AI-powered people operations for fleets and distributed teams.
Effective Date: August 1, 2026 · Last Updated: August 1, 2026
This Privacy Policy explains how Orior Media, LLC (“Orior Media,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with (a) our website at pplgo.com (the “Site”) and (b) PPL., the multi-tenant HR and workforce-management software we license to business customers (the “Service”).
Section 2 explains two different roles we play depending on the data involved — read it first, since it determines who to contact about your information.
ON THIS PAGE
Site Visitors — anyone who visits pplgo.com, submits a contact or demo-request form, or subscribes to our newsletter.
Customer Personnel — administrators, HR staff, and managers at a business that licenses the Service (a “Customer”) who are authorized to use it.
End Users — employees, job applicants, and contractors of a Customer, whose personal information a Customer enters into, or generates within, the Service in the course of its own HR and recruiting operations.
Privacy law distinguishes between a controller (the party that decides why and how personal data is processed) and a processor / service provider (the party that processes data on behalf of and under the instructions of a controller).
Where we act as Controller — for Site visitor data (contact forms, newsletter sign-ups, Site analytics and advertising) and for our own account and billing records with Customers, Orior Media determines the purpose and means of processing and is the controller responsible for that data.
Where we act as Processor — for personal information a Customer enters into, uploads to, or generates within the Service about its own employees, applicants, or contractors (“End User Data”), Orior Media acts solely as a processor. The Customer is the controller: it decides what data to collect, how long to keep it, who may access it, and how to respond to End User rights requests. We process End User Data only under the Customer’s instructions and our Data Processing Addendum with that Customer.
If you are an End User and have a question about your data, contact your employer or the organization you applied to directly — they control your record. We assist our Customers in responding to verified End User requests as required by law and by our contract with them.
3.1 Information Collected on the Site (as Controller)
Contact information — name, email, phone, company, job title. Source: you, via forms.
Inquiry content — message content, stated requirements. Source: you, via forms.
Newsletter subscription — email address. Source: you, via sign-up form.
Usage and device data — IP address, browser/device type, pages viewed, referring URL, approximate location derived from IP. Source: automatically, via cookies (Section 6).
Advertising identifiers — cookie/pixel identifiers used by Google and Meta. Source: automatically, via cookies (Section 6).
You can unsubscribe from marketing emails at any time using the link included in those emails.
3.2 Information Processed Through the Service (as Processor)
The specific fields a Customer collects are configurable by that Customer. Categories the Service is built to process include:
Identity & contact — name, email, phone, address, date of birth, emergency contact.
Employment records — title, department, team, manager, employment type, work location, status, start/end date, employment history.
Recruiting & candidate data — résumé/CV content, cover letters, application answers, interview notes and feedback, hiring-pipeline status.
Compensation — salary, bonus eligibility, payroll-related metadata (visible only to authorized roles).
Performance — KPI scores, performance reviews, goals, improvement plans, meeting notes.
Time & scheduling — PTO/leave requests and balances, shift assignments, calendar data.
Documents — employment contracts, identification documents, policy acknowledgments, training certificates, and — for Customers in regulated industries such as commercial transportation — driver’s license / CDL numbers, DOT medical certification records, drug- and alcohol-testing records, and background check results.
Communications — messages, notifications, and acknowledgment records sent through the Service.
System & audit data — login activity, IP address, and an immutable audit trail of actions taken on records.
We do not knowingly process Social Security numbers or other government national ID numbers, biometric identifiers (e.g., fingerprint or facial recognition data), or precise geolocation/GPS tracking data through the Service. If that changes, this Policy will be updated before such processing begins.
Sensitive categories. Driver’s license/CDL numbers, DOT medical and drug/alcohol testing records, and background check results are treated as sensitive personal information under several privacy and employment laws (see Section 9). These fields exist to support Customers in regulated industries that are legally required to collect and retain them. Access is restricted through role- and field-level permissions, and every view, edit, and export is logged.
As Controller (Site data): to respond to inquiries, provide requested demos or information, operate and improve the Site, send marketing communications you’ve opted into, measure and improve advertising performance, and comply with legal obligations.
As Processor (Service data): solely to provide, maintain, secure, and support the Service under our Customer’s instructions and our contract with them — authenticating users, enforcing the Customer’s configured permissions, storing and displaying the records its users enter, sending the notifications its workflows trigger, generating the reports it requests, and troubleshooting issues it reports. We do not use End User Data for our own marketing, do not sell it, and do not use it to train AI models.
Where European data protection law applies, we rely on:
Contract — processing necessary to provide services you’ve requested, or to perform our contract with a Customer.
Consent — for newsletter sign-ups, non-essential cookies, and any processing of special category data where consent is the applicable basis.
Legitimate interests — for Site analytics, security, fraud prevention, and service improvement, balanced against your rights.
Legal obligation — where processing is required by law (e.g., tax, employment, or transportation recordkeeping rules).
For End User Data, the Customer, as controller, is responsible for identifying its own legal basis for processing.
The Site uses cookies and similar technologies, deployed via Google Tag Manager:
Google Analytics 4 (GA4) — Site usage analytics. Category: Analytics.
Google Ads — conversion tracking, remarketing. Category: Advertising.
Meta Pixel — conversion tracking, remarketing on Facebook/Instagram. Category: Advertising.
Cookie categories: Necessary (required for the Site to function; cannot be disabled) · Analytics (help us understand Site usage) · Advertising (used by Google and Meta to measure ad performance and show relevant ads elsewhere; these involve sharing an online identifier with those companies).
