Home / Privacy
Privacy Policy
Confidentiality is fundamental to this practice. This policy explains, plainly and accurately, what we collect, how we protect it, who we share it with, and the rights you have.
Last updated: September 2026
This Privacy Policy explains how Draco Investigative Services ("we," "us," "our") collects, uses, protects, shares, and retains personal information across both this public website and our secure customer portal, where clients order background checks and employment screening.
We operate as a consumer reporting agency (CRA). When a report we assemble is used for a purpose covered by the federal Fair Credit Reporting Act (FCRA) — such as employment or tenant screening — that report is a "consumer report," and both we and the client who orders it have specific legal responsibilities. Those responsibilities are described below and in our Terms of Use.
Who this policy covers
This policy concerns two groups of people:
- Our clients — the individuals and organizations who contact us or hold a portal account.
- The subjects of our work — the job applicants, tenants, or other individuals a client asks us to research or screen. Much of the sensitive information we hold is about these individuals, who are not the person submitting it.
Information we collect
When you contact us
Through the public contact form we collect your name and email address (required so we can respond), your phone number (optional), the subject of your inquiry, and the details of your message. Please share only general information here — do not send Social Security numbers or other sensitive identifiers through the contact form or by email.
When you create a portal account
We collect your email address, an optional phone number, and a password (stored only as a secure, irreversible hash — we never store your actual password). Employer accounts also include company name, primary contact name, and business address details.
When you order an individual background check
We collect the details you provide about yourself (name, contact information) and about the subject of the check — their name, last known address, date of birth, and any other identifiers you supply — together with your stated relationship to the subject, your reason for the request, and your attestation that your purpose is lawful and permissible.
When you order employment screening (employer accounts)
We collect each applicant's identifying information — name, contact details, address, date of birth, and Social Security number — entered individually or uploaded in bulk (CSV/XLSX). We also record your certification that you have a permissible purpose and the applicant's written authorization.
Payment information
Payments are processed by Stripe. Card details are entered on Stripe's own secure checkout — we never receive or store your full card number. For employer accounts that save a card, we store only a Stripe reference token for that card; its brand, last four digits, and expiry are retrieved from Stripe only to display your saved card to you.
Information collected automatically
To operate and protect the site, our servers and logs record standard technical information: your IP address, browser type (user-agent), pages viewed, referring page, and the date and time of activity. We keep an audit log of key account actions (such as sign-in and report downloads) that includes the IP address and browser used. See Cookies below.
Sensitive identifiers & how we protect them
Social Security numbers and dates of birth are encrypted at rest using strong, modern encryption, with the encryption key stored separately from the database records. Other information you provide (such as names and addresses) is held in our secured systems but is not individually encrypted. Completed reports are stored on access-controlled storage outside the public web area and are released only to the verified, signed-in account owner who ordered them. Access to decrypted identifiers and case details is limited to authorized personnel. No system is perfectly secure, but we apply reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of this information.
How we use information
We use the information we collect to:
- respond to your inquiries and communicate with you;
- deliver the services you order — conducting background checks and screening, verifying records, and producing and delivering reports;
- process payments and maintain billing records;
- authenticate accounts, prevent fraud and abuse, and secure the site;
- comply with our legal obligations, including those under the FCRA.
We do not sell, rent, or trade personal information, and we do not share it with third parties for their own marketing.
Our role as a consumer reporting agency
Because we act as a CRA, the following apply to the reports we assemble:
- Permissible purpose. We furnish a consumer report only for a purpose permitted by the FCRA (for example, employment or tenant screening with the subject's authorization). Clients must certify their permissible purpose and are contractually barred from using a report for any other purpose.
- Reasonable accuracy procedures. We follow reasonable procedures to assure maximum possible accuracy of the information we report — verifying at the source rather than relying on an unconfirmed database result. This is a commitment to reasonable procedures, not a guarantee that every third-party record is error-free.
- Where report information comes from. Reports draw on public records, licensed databases, and direct verification. Where a report includes motor-vehicle or driving records, we obtain and use that information only for a purpose permitted under the Driver's Privacy Protection Act; where it includes financial or credit information, we obtain it only through lawful, permissible-purpose means and never through false or fraudulent pretenses.
