Privacy policy
This page says what happens to information when you use this site. It is written to be read, not to be survived. If something here is unclear, that is a fault in the writing and we would like to know.
NBOP is a certification body in formation. The National Board of Operations Professionals, of 16220 N. Scottsdale Rd, Suite 300, Scottsdale, AZ 85254, United States, is the data controller for everything described below, and is the only party that holds any of it.
Companies see anything at all, Google Analytics and Meta, and neither of them sees a thing you type.
Accounts required to read this site, check eligibility, or verify a credential.
Field on this site asks for a personal detail, and it is optional.
We do not sell, rent or trade personal information, and there is no arrangement under which we could.
What we collect, and when
Reading the site
Nothing is asked of you. Our web server keeps ordinary access logs, which include your IP address, the page requested, the time, and your browser user agent. Those logs exist so the site can be kept running and abuse can be investigated. They are not used to build a profile of you.
The eligibility check
The check at Am I eligible? sends your three answers, the years, whether the role is current, and which domains you hold, to our API. That is deliberate. The published criteria and the code that applies them are one implementation rather than two, so the page cannot drift from the standard and quietly tell you something the rule does not say.
Those answers are not kept. The response from that endpoint contains
stored: false and the page prints that back to you, because a
claim that we are not keeping something is only worth making if you can
check it. There is no account and no email field, and nothing about the
check is written to a database.
The job task analysis
The form at Contribute to the standard is the only place on this site that collects anything from you deliberately. It collects your ratings of 48 tasks, your rough split of time across the eight domains, your free-text answers about what is missing, your answer about serving on the standards committee, and an email address if you choose to give one. The email field is optional and the form submits without it.
Individual responses are never published, never shared, and never disclosed to an employer or a third party. Ratings are aggregated into published summary statistics. If you give an email address it is used to send you the published results and, if you said you would consider serving, to talk to you about the standards committee. It is not added to a marketing list.
We ask you not to name your employer in the free-text fields. If you do, we will remove it before anything is analysed or published.
The register and verification
The register and the verification tool are public by design. When certificates exist, a holder's name, sector, region, endorsements, certificate number and status will appear there, because a credential nobody can check is not a credential. Searching the register or verifying a number does not require an account and the holder is not told that you looked.
Certification, when applications open
Applications are not open. When they are, applying will require the personal and employment information needed to assess you against the published criteria, and the fee will be taken by a payment processor. Card details go to that processor directly. We never see them and never store them. This section will be rewritten with the specifics before the first application is accepted, not after.
Everyone who sees anything
We would rather this list were shorter, and in August 2026 it got shorter. Here it is in full. There is nothing else. No tag manager, no session recorder, no heat map, no chat widget, no advertising network other than Meta.
| Who | What they get | Why |
|---|---|---|
| Google Analytics | Pages you viewed, roughly where you are, what brought you here, and an identifier stored in your browser. Google signals and advertising personalisation are both switched off, so this data does not feed Google's advertising graph. | To know whether anyone is reading, and which pages lose people. |
| Meta | That you visited a page, the page title and description, and whether you started or finished the job task analysis. Not your answers. Meta may match this to a Facebook or Instagram account if you have one. | We buy advertising on Meta to reach operations professionals for the job task analysis, and this is how we know whether it worked. |
| Google Fonts, until 23 August 2026 | Nothing, now. Your browser used to fetch the two typefaces from Google's servers, which handed Google your IP address on every page. | It was there for typography, which we called the weakest justification on this page. The two typefaces are open licensed, so they are now served from this domain and Google is no longer involved in rendering this site. |
The signed-in portal at /portal/ carries no Meta pixel. That
exclusion is deliberate: what a certificate holder or an administrator does
inside their own account is not advertising data.
Cookies and similar storage
Google Analytics and the Meta pixel each store an identifier in your browser. Nothing on this site stores anything for advertising beyond that, and there are no cookies from any other party. The cookie page lists every one of them by name, with what it does and how long it lasts.
One item in that list is ours rather than theirs, and it is the only one that holds anything you wrote. The job task analysis saves your unfinished answers into your own browser so that rating 48 tasks does not have to happen in one sitting. That draft includes your ratings, your free text and the email address if you have typed one. It stays on your device, we cannot read it, it is never transmitted, and it is deleted as soon as a submission succeeds. On a shared computer, finishing the form or clearing site data is what removes it, and there is no control on our side that can.
You can refuse all of it. Browser settings, tracking protection, and any common content blocker will stop both scripts, and every page on this site works normally without them. Nothing is gated, degraded or nagged. If you block us, we simply do not see you, which is a trade we accept.
How long we keep things
| What | How long |
|---|---|
| Server access logs | Our host archives them monthly and we keep only the current archive, so an entry is gone within about two months at the outside. |
| Job task analysis responses | Kept while the round is open and for the life of the standard version they informed, because a finding that cannot be re-checked is not evidence. Any email address attached to a response is deleted once the results of that round have been sent. |
| Google Analytics, event data | 2 months, which is the shortest Google allows. |
| Google Analytics, user data | 14 months. Google restarts that clock each time the same browser returns, so for a regular reader it does not expire while they keep reading. |
| Register entries | For as long as the credential is live, and afterwards as an expired or revoked record, because withdrawing the history would defeat the point of a public register. |
Where the data is
Our site and our database are hosted in the United States. Google and Meta are United States companies operating globally. If you are reading this from the United Kingdom, Ireland, the European Economic Area, Canada or Australia, your information is being handled in the United States and you should decide with that in mind.
Your rights
Depending on where you live you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to object to how it is used, or to receive a copy. We do not require you to live anywhere in particular to ask. Write to us and we will answer.
The one thing we will not do on request is remove a live credential from the public register, because employers rely on it and a register with holes is worse than none. Everything else is negotiable and most of it is automatic.
Requests go to the address on the contact page. We aim to answer inside 30 days. If we get it wrong, people in the United Kingdom can complain to the Information Commissioner's Office and people in the European Economic Area can complain to their national supervisory authority. We would rather you told us first.
What we do not do
- We do not sell, rent or trade personal information.
- We do not run a marketing list, and there is nothing on this site to subscribe to.
- We do not publish individual job task analysis responses, in any form, ever.
- We do not tell a credential holder who checked them.
- We do not require an account to read anything, check eligibility, or verify a credential.
- We do not use dark patterns to obtain consent, because we do not ask for consent to do anything you cannot already block.
Children
This site is for working operations professionals and is not directed at anyone under 18. We do not knowingly collect anything from a child. If you believe we have, tell us and it will be deleted.
Changes
When this policy changes materially we will say so on the changelog alongside changes to the standard, rather than quietly updating a date at the bottom of the page and calling that notice.
If any of this is wrong, tell us
A body that assesses other people's rigour should be checkable on its own.
If you find a claim on this page that is not true of what the site actually does, that is a defect and we want it reported. The technical facts here were checked against the live site, and they should stay checked.