Data policy
How we handle data
Last updated: 26 July 2026
What we collect
Depending on how you use we-verifi, we hold:
- Certificate holder details — name, email address, and the course or qualification a certificate relates to.
- Account details — email address, and for staff accounts, role and organisation.
- Organisation details — the name and configuration of your organisation on the platform.
- Usage and audit records — a log of significant actions taken on the platform (e.g. a certificate being issued or revoked), kept for accountability and troubleshooting.
We only collect what's needed to issue, verify, and manage certificates — not for advertising or unrelated profiling.
Where it's stored
Data is stored on Google Cloud infrastructure, encrypted both in transit and at rest. Each organisation's data is kept logically separate from every other organisation's — one customer never has visibility into another's records.
Google Cloud's infrastructure may process data outside the UK and EEA as part of its global operation. Google provides contractual safeguards for this (their own Data Processing Terms and Standard Contractual Clauses) — we rely on these as our underlying legal basis for any such transfer.
Who we share it with
We use a small number of third-party services to actually run the platform — each only processes the specific data needed to do its job:
- Google Cloud / Firebase — hosting, database, file storage, and authentication.
- Email delivery providers (currently Brevo and Resend) — to send certificates, account, and verification emails.
- Payment processing (Stripe, where applicable) — to process credit bundle purchases. Card details are handled entirely by Stripe; we never see or store them.
What we don't do
We do not sell personal data to third parties. We do not share it with advertisers, data brokers, or anyone outside the small set of processors listed above who help us run the service.
Use across the we-verifi group
we-verifi is the parent platform behind a family of products — Cert Verifi today, with Project Verifi and Art Verifi in development. Data collected through one product may be used across other products in the we-verifi group, for purposes like providing a consistent account experience, platform security, and improving our services. It is not shared outside the we-verifi group, and each product still only collects and uses what's relevant to what it actually does.
Certificates issued through school accounts
Where a certificate is issued through a school account, the certificate holder's information (name, email address, and course or qualification details) is used only to issue, deliver, and verify that certificate — not for any additional purpose, marketing, or profiling.
Staff members who administer a school's account may separately receive informational and product updates from us, based on their own preference setting. This applies only to staff accounts, never to certificate holders.
How long we keep it
Certificates and their associated records are kept for as long as the issuing organisation's account is active, since a certificate is meant to remain verifiable long-term. Temporary records — like sign-in codes and password reset links — are automatically deleted shortly after they expire, typically within a few days.
Your rights
Depending on where you're located, you may have rights to access, correct, or request deletion of your personal data, or to object to certain uses of it. If you'd like to exercise any of these, contact hello@we-verifi.co.uk and we'll respond as required by applicable law.
Questions
For anything not covered here, or if you're a school or organisation with a specific data protection question before signing up, reach out to hello@we-verifi.co.uk.