- Public-record information for employment. When a report includes public-record information for employment purposes that may adversely affect a person, we handle it in accordance with the FCRA's requirements for such information.
How we share information
We share personal information only as needed to run our services and meet our obligations:
- Completed reports are delivered to the client who ordered them for their certified permissible purpose.
- Service providers that process data on our behalf: Stripe (payment processing and card storage), SendGrid (delivery of email such as confirmations, receipts, and account messages), Google reCAPTCHA (bot protection) and Google Fonts (web fonts), which receive your IP address and browser information when pages load, an IP-geolocation service used to understand the approximate region of site visitors, and our hosting and infrastructure providers that store data on our behalf.
- Authorized personnel and investigators who carry out the work.
- Legal and safety — when required by law, legal process, or to protect rights and safety.
Your use of Google reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
Cookies & similar technologies
- A session/authentication cookie that keeps you securely signed in to the portal and carries a security token that protects against cross-site request forgery.
- A first-party analytics cookie that helps us tell new visitors from returning ones so we can understand overall site usage. It contains a random identifier only.
- Cookies set by Stripe during checkout and by Google reCAPTCHA.
- A small amount of browser storage that remembers your light/dark display preference.
We do not use advertising or cross-site tracking cookies.
Data retention & disposal
We retain account information, payment records, consumer-report data, completed reports, contact inquiries, and logs for as long as necessary to provide our services and to meet our legal, tax, and regulatory obligations, including the recordkeeping expected of a consumer reporting agency. Retention periods vary with the type of record and the applicable requirement.
When we dispose of records that contain personal information, we take reasonable steps to do so securely — for example, deleting electronic records and destroying or erasing stored files — so that the information is not readily readable or reconstructable, consistent with applicable law.
Because consumer-report data is governed by the FCRA, it generally cannot be deleted on demand the way an unengaged inquiry can. If you are the subject of a report and believe information about you is inaccurate, please use the dispute process described below rather than a deletion request.
Your rights
If you are the subject of a report (FCRA rights)
If we have assembled a consumer report about you, the FCRA gives you the right, on request and after we verify your identity, to:
- learn whether a report about you was provided and obtain a copy of the information in your file, its sources, and the identity of those who obtained a report about you;
- dispute the accuracy or completeness of any item — the FCRA provides for a reasonable reinvestigation (generally within 30 days), after which information that is inaccurate, incomplete, or cannot be verified is corrected or deleted and you are notified of the result;
- receive a copy of "A Summary of Your Rights Under the FCRA," which we will provide on request.
To exercise any of these rights, use our consumer request form or contact us using the details below; we will verify your identity and respond as the FCRA requires. If an employer, landlord, or other user takes adverse action based on our report, that user must give you the notices the FCRA requires, including our name and contact information and notice of your right to a free copy of the report and to dispute it.
California residents
Under California law (CCPA/CPRA) you may request to know the personal information we collect about you and its sources, to access or delete it, to correct it, and to limit the use of sensitive personal information, and you will not be discriminated against for exercising these rights. We do not sell or "share" personal information as those terms are defined. Where information is collected or used as part of activity regulated by the FCRA, that information is handled under the FCRA (including the file-disclosure and dispute process above) rather than the CCPA's access/deletion process.
How to exercise your rights
Email us at damien@dracosvc.com. To protect your information, we will take reasonable steps to verify your identity before acting on a request.
Security
This website is served over an encrypted (HTTPS) connection. Sensitive identifiers are encrypted at rest; passwords are stored only as secure hashes; access is authenticated and, for reports, limited to the verified account owner; and we apply rate-limiting, audit logging, and other safeguards. No method of transmission or storage is perfectly secure, but we work to keep your information safe.
Children
This site and our services are intended for adults and are not directed to children under 13, and we do not knowingly collect their information from them directly.
Where we operate
Our services are offered in the United States (and, where noted, elsewhere in North America) and are not directed to individuals in other regions.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy, or an FCRA file-disclosure or dispute request? Email damien@dracosvc.com.
This policy is provided for general informational purposes and is not legal advice. Statutory references are included for clarity and should be confirmed against current law. Please have this policy reviewed by qualified counsel against your specific practices before relying on it.