what goes into custom fields; our Acceptable Use Policy prohibits storing certain sensitive categories of data in them.
- Operational logs attributed to Users. Change history (see Section 10), inventory movements, automation run logs, and sync logs record which User took an action.
3.4 Information from Third Parties
We may receive information about you from third parties, including:
- Stripe — payment confirmations, fraud signals, and dispute information relating to your subscription;
- Email infrastructure — delivery, bounce, and complaint events for messages sent through the Service; and
- Public sources — when relevant (for example, business look-ups in fraud investigations).
3.5 What We Do Not Collect
- The Service is not directed to minors; you must be 18 or older to hold an Account, and we do not knowingly collect personal information from anyone under 18. See Section 13.
- We do not store payment card numbers — for our billing of you, or for the payments you collect from your own customers through your connected Stripe or Square account.
- We do not collect precise geolocation (beyond what an IP address incidentally implies), and we do not intentionally collect special categories of data such as health information, government identifiers, racial or ethnic origin, or union membership. Captured checkout signatures (Section 3.3) are stored as images for record-keeping only and are not used by us as biometric identifiers.
- Our mobile app requests camera permission only, for barcode scanning; it does not access your location, contacts, or photo library.
4. How We Use Information
We use the information described in Section 3 to:
- Provide the Service — operate your Account, authenticate your Users, run your modules, sync your connected integrations, generate documents and reports, and process Tenant Data on your instructions;
- Bill you and process payments — charge your payment method on file via Stripe, send receipts, and manage refunds and disputes;
- Send email and SMS you trigger, and protect deliverability — deliver messages the Service sends on your behalf and under your branding (invoices, reminders, survey invitations, portal links, and automation-rule messages), monitor bounce and complaint events, maintain a suppression list, and throttle sending that threatens platform deliverability;
- Communicate with you — service announcements, security and account notices, support responses, and (if you opt in) marketing emails;
- Improve the Service — diagnose issues, analyze performance, and develop new features;
- Maintain security and integrity — detect and prevent fraud, abuse, account takeover, and other harm, and maintain audit and change-history records; and
- Comply with legal obligations and enforce our agreements — including tax reporting, legal process, and the Terms and Acceptable Use Policy.
We do not sell your personal information for monetary consideration, and we do not use Tenant Data for any purpose other than providing the Service. See Section 11 for state-specific definitions and rights.
5. Connected Mailboxes — Google and Microsoft Limited Use
The optional mailbox-sync feature reads a connected mailbox and files matched customer correspondence onto the relevant customer record. Because this is the most sensitive data flow in the Service, the following specific commitments apply.
5.1 Google API Services — Limited Use Statement
Knowledge ERP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, for data obtained through Google Workspace APIs (including Gmail data accessed under the read-only Gmail scope):
- We use that data only to provide and improve the mailbox-sync feature that the connecting User can see in the product — filing matched messages onto customer records — and for no other purpose.
- We do not use it for advertising of any kind.
- We do not sell it or transfer it to third parties, except as necessary to provide the mailbox-sync feature (for example, storage on our hosting sub-processor), to comply with applicable law, or as part of a merger or acquisition with notice as described in Section 6.4.
- We do not use Google Workspace data to develop, improve, or train generalized artificial intelligence or machine-learning models.
- We do not allow humans to read it, except (a) with the connecting User's affirmative agreement for a specific message or issue; (b) as necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized for internal operations.
5.2 Microsoft Graph — Parallel Statement
The same commitments apply to mailbox data obtained through the Microsoft Graph API (read-only mail access for connected Outlook / Microsoft 365 mailboxes): we use it only to provide the mailbox-sync feature, we do not use it for advertising, we do not sell it, and human access is limited to the same narrow circumstances listed in Section 5.1. Our use of Microsoft Graph data complies with the Microsoft APIs Terms of Use.
5.3 What the Sync Stores, and Your Controls
- The sync is read-only: we never send, modify, or delete messages in a connected mailbox.
- Matched messages are stored on the customer record with subject, participants, and full message body, and are visible to your Users according to the permissions you configure. Because a mailbox contains messages from people who may not be your customers, you and the connecting User are responsible for ensuring the connection is appropriate for the mailbox's contents.
- A connected mailbox can be disconnected at any time in the integration settings, which stops further syncing. Disconnecting alone keeps the messages already filed on your customer records; the settings also offer "Disconnect and delete synced mail," which stops the sync and permanently deletes every message that mailbox filed. Individual messages can be deleted from the Email tab on any customer record. Anything you keep remains part of your Tenant Data and is deleted with your Account as described in Section 9. You may also request deletion of synced mailbox data by contacting us (Section 14).
6. How We Share Information
We disclose your information in the following situations.