Your choices. Where required by law, we request consent before setting non-essential cookies via a cookie-consent banner. You can withdraw consent, adjust preferences in the banner, or manage cookies through your browser settings at any time. You can also opt out directly through Google Ads Settings, Meta Ad Preferences, and the Digital Advertising Alliance opt-out page. We honor the Global Privacy Control (GPC) signal as a valid opt-out of sale/sharing where required by applicable law.
We do not sell personal information. We do share certain Site identifiers with Google and Meta via the advertising cookies described in Section 6, which may constitute “sharing” for cross-context behavioral advertising under some state laws — you can opt out as described in Section 6.
We disclose personal information to:
Sub-processors / service providers, under contractual confidentiality and security obligations:
Microsoft Azure — cloud application hosting, PostgreSQL database, file/object storage, and background job queue (Redis). Data involved: all Service data.
SendGrid (Twilio) — transactional and system email delivery. Data involved: name, email, message content.
Google (Calendar / Meet) — calendar sync, interview scheduling, video-meeting links, where a Customer enables this integration. Data involved: name, email, event details.
Google Analytics, Google Ads, Meta — Site analytics and advertising (Site only, not the Service). Data involved: device/usage/advertising identifiers.
Customer-configured integrations. A Customer may connect its own third-party tools. Those integrations are configured and controlled by the Customer, and data shared through them is subject to that third party’s own privacy practices.
Legal and safety disclosures. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Orior Media, our Customers, or others.
Business transfers. If Orior Media is involved in a merger, acquisition, financing, or asset sale, personal information may be transferred as part of that transaction, subject to standard confidentiality protections.
We retain personal information for as long as necessary to provide the Site or Service, fulfill the purposes described in this Policy, and meet our legal and contractual obligations, then delete or anonymize it, except where a longer period is required or permitted by law.
End User Data specifically: retention periods for candidate records, employee records, documents, and audit logs are configurable by each Customer, since the Customer — as controller — is responsible for setting retention consistent with its own legal and business requirements. Absent a Customer-specific configuration, we retain such records only as long as necessary for the purposes above.
Regulated records. Where a Customer operates in a regulated industry such as commercial transportation, certain records — including driver qualification files and drug- and alcohol-testing records — are subject to separate minimum retention periods mandated by applicable law (e.g., U.S. Department of Transportation / Federal Motor Carrier Safety Administration recordkeeping rules), regardless of a Customer’s general retention configuration.
Your rights depend on where you live and, for End User Data, on your relationship to the Customer (see Section 2).
If you are in the EEA, UK, or Switzerland: you may access, correct, or erase your data; restrict or object to processing; request portability; and lodge a complaint with your local data protection authority. Certain data we process — including health-related data such as DOT medical or drug/alcohol testing records — is “special category data” under Article 9 GDPR and receives heightened protection.
If you are a California or other U.S. state resident: depending on your state, you may have the right to know what personal information we collect, use, and disclose; delete it; correct inaccuracies; opt out of the sale or sharing of personal information for cross-context behavioral advertising (Section 6); and limit the use of Sensitive Personal Information. “Sensitive Personal Information” under laws like California’s CPRA includes certain government ID numbers (such as driver’s license/CDL numbers) and health-related information (such as DOT medical or drug/alcohol testing records) — categories the Service processes for certain Customers as described in Section 3.2. We do not use or disclose Sensitive Personal Information for purposes other than providing the Service. We will not discriminate against you for exercising any privacy right.
If you are an End User (employee, applicant, or contractor of a Customer): your employer or prospective employer controls your data. Please direct requests to them first. If you contact us directly, we will refer you to the relevant Customer or assist them in responding, consistent with our contract with that Customer.
To exercise your rights, contact support@oriormedia.com. We may need to verify your identity before acting on a request.
We maintain administrative, technical, and organizational safeguards, including:
Layered access control — every request is checked for authentication, correct tenant scope, role-based module permissions, and field-level permissions before data is returned.
Encryption — data is encrypted in transit; sensitive data is encrypted at rest where supported by our infrastructure.
Credential hygiene — third-party integration credentials are stored as references to a secrets manager, never as plaintext, and are never returned in API responses.
File security — uploaded files are validated and virus-scanned, and served only via time-limited signed URLs — never direct public links.
Audit logging — sensitive actions (record changes, document access, exports, permission changes) are recorded in an immutable audit trail, including actor, timestamp, and IP address.
Tenant isolation — every query is scoped to the requesting Customer; cross-tenant access by our own support staff requires explicit, time-limited, audited authorization.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Orior Media is based in the United States, and the infrastructure we use is primarily located in the United States. If you are located outside the United States, your information will be transferred to, stored, and processed in the United States and potentially other countries where our service providers operate. Where required, we rely on appropriate safeguards for such transfers, such as Standard Contractual Clauses, for personal information originating in the EEA, UK, or Switzerland.
The Site and Service are intended for business use by adults and are not directed at children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us at support@oriormedia.com and we will take appropriate steps to delete it.
The Site may link to third-party websites we do not control. This Policy does not apply to those sites; please review their own privacy policies.
We may update this Policy from time to time. If we make material changes, we will update the “Last Updated” date above and, where appropriate, provide additional notice (such as an email to Customer administrators or a notice on the Site).
Orior Media, LLC
1581 W Marlin Dr
Chandler, AZ 85286, USA
support@oriormedia.com
This Policy is governed by the laws of the State of Arizona, without regard to conflict-of-laws principles, except where applicable data protection law requires otherwise.
Questions about this page? Contact support@oriormedia.com.