Privacy Policy
Last updated: May 20, 2026
1. Information We Collect
Account Information
When you register an organization on CertProof, we collect your name, email address, organization name, and password. Organization administrators may also provide a website URL, phone number, and address.
Certificate Data
Organizations provide student or recipient names, email addresses, certificate titles, and other custom fields when issuing certificates. This data is stored to generate verifiable digital certificates.
Usage Data
We automatically collect information about how you interact with the platform — including pages visited, features used, timestamps of actions, and device/browser information. This helps us improve the product.
Payment Information
When you upgrade to a paid plan, payment is processed by Razorpay (operated by Razorpay Software Private Limited). CertProof does not store your card or bank details. We only receive a payment confirmation and transaction ID.
Email Delivery
If you use the certificate email feature, recipient email addresses are shared with Resend (our email delivery provider) solely for the purpose of delivering the certificate email. We do not use recipient emails for any other purpose.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your organization account
- Issue, store, and display digital certificates
- Enable public certificate verification
- Send transactional emails (certificate delivery, account notifications)
- Process subscription payments and billing
- Provide customer support
- Improve platform features and fix bugs
- Comply with legal obligations
We do not sell your personal data to third parties. We do not use your data for advertising.
3. Data Storage and Security
CertProof uses Google Firebase (Firestore and Firebase Storage) to store all platform data. Data is stored on Google Cloud infrastructure with encryption at rest and in transit.
We use Firebase Security Rules to ensure that organization data can only be accessed by authorized users. Certificate verification pages are intentionally public — this is the core purpose of the platform.
While we take reasonable measures to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
4. Sharing of Information
We share your information only in these circumstances:
Service Providers
We share data with Google Firebase (storage), Resend (email delivery), and Razorpay (payment processing) — solely to operate the platform. These providers have their own privacy policies.
Public Certificate Verification
Certificate data (student name, certificate title, issue date, status) is publicly accessible via the verification URL. This is by design — organizations issue certificates knowing they will be publicly verifiable.
Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal process (court orders, government requests).
5. Cookies and Tracking
CertProof uses session cookies and browser local storage to keep you logged in and maintain your preferences. We use Firebase Analytics to understand aggregate usage patterns. We do not use third-party advertising cookies.
6. Data Retention
We retain your account and certificate data for as long as your organization account is active. If you delete your account, we will delete your organization data within 30 days, except where we are required to retain it for legal or compliance purposes.
Certificate records may be retained for a longer period if they have been publicly shared and verified, to maintain the integrity of the verification record.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data via your Settings page
- Delete your account and associated data by contacting us
- Withdraw consent for email communications by contacting us
To exercise any of these rights, contact us at support@certproof.in.
8. Children's Privacy
CertProof is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered organizations of significant changes by email or via a notice in the dashboard. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact Us
If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us: