Privacy Policy

Effective date: September 12, 2026


Certifable, Inc. ("Certifable," "we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share information when you use our certification management platform and related services (the "Service").

1. Information We Collect

Information You Provide

  • Account information: Name, email address, organization name, and role when you register for an account.
  • Certification data: Documents, audit records, registration details, and other materials you upload or create within the platform.
  • Payment information: Billing address and payment method details, processed securely through our payment provider (Stripe).
  • Communications: Messages you send through our contact form, support channels, or email correspondence.

Information Collected Automatically

  • Usage data: Pages visited, features used, timestamps, and interaction patterns within the Service.
  • Device information: Browser type, operating system, screen resolution, and device identifiers.
  • Network data: IP address, approximate geographic location, and referring URLs.
  • Campaign attribution: Recognized campaign parameters and advertising click identifiers included in a landing-page URL, such as UTM values, Google click IDs, LinkedIn click IDs, Meta click IDs, and TikTok click IDs.

2. How We Use Your Information

We process your information for the following purposes:

  • Providing, maintaining, and improving the Service
  • Processing certification workflows, document reviews, and audit scheduling
  • Managing your account and processing payments
  • Communicating service updates, security alerts, and support responses
  • Analyzing usage patterns to enhance platform performance and features
  • Measuring which campaigns produce genuine inquiries, account registrations, and subscriptions
  • Detecting and preventing fraud, abuse, or security incidents
  • Complying with legal obligations and regulatory requirements

3. Data Sharing and Disclosure

We do not sell your personal information. We may share data in the following circumstances:

  • Service providers: Trusted third parties that assist in operating the Service (hosting, payment processing, email delivery), bound by confidentiality agreements.
  • Within your organization: Data shared between agency staff and clients as configured within the platform's permission structure.
  • Legal requirements: When required by law, subpoena, court order, or to protect the rights, safety, or property of Certifable or others.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to affected users.

4. Third-Party Services

The Service integrates with the following categories of third-party providers:

ProviderPurposeData Shared
StripePayment processingBilling details, transaction amounts
Cloud hosting (AWS)InfrastructureAll platform data (encrypted at rest)
Email serviceTransactional emailsRecipient email, message content
AnalyticsUsage insightsAnonymized interaction data
Google AdsConsent-gated campaign and inquiry measurementBrowser and device data, page context, advertising click identifiers, and an opaque inquiry reference

5. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential cookies: Required for authentication, session management, and security. Cannot be disabled.
  • Analytics cookies: Help us understand how the Service is used. These can be opted out of via your browser settings.
  • First-party campaign attribution: When a recognized campaign or click identifier appears in the page URL, we retain it for the current browser session and attach it to a contact inquiry only if you submit the form.
  • Optional Google Ads measurement: On Certifable-owned public marketing pages, the Google tag loads only after you choose Allow measurement. If a contact inquiry is successfully stored, we may send Google an opaque inquiry reference to count one conversion. We do not send the name, email address, company, subject, or message entered in the form.

Google Ads measurement is not loaded on agency-owned portal domains or authenticated application areas. Enhanced conversions and personalized advertising are not enabled. You may decline measurement or change your choice through the Privacy choices control on a Certifable marketing page. We do not participate in cross-site behavioral advertising.

6. Data Retention

  • Active accounts: Data is retained for the duration of your subscription and 30 days after cancellation.
  • Certification records: Retained for the validity period of issued certificates plus 3 years, as required by certification industry standards.
  • Audit logs: Retained for 7 years to satisfy regulatory and compliance requirements.
  • Sales inquiries: Contact details, messages, and campaign attribution are retained while the inquiry is active and for up to 3 years afterward, unless a longer period is required for a resulting customer relationship or legal obligation.
  • Deleted accounts: Personal information is purged within 90 days of account deletion, except where retention is legally required.

7. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Regular security audits and penetration testing
  • Role-based access controls and principle of least privilege
  • Automated monitoring for suspicious activity
  • Secure, isolated database environments with daily backups

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the data we hold about you
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Request that we limit processing of your data
  • Objection: Object to processing based on legitimate interests

To exercise any of these rights, contact us at privacy@certifable.com. We will respond within 30 days.

9. International Data Transfers

Your data may be processed in the United States. Where data is transferred across borders, we rely on Standard Contractual Clauses or equivalent safeguards to ensure adequate protection in compliance with applicable data protection laws.

10. Children's Privacy

The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal data, please contact us for immediate removal.

11. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice within the Service at least 30 days before taking effect. The "Effective date" at the top reflects the latest revision.

12. Contact Us

For privacy-related inquiries or to exercise your data rights, reach us at:

Certifable, Inc.
Attn: Privacy Team
privacy@certifable.com