Skip to main content
MYID Self Verify
Platform Manage Protect Autopilot Analytics Case Studies Compliance Support
Support Book a Demo
Privacy

Privacy Policy

How Software Productivity Strategists, Inc. collects, uses, shares, retains, and protects information through MYID Self Verify.

Effective
July 18, 2026
Operator
Software Productivity Strategists, Inc.
Privacy contact
privacy@ext.myidselfverify.com

Contents

  1. Scope and roles
  2. Website information
  3. Customer platform information
  4. Mobile application information
  5. Audit and performance data
  6. How information is used
  7. Sharing and providers
  8. Sale and advertising
  9. Retention
  10. Security
  11. Rights and requests
  12. International transfers
  13. Children
  14. Changes
  15. Contact

1. Scope and roles

This Policy applies to the public website, mobile application, platform, administration tools, APIs, support, and related MYID Self Verify services operated by Software Productivity Strategists, Inc., which this Policy calls SPS, MYID, we, us, or our.

For public website, business contact, and direct support information, SPS commonly decides the purpose and means of processing. For employee identity information processed through a customer deployment, the customer commonly decides the purpose and means and SPS acts as its service provider or processor. The signed customer agreement controls the exact roles.

Customer privacy notices and policies also apply to information that a customer controls.

2. Website information

We can collect information you provide through a contact, support, privacy, legal, security, partner, or demonstration request. This can include name, business email, company, role, company identifier, app version, message, and communication history.

Contact and privacy request forms use short lived keyed pseudonyms derived from the transport address and submitted email to enforce hourly abuse limits. The rate files do not store the raw address or email and are removed through operational cleanup.

With analytics consent, the website can record a random pseudonymous visitor identifier, random session identifier, visit time, page path, referring site without its query string, approved campaign parameters, device category, browser family, operating system family, full browser user agent, general screen and viewport size, language, time zone, engagement, scroll depth, clicked link text, and destination without its query string.

When the hosting environment supplies it, website analytics can also record approximate country, region, and city. These locations can be incomplete or inaccurate and are not used to make an identity or access decision.

New analytics events store a protected pseudonymous network value rather than the raw address. Query strings are removed from stored page and link addresses. The website analytics system is first party and does not load advertising trackers.

3. Customer platform information

Depending on customer configuration, MYID can process company configuration, tenant identifiers, identity attributes, usernames, display names, business contact details, group or role information, authentication and session events, MFA factor metadata, account and directory status, password policy results, profile updates, security incidents, user responses, device management evidence, risk signals, notifications, training status, administrator configuration, readiness tests, and support records.

Connected providers can return additional data required for the enabled function. The customer determines which providers and capabilities are authorized.

4. Mobile application information

The app can store protected company configuration, session state, capability state, recent summary data, freshness timestamps, notification intent, and a scoped profile image cache on the device. The operating system can provide device platform, app version, build, notification token, and security service results.

Face ID, Touch ID, and Android biometric checks are performed by the device operating system. MYID does not receive or store the user’s face, fingerprint template, or biometric measurement from those services.

Profile images can be downloaded to a local cache and refreshed separately from the main security sync. When the customer enables image writeback, a selected image can be sent to the configured directory or identity provider.

5. Audit and performance data

Audit evidence can include tenant, actor, action, request method and route, timestamps, source and destination, reason, protocol, outcome, status, duration, correlation identifier, device context, capture mode, length, integrity data, and safely captured request or response values.

Passwords, OTP values, recovery codes, access tokens, refresh tokens, authorization values, cookies, API keys, client secrets, private keys, and similar authentication material are redacted. Audit capture can be complete, partial, summarized, or unavailable depending on the transport and connector.

Mobile performance telemetry can include normalized operation category, duration, status, outcome, app platform, approved build cohort, frame timing, and jank. It is designed to exclude credentials, request bodies, device identifiers, and user entered values.

6. How information is used

We use information to provide and secure the Services; authenticate and authorize; perform customer instructions; connect approved providers; show current or cached state; process identity and security actions; deliver notifications; create audit evidence; measure performance; troubleshoot; prevent abuse; support users and customers; improve reliability; communicate; enforce agreements; protect rights; and comply with law.

Where law requires a legal basis, processing can rely on contract, customer instruction, consent, legitimate interests in operating and securing the Services, legal obligation, or protection of rights and safety, as applicable.

