Privacy Policy
Effective date: July 1, 2026
Certifable, Inc. ("Certifable," "we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share information when you use our certification management platform and related services (the "Service").
1. Information We Collect
Information You Provide
- Account information: Name, email address, organization name, and role when you register for an account.
- Certification data: Documents, audit records, registration details, and other materials you upload or create within the platform.
- Payment information: Billing address and payment method details, processed securely through our payment provider (Stripe).
- Communications: Messages you send through our contact form, support channels, or email correspondence.
Information Collected Automatically
- Usage data: Pages visited, features used, timestamps, and interaction patterns within the Service.
- Device information: Browser type, operating system, screen resolution, and device identifiers.
- Network data: IP address, approximate geographic location, and referring URLs.
2. How We Use Your Information
We process your information for the following purposes:
- Providing, maintaining, and improving the Service
- Processing certification workflows, document reviews, and audit scheduling
- Managing your account and processing payments
- Communicating service updates, security alerts, and support responses
- Analyzing usage patterns to enhance platform performance and features
- Detecting and preventing fraud, abuse, or security incidents
- Complying with legal obligations and regulatory requirements
3. Data Sharing and Disclosure
We do not sell your personal information. We may share data in the following circumstances:
- Service providers: Trusted third parties that assist in operating the Service (hosting, payment processing, email delivery), bound by confidentiality agreements.
- Within your organization: Data shared between agency staff and clients as configured within the platform's permission structure.
- Legal requirements: When required by law, subpoena, court order, or to protect the rights, safety, or property of Certifable or others.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to affected users.
4. Third-Party Services
The Service integrates with the following categories of third-party providers:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Billing details, transaction amounts |
| Cloud hosting (AWS) | Infrastructure | All platform data (encrypted at rest) |
| Email service | Transactional emails | Recipient email, message content |
| Analytics | Usage insights | Anonymized interaction data |
5. Cookies and Tracking
We use cookies and similar technologies for:
- Essential cookies: Required for authentication, session management, and security. Cannot be disabled.
- Analytics cookies: Help us understand how the Service is used. These can be opted out of via your browser settings.
We do not use advertising cookies or third-party tracking pixels. We do not participate in cross-site behavioral advertising.
6. Data Retention
- Active accounts: Data is retained for the duration of your subscription and 30 days after cancellation.
- Certification records: Retained for the validity period of issued certificates plus 3 years, as required by certification industry standards.
- Audit logs: Retained for 7 years to satisfy regulatory and compliance requirements.
- Deleted accounts: Personal information is purged within 90 days of account deletion, except where retention is legally required.
7. Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Regular security audits and penetration testing
- Role-based access controls and principle of least privilege
- Automated monitoring for suspicious activity
- Secure, isolated database environments with daily backups
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal data
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Request that we limit processing of your data
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@certifable.com. We will respond within 30 days.
9. International Data Transfers
Your data may be processed in the United States. Where data is transferred across borders, we rely on Standard Contractual Clauses or equivalent safeguards to ensure adequate protection in compliance with applicable data protection laws.
10. Children's Privacy
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal data, please contact us for immediate removal.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice within the Service at least 30 days before taking effect. The "Effective date" at the top reflects the latest revision.
12. Contact Us
For privacy-related inquiries or to exercise your data rights, reach us at:
Certifable, Inc.
Attn: Privacy Team
privacy@certifable.com