Privacy Policy
Last updated: August 17, 2026
1. Introduction
CertVerify ("we," "us," "our," or "Company") is committed to protecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information
when you visit our website we-verifi.co.uk (the "Site") and use our certificate
issuance platform.
2. Information We Collect
2.1 Information You Provide Directly
- Contact forms: Name, email, company, inquiry details (when you contact sales or request a demo)
- Account creation: Email, password, organization name, role
- Certificate data: Learner names, emails, course information, scores (when you issue certificates)
2.2 Information Collected Automatically
- Google Analytics: Pages visited, time on site, referrer, device type, browser, IP address (anonymized)
- Cookies: Session ID, consent preferences, usage analytics
- Server logs: Request timestamps, HTTP status codes (standard web server logs)
3. How We Use Your Information
3.1 Marketing Site (we-verifi.co.uk)
- Improve site performance and user experience
- Understand how visitors use the site (Google Analytics)
- Respond to inquiries and provide customer support
- Send marketing emails (only if you opt-in)
3.2 CertVerify Platform (certs.we-verifi.co.uk)
- Deliver certificate issuance services
- Verify and revoke certificates
- Generate audit logs for compliance
- Process payments (Stripe)
- Send certificate delivery emails
4. Legal Basis (GDPR / UK PECR)
4.1 For the Marketing Site
- Analytics (Google Analytics): Your consent via cookie banner
- Contact forms: Your consent to be contacted
- Marketing emails: Your explicit opt-in
4.2 For the Platform
- Certificate issuance: Performance of contract with your organization
- Payment processing: Contractual necessity
- Audit logs: Legal obligation (compliance & fraud prevention)
Cookie consent: We do not fire Google Analytics or place non-essential cookies
until you explicitly accept via our cookie banner. You can decline analytics while still using
the Site.
5. Cookies & Tracking
5.1 Essential Cookies (Always On)
- Session ID (allows you to stay logged in)
- CSRF token (security)
5.2 Analytics Cookies (Requires Consent)
5.3 Marketing Cookies
We currently do NOT use remarketing or social media cookies. If this changes, we will update this policy.
6. Data Retention
6.1 Marketing Site
- Google Analytics data: 26 months (Google default)
- Contact form submissions: 2 years (for support inquiries)
- Cookies: 12 months (cookie consent preference)
6.2 Platform
- Certificates: Retained indefinitely (learners need permanent access)
- Audit logs: 90 days (auto-delete via TTL)
- Payment records: 7 years (legal/tax requirement)
7. Data Sharing & Third Parties
We share data only with essential service providers:
- Google Analytics: Anonymized traffic data (no personal info sent)
- Stripe: Payment information (PCI-DSS compliant)
- Brevo/Resend: Email addresses for certificate delivery
- Firebase (Google Cloud): Hosting & database (Data Processing Agreement in place)
We do NOT sell or rent your personal data to third parties.
We do NOT share certificate holder information with external parties without explicit instruction from your organization.
8. Data Rights (GDPR / UK GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion ("right to be forgotten")
- Portability: Receive your data in a standard format
- Withdraw consent: Opt out of analytics, marketing emails
To exercise these rights, email us at support@we-verifi.co.uk with your request.
We will respond within 30 days.
9. Security
- All data transmitted via HTTPS (TLS 1.2+)
- Passwords hashed (Firebase Auth)
- API keys stored in Secret Manager (never in code)
- Audit logs immutable (append-only)
- Infrastructure hosted on Google Cloud (SOC 2 compliant)
While we implement strong security measures, no system is 100% secure.
If you believe your data has been compromised, contact us immediately.
10. International Data Transfers
Your data may be processed in the US (Google Cloud / Firebase).
We rely on the UK's adequacy determination for US transfers and Standard Contractual Clauses
where necessary.
11. Children's Privacy
We do not knowingly collect data from children under 13.
Learners using our platform should have parental consent if under 13.
12. Changes to This Policy
We may update this Privacy Policy from time to time.
We will notify you of material changes via email or a prominent notice on the Site.
Continued use of the Site after changes constitutes acceptance.
13. Contact Us
If you have questions about this Privacy Policy, contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with the
Information Commissioner's Office (ICO) at ico.org.uk.