Privacy Policy
Last updated: August 2026
Plain English Summary
- We collect only the data we need to run the service.
- We never sell your data to anyone — ever.
- You can delete your account and all your data at any time.
- We use industry-standard encryption and secure cloud storage.
- We send you emails related to your compliance alerts and your account only.
1. Who we are
Certivenza is a software-as-a-service (SaaS) platform that helps businesses track employee compliance documents. When this policy says "we", "us", or "Certivenza", it means the team operating this service at support@certivenza.app.
2. What information we collect
Account information: When you sign up, we collect your name, email address, and a hashed (unreadable) version of your password. We never store your plain-text password.
Organisation information: Your company name, country, industry, and any logo you upload.
Employee data: Names, email addresses, phone numbers, job titles, departments, and locations of employees you add to your account. This data belongs to you — we process it on your behalf.
Compliance documents: Expiry dates, issue dates, and any certificate files (PDF, JPG, PNG) you upload. Uploaded files are stored securely in encrypted cloud storage.
Usage data: We collect basic server logs (IP address, browser type, pages visited) to keep the service running and to diagnose problems. This is standard practice for any web application.
Payment data: We do not store card numbers. Payments are handled by LemonSqueezy, a PCI-DSS compliant payment processor. We receive confirmation of payment status only.
3. How we use your information
We use your data only to:
- Provide and improve the Certivenza service
- Send compliance expiry alert emails (which is the whole point)
- Send important account emails (password resets, billing confirmations)
- Respond to your support requests
- Understand how the product is used so we can improve it
We do not use your data for advertising. We do not sell your data. We do not share your data with third parties except as described in section 4.
4. Who we share data with
We use a small number of trusted third-party services to operate Certivenza:
- MongoDB Atlas — database hosting (AWS-backed, encrypted at rest)
- Supabase Storage — encrypted file storage for uploaded documents
- LemonSqueezy — payment processing (PCI-DSS compliant)
- SMTP email provider — for sending alert and transactional emails
Each of these providers has its own privacy policy and is contractually required to protect your data. We do not share your data with any other parties.
We may disclose data if required by law (e.g. a court order), but we will notify you where legally permitted before doing so.
5. How we protect your data
We take security seriously:
- All data is transmitted over HTTPS (TLS encryption)
- Passwords are hashed using bcrypt — we cannot read them
- Uploaded files are stored with access controls — only users in your organisation can access them
- File download links expire after 1 hour
- Session tokens are stored in httpOnly cookies (not accessible to JavaScript)
6. How long we keep your data
We keep your data for as long as your account is active. If you cancel your subscription or delete your account:
- Your data remains accessible for 30 days (in case you change your mind)
- After 30 days, all employee data, documents, and account information is permanently deleted
- Payment records may be kept for up to 7 years for legal/accounting reasons (LemonSqueezy handles this)
7. Your rights
You have the right to:
- Access — request a copy of all data we hold about you
- Correct — update any inaccurate information (you can do this yourself in Settings)
- Delete — request deletion of your account and all associated data
- Export — download your employee and document data at any time using the Audit Report feature
- Object — opt out of any non-essential communications
To exercise any of these rights, email us at privacy@certivenza.app.
8. GDPR (UK & EU users)
If you are based in the UK or EU, we process your data under the lawful basis of "contractual necessity" — meaning we need to process it to provide the service you signed up for.
You also have the right to lodge a complaint with your national data protection authority (e.g. the ICO in the UK) if you believe we have not handled your data appropriately.
9. Cookies
We use one essential cookie: auth_token — an httpOnly session cookie that keeps you logged in. This is strictly necessary for the service to function. We do not use tracking cookies or advertising cookies.
10. Changes to this policy
If we make significant changes to this policy, we will notify you by email and update the "Last updated" date at the top. Continued use of the service after changes means you accept the updated policy.
11. Contact
For any privacy questions or requests, contact us at privacy@certivenza.app.