6.1 Service Providers and Sub-Processors
We use third-party vendors to operate the Service. These vendors process information only on our instructions and under contractual obligations to protect it. Our principal sub-processors are:
- Amazon Web Services (AWS) — cloud infrastructure in the United States: application hosting, databases, storage of files and media, content delivery (CDN), DNS, web application firewall, and outbound email delivery (Amazon SES);
- Stripe — payment processing and subscription billing for your subscription with us;
- Sentry — application error and performance monitoring; and
- GitHub — source control and deployment tooling.
A current, detailed list is maintained in our Sub-Processor List, which we update as our vendors change.
6.2 Tenant-Directed Integrations (At Your Direction)
The optional integrations described in Section 7.2 (QuickBooks Online, Shopify, WooCommerce, ShipStation, Gmail, Outlook, Twilio, your own Stripe or Square account, outbound webhooks, and the REST API) are not our sub-processors. When you connect one, you are directing us to exchange your Tenant Data with a service of your own choosing, under your own agreement with that provider. Those disclosures are made at your direction and are governed by the destination service's terms and privacy policy.
6.3 Legal Process and Safety
We may disclose information when we believe in good faith that disclosure is required or appropriate to (a) comply with applicable law or legal process; (b) protect the rights, property, or safety of Knowledge ERP, our Customers, or the public; (c) detect, prevent, or investigate fraud, security, or technical issues; or (d) enforce our Terms or other agreements.
6.4 Business Transfers
If Pelton Solutions LLC is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
6.5 With Your Direction
We share information with third parties when you otherwise instruct us to.
6.6 Aggregated and De-Identified Information
We may share aggregated or de-identified information that cannot reasonably be used to identify you for any purpose.
7. Tenant Data, Public Forms, and Integrations
7.1 Our Role as Processor
For all Tenant Data (Section 3.3), we act only as your service provider / processor: we process it to provide the Service, on your instructions, and for no independent purpose. Specifically:
- You determine what data goes into the Service — which records you create, which fields (including custom fields) you define, which files you upload, which mailboxes you connect, and what your public booking pages, questionnaires, and surveys ask for.
- You are responsible for having a lawful basis to collect and use that data, for providing any privacy notice required to the people it describes (including visitors to your public booking, survey, and questionnaire pages), and for obtaining any consents required for the emails and SMS messages the Service sends on your behalf. Under the Terms, you are the sender of record for those communications.
- If one of your customers, contacts, or survey respondents contacts us directly with a privacy request about data you hold in the Service, we will generally redirect them to you as the responsible party, and we will assist you as described in the DPA.
Data Processing Addendum. For Customers who require one, our Data Processing Addendum governs our processing of Tenant Data on your behalf and incorporates our Sub-Processor List.
7.2 Tenant-Directed Integrations
All integrations are optional, connected by you per Account, and disconnectable at any time. When connected, Tenant Data flows to (and, for two-way integrations, from) the destination as follows:
| Integration | Data exchanged at your direction |
|---|---|
| QuickBooks Online | Customers, vendors, invoices, bills, payments, inventory adjustments (two-way) |
| Shopify / WooCommerce | Products, inventory levels, orders including buyer names and addresses, fulfillments (two-way) |
| ShipStation | Orders, shipping addresses, tracking numbers (two-way) |
| Gmail / Microsoft Outlook | Read-only mailbox sync; see Section 5 |
| Twilio | Recipient phone numbers and message bodies for SMS sent by your automation rules through your own Twilio account |
| Your own Stripe / Square | Payment collection from your customers into your own account; we record amount, method, and date — never card data |
| Outbound webhooks | Record payloads POSTed to any URL you nominate; you are solely responsible for the security and appropriateness of the destination |
| REST API | Full read/write access to your data by any application you issue an API token to |
Integration credentials you supply are protected by encryption in transit, encryption at rest at the infrastructure layer, and strict access controls.
7.3 Staff Administrative Access
Pelton Solutions staff have an administrative capability that can access Customer Accounts across tenants. Using it to view Tenant Data requires the Customer's approval.
How approval works. A staff member requests access to a specific Account and states a reason. We notify the Users in that Account who hold account-administration permission, by email and by a notice in the product. One of them reviews the reason and either approves the request — choosing its duration, from one hour up to seven days — or declines it. Access granted this way is limited to that staff member, that Account, and that period; it expires on its own; the Customer can revoke it at any time; and while it is active, every User in the Account can see that it is active, not only administrators.
Without an approval, staff can see Account-level and subscription information — plan, billing and subscription status, seat and storage usage, and email delivery health — and cannot use the administrative interface to view Tenant Data.