7. Sharing and service providers

Information can be shared with the applicable customer, authorized Users and administrators, connected systems selected by the customer, service providers needed to operate the Services, professional advisers under confidentiality, authorities when lawfully required, and a successor in a corporate transaction subject to appropriate protection.

The provider set varies by deployment. Review the Subprocessor Notice and customer agreement for more detail.

8. Sale, sharing, and targeted advertising

We do not sell personal information for money. The public MYID website does not use information for cross context behavioral advertising or targeted advertising and does not load advertising trackers.

Global Privacy Control signals are treated as a request not to start optional website analytics where the browser exposes the signal. You can also choose Necessary only in the analytics notice or reopen Cookie choices in the footer.

9. Retention

Customer platform data is retained according to the signed agreement, customer configuration, provider behavior, backup cycle, legal need, security need, and documented deletion instruction. Different event types can have different periods.

Website analytics are generally retained for about 395 days unless a shorter operational setting applies. Periodic cleanup triggered by eligible analytics traffic applies the configured period, and operational delay can affect the exact deletion time. The visitor cookie lasts up to 180 days. Contact and support records are retained as needed to answer requests, maintain business records, secure the Services, resolve disputes, and comply with law.

Information can remain in a protected backup until the applicable backup cycle expires. Minimal records can be retained to document a request, protect security, enforce rights, or meet a legal obligation.

10. Security

We use technical and organizational measures selected for the nature of the information and deployment. Measures can include encrypted transport, protected secrets, tenant context, access control, redaction, audit evidence, secure storage, bounded telemetry, dependency management, backups, monitoring, and release testing.

No system is perfectly secure. Customers must test their deployment, control provider access, maintain recovery procedures, and promptly report suspected misuse or unauthorized access. Review the Security Disclosure for current boundaries.

11. Rights and requests

Depending on location, role, and applicable law, a person may have rights to know, access, correct, delete, restrict, object, receive a copy, withdraw consent, or appeal a decision. Some laws exclude employee or business context information, and legal exceptions can apply.

For customer controlled employee data, contact the employer or customer first. SPS will assist the customer as required by the agreement and applicable law. For website or direct SPS data, use the Privacy Request form. We may verify identity and authority before acting.

We do not discriminate against a person for exercising an applicable privacy right.

12. International transfers

The Services and providers can process information in countries other than the person’s location. Before a regulated deployment, the customer and SPS should identify the applicable regions, providers, contract roles, transfer mechanism, and supplementary safeguards. No public page guarantees a specific data region unless a signed customer agreement states it.

13. Children

The public website and enterprise Services are not directed to children for personal or household use. Customers must not enable a student or minor deployment without the authority, notices, consent, contracts, and controls required by applicable law.

14. Changes to this Policy

We may update this Policy to reflect product, provider, legal, or operational changes. The current version and effective date will be posted here. We will provide additional notice when required by law or contract.

15. Contact

Privacy questions and requests can be sent to privacy@ext.myidselfverify.com or submitted through the Privacy Request page.

Postal address: Software Productivity Strategists, Inc., 2400 Research Blvd, Suite 115, Rockville, Maryland 20850, United States.

Plain Language Data Guide Privacy Request Cookie Notice
MYID Self Verify

Mobile identity operations, user guided security response, tenant controls, truthful synchronization, and measurable performance around the systems your organization already owns.

mail public

Product

  • Platform
  • Manage
  • Protect
  • Autopilot
  • Analytics
  • Mobile App
  • Enterprise MFA
  • IBM Verify
  • Pricing

Trust

  • Security
  • Compliance
  • Data Processing
  • Subprocessors
  • Accessibility
  • Legal Center

Support

  • Support Center
  • Employee Guide
  • Administrator Guide
  • How Data Is Used
  • Privacy Request
  • Account Deletion
  • Contact Us

Company

  • Case Studies
  • SPS, Inc.
  • General Contact
  • Security Contact
  • Privacy Contact
© 2026 Software Productivity Strategists, Inc. MYID Self Verify is an SPS product.
Privacy Terms Cookies Cookie choices
Your analytics choice

We use optional first party analytics to understand when people visit, where they came from, which pages they use, and the general device category. We do not use advertising trackers or sell this information. Read our Cookie Notice.