Skip to main content

User-directed access

Users direct Argyle through Link to connect selected accounts and share their data with your organization. At the user’s instruction, the platform uses the credentials they provide to create the connection and deliver available information to the requested recipient. Your application can access that data through Console or the API according to its Argyle permissions.
See our Consumer Privacy Notice and Consumer Terms for access, processing, sharing, retention, and deletion terms.

Connections and deletion

Users can remove connections through Link or Argyle Passport. They can also request help removing a connection by emailing privacy@argyle.com. When a connection is removed, data from that account is no longer available to your organization through Console or the API. Argyle’s systems are designed to delete the associated employment data subject to the exceptions described in the Consumer Privacy Notice. Your application should also delete data it no longer needs according to your own retention requirements and applicable agreements.

Security measures

Argyle applies physical, organizational, and technical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, or destruction.

Implementation best practices

  1. Grant team members only the Console permissions required for their role.
  2. Create separate API keys for separate backend systems and environments.
  3. Store API secrets outside client-side code and source control. See API key security.
  4. Remove unused API keys and team access promptly.
  5. Keep Link SDK installations current by following the Upgrade Guide.
  6. Subscribe to the Changelog for API, SDK, and security-related product updates.