Emergency access. Where an Account is inoperable or the Service is materially impaired and the Users who could approve a request cannot respond, a senior engineer may take access without prior approval in order to restore the Service. When this happens, the Account's administrators are emailed at the time it occurs with the reason; the session is permanently identified as emergency access in the record the Customer can see; it is time-limited; and the Customer can revoke it. It exists so that a support team facing an outage has a path that leaves a record, rather than an undocumented one.
Throughout, least access still applies. Staff access Tenant Data only for support (at your request or to resolve your issue), maintenance, security, and legal-compliance purposes; administrative actions are attributable and logged; and staff are bound by confidentiality obligations. Staff do not browse Tenant Data for any other purpose. Changes staff make while in your Account appear in your own change history, attributed to the staff member rather than to one of your Users.
This Section describes access through the Service's administrative interface. It does not limit our rights to preserve, review, remove, or disclose Customer Data as described in the Terms of Service (Sections 8.5 and 17) and in Section 6 of this Policy, nor does it describe the access that personnel administering the underlying infrastructure necessarily have in the course of operating, securing, and backing up that infrastructure.
8. Cookies, Tracking, and Similar Technologies
Knowledge ERP uses a minimal set of first-party technologies and does not use third-party advertising or cross-site tracking cookies anywhere in the Service.
- Strictly necessary (in-product). A first-party session/authentication cookie, a CSRF-protection token, and "remember me" tokens keep Users securely signed in. Session records include IP address and user-agent (Section 3.2). These cannot be turned off without breaking the Service.
- Survey and email open tracking (on your behalf). Survey invitations sent through the Service record when the invitation is opened and when it is answered, and certain emails the Service sends on your behalf may include an open-tracking element that records an open timestamp. This tracking exists so that you can see engagement with your own communications; we do not use it to profile recipients, and it is not connected to any advertising. You are responsible for any disclosure to your recipients that applicable law requires for these communications.
- Public documentation pages. Our public docs pages do not run analytics or tracking scripts.
Because we do not engage in cross-context behavioral advertising and do not "sell" or "share" personal information in the advertising sense, a consent banner is generally not required for our own technologies. You can manage cookies through your browser settings, though disabling strictly necessary cookies will prevent the Service from working. Where any applicable law treats a browser Global Privacy Control (GPC) signal as a valid opt-out request, we will honor it.
9. Data Retention
We retain personal information for as long as we need it to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific practices:
| Data | Retention |
|---|---|
| Account, User, and Tenant Data | Retained for the life of your Account. On cancellation or termination, access ends and you have an approximately 30-day grace period to export your data in-app; after that period we permanently delete your Account and Tenant Data from active systems. Residual copies in routine backups age out on their normal rotation cycle. |
| Audit / change history | While your Account is active, correcting or deleting a record does not remove its prior values from your Account's change history, which we keep for integrity, security, and fraud-prevention purposes. The entire audit trail is deleted together with your Account. |
| Deleted attachments | Files your Users delete are purged from storage approximately 30 days after deletion. |
| Billing and tax records | Retained for the period required by applicable tax and financial regulations (typically about seven years in the U.S.), even after Account closure. |
| Policy acceptance records | Retained as evidence of assent for as long as reasonably necessary to enforce our agreements. |
| Sessions and tokens | Sessions expire after a period of inactivity; portal magic links, mobile pairing tokens, and survey invitation tokens carry explicit expiry dates. |
| Email deliverability events | Bounce, complaint, and suppression-list records are retained to protect ongoing deliverability. |
| Infrastructure and diagnostic logs | Server, network, and error logs (which can include IP addresses and request details) are retained for a limited period. |
Deletion requests. Verified deletion requests (Section 14) are honored within 45 days, with one 45-day extension where the law allows. If you ask us to delete Tenant Data mid-subscription, we act on your instruction as processor.
When we no longer need information, we delete or de-identify it, except where law or contractual obligation requires continued retention.
10. Security
We use reasonable administrative, technical, and physical safeguards to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include:
- TLS enforced in transit, with HTTP requests redirected to HTTPS, and SPF / DKIM authentication on outbound email;
- logically separated multi-tenancy — every query is automatically constrained to the signed-in Account by a tenant scope, backed by an automated cross-account isolation test suite (tenant separation is logical, within shared infrastructure);
- encryption at rest at the infrastructure layer for databases, object storage, and cache;
- secrets held in a managed secrets store and fetched at runtime rather than embedded in application code;
- a web application firewall (WAF) with managed rule sets and per-IP rate limiting in front of the application, with application servers in private network subnets;
- a full audit trail — edits to your records are logged with before-and-after values and the acting User (including API writes, attributed to the token that made them); and
- role-based access controls for your Users, and customer-approved, time-limited, least-access, logged administrative access for our staff (Section 7.3).
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident that affects your personal information in a way that triggers a notification obligation under applicable law, we will notify you and the appropriate regulators in accordance with that law. You are responsible for the security of your Users' credentials, for the permissions you grant within your Account, and for promptly notifying us of any suspected compromise.
11. State Privacy Rights
Several U.S. states grant residents specific rights with respect to their personal information. The rights below apply where you are a resident of the applicable state and relate to data for which we are the controller (Sections 3.1, 3.2, and 3.4). For Tenant Data, your rights run against the Customer that collected your information; if you contact us about Tenant Data, we will redirect you to the responsible Customer and assist them as their processor. To exercise rights against us, see Section 14.
11.1 California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; access a copy of it; correct inaccuracies; delete it (subject to exceptions); limit the use of sensitive personal information; opt out of any "sale" or "sharing" for cross-context behavioral advertising; and not be discriminated against for exercising these rights.
Sale and sharing. Knowledge ERP does not sell personal information for monetary consideration and does not "share" personal information for cross-context behavioral advertising. We engage our vendors as service providers under contracts that restrict their use of personal information to providing services to us.
Categories collected. See Section 3. For data we control, categories include: identifiers (name, email, IP address); commercial information (subscription and billing); internet/usage activity (sessions, user-agent, diagnostic data); and professional information (work email, organization, role). We do not collect the sensitive categories listed in Section 3.5.
Authorized agents. California residents may use an authorized agent to submit a request; we may require verification of the agent's authority.
11.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Similar States
Residents of these states (and other states with comparable privacy laws) generally have the right to access their personal information, correct inaccuracies, delete it, obtain a portable copy, opt out of targeted advertising / sale / certain profiling, and appeal a denied request. The exact scope depends on your state of residence. Because we do not engage in targeted advertising, sale, or profiling with legal or similarly significant effects, the opt-out rights generally have no application to our processing. To submit a request, see Section 14.
11.3 General
We will verify your identity before fulfilling a request and may decline requests that are unverifiable, manifestly unfounded, excessive, or that conflict with our legal obligations. We will not retaliate against you for exercising a privacy right.
12. Marketing Communications
We may send you marketing emails (about new features, tips, or promotions) if you have opted in or where applicable law permits a "soft opt-in" based on your Customer relationship with us. You can unsubscribe at any time using the link in any marketing email or by emailing hello@knowledgeerp.com. We will still send you operational messages (about your Account, billing, and security), which are not marketing.
Messages the Service sends to your customers and contacts on your behalf are your communications, not ours; opt-out requests for those belong to you (Section 7.1).
13. Children's Privacy
The Service is intended for business use by adults and is not directed to minors. You must be at least 18 years old to create an Account or be a User, and we do not knowingly collect personal information from anyone under 18. If you believe we may have collected personal information from a minor, please contact us at legal@peltonsolutions.com and we will take appropriate steps to delete it.
If your business serves minors, you are solely responsible for complying with the Children's Online Privacy Protection Act ("COPPA") and any similar laws with respect to the Tenant Data you collect through the Service.
14. How to Exercise Your Rights
You may submit a privacy request (access, correction, deletion, portability, opt-out, or appeal) by emailing legal@peltonsolutions.com with the subject line "Privacy Request — [your state]", or through any privacy-request option we make available in your Account settings.
Include enough information to identify your Account (or your relationship to a Customer's Account) and the right you wish to exercise. We will respond within the timeframe required by applicable law (generally within 45 days, with one possible 45-day extension). If we deny your request, we will explain why and how to appeal.
If your request concerns Tenant Data held in a Customer's Account, we will refer the request to that Customer and assist them in responding.
15. International Users and Data Location
The Service is intended only for users in the United States, and all information is processed and stored in the United States on AWS infrastructure. By using the Service from any other location, you understand that your information will be transferred to and processed in the United States, which may have data-protection laws that differ from those of your country.
We do not currently offer the Service to residents of the European Economic Area, the United Kingdom, or Switzerland, and we do not provide GDPR-style data subject rights or Standard Contractual Clauses for international transfers. The Data Processing Addendum referenced in Section 7 governs our role as a service provider/processor for Tenant Data under U.S. law; it is not a GDPR transfer mechanism. If you are located in the EEA, UK, or Switzerland, please do not create an Account, and do not use the Service to collect data from individuals located there.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will give you reasonable advance notice (by email and/or in-product notice). The "Last Updated" date at the top reflects the most recent revision.
17. Contact
Pelton Solutions LLC Attn: Knowledge ERP — Privacy 101 Rainbow Drive PMB 1624 Livingston, TX 77399
Privacy questions and requests: legal@peltonsolutions.com General support: hello@knowledgeerp.com