Privacy Policy
Last updated: October 4, 2026
1. Introduction
This Privacy Policy explains how CertiTrack (“CertiTrack”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you visit thecertitrack.com, use the CertiTrack application at app.thecertitrack.com, or use the vendor upload portal (together, the “Services”).
CertiTrack is a business tool. Our customers are companies that use the Services to track the compliance documents of their vendors, contractors, and suppliers. If you do not agree with this policy, please do not use the Services.
2. Our role: controller and processor
- Account and website data. For information about our customers’ users, website visitors, and people who start signing up, CertiTrack decides how the information is used and acts as the “controller.”
- Customer Data. For the information our customers upload or enter about their vendors (for example vendor names, contact details, certificates, licenses, permits, and payment records), we act as a “processor” or “service provider” on the customer’s behalf. The customer decides what is collected and is responsible for having a lawful basis to share it with us. If you are a vendor and have a question about your information, please contact the company that requested your documents. We will help them respond.
3. Information we collect
Information you give us
- Account details: first and last name, work email address, company name, password (stored only in hashed form), time zone, and your user role.
- Sign-up details: the name and email address you enter when you start signing up, even if you don’t finish.
- Billing details: your plan and billing history. Card and bank details are entered directly with our payment processor, Stripe. We never see or store full card numbers.
- Customer Data: vendor names, contact names, email addresses, phone numbers, addresses, notes, uploaded documents (such as certificates of insurance, licenses, and permits), the details extracted from them, and payment records.
- Vendor portal uploads: documents and document types submitted by a vendor through a secure upload link.
- Communications: messages you send to us, including support requests.
- Settings: notification and account preferences.
Information collected automatically
- Technical and log data: IP address, browser type, device and operating system, pages and features used, and the date and time of requests. We record the IP address when you sign in, when you request a password reset, and when you accept our Terms, to protect accounts and to keep a record of acceptance.
- Product activity: actions taken in your account (for example uploads, extractions, and reminders sent), kept as an activity log for your company.
- Cookies and browser storage: see Section 7.
Information from others
- Members of your company may add you as a user.
- Customers provide information about their vendors, as described in Section 2.
- When you sign up, an email verification service checks that your email address is valid and deliverable.
4. How we use information
We use personal information to:
- Provide, operate, maintain, and secure the Services, including your account and subscription.
- Read uploaded documents with AI to extract details such as expiry dates, and show them to you for review.
- Send service emails, including verification codes, password resets, expiry reminders to you and your vendors, upload confirmations, usage alerts, and billing notices.
- Process payments and manage plans and limits.
- Respond to questions and support requests.
- Understand how the Services are used, fix problems, and improve them.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with law and enforce our Terms of Service.
Where the GDPR or similar laws apply, we rely on these legal bases: performing our contract with you or your company; our legitimate interests in running, securing, and improving the Services; your consent where we ask for it; and compliance with legal obligations.
We do not use Customer Data to train AI models. Our AI provider, Anthropic, reads documents for us under commercial terms that do not allow it to train its models on them.
5. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- Service providers (sub-processors) that help us run the Services, under contracts that require them to protect the information and use it only to provide their services to us:
| Provider | Purpose |
|---|---|
| Xano | Application backend and database |
| Amazon Web Services (S3) | Private storage of uploaded document files (United States) |
| Cloudflare | Website and application hosting and network security |
| Stripe | Payment processing and billing |
| Anthropic | AI reading of uploaded documents |
| Resend | Sending service emails |
| ZeroBounce | Checking that email addresses are valid at sign-up |
| Google Fonts | Delivering the typeface used on our website and app |
- Within your company account. Other users in your company account can see the Customer Data and activity in that account.
- Your vendors. When you send a reminder or upload link, the vendor receives the information included in it.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
- Legal reasons. To comply with law or valid legal process, or to protect the rights, property, or safety of CertiTrack, our customers, or others.
- With your direction or consent.
6. Data retention
- Account information and Customer Data are kept while your company’s account is active.
- When an account is closed, or when you ask us to delete your data, we delete or anonymize personal information within 30 days, except where we must keep it longer to meet legal, tax, or accounting obligations, resolve disputes, or enforce our agreements.
- Backups are overwritten on their regular cycle.
- Security and sign-in logs are kept only as long as needed for security purposes.
7. Cookies and browser storage
The CertiTrack application uses your browser’s local storage to keep you signed in and to remember small preferences (for example, whether you hid the Getting Started card). These are strictly necessary for the application to work. The application does not use advertising or tracking cookies.
Our marketing website may use privacy-friendly analytics to count visits. At the time of this policy, the website does not use analytics or advertising cookies. If we add analytics, we will use a privacy-friendly service and update this section first.
You can clear cookies and local storage in your browser settings at any time. If you do, you will be signed out of the application.
8. Security
We use technical and organizational measures designed to protect personal information, including:
- Encryption of data in transit using TLS (HTTPS).
- Passwords stored only as salted hashes, never in readable form.
- Uploaded documents kept in private cloud storage, encrypted at rest, and never published at a public address.
- Documents opened only through links that expire after five minutes, issued after we confirm the person is signed in to the company that owns the document.
- Each company’s data available only to that company’s signed-in users.
- Upload links for vendors that are unique and expire.
- Limited internal access to production systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a security incident that affects your personal information, we will notify you and any authorities as required by law.
9. Your privacy rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information.
- Receive your information in a portable format.
- Object to or restrict certain processing.
- Withdraw consent where we rely on consent.
- Not be discriminated against for exercising these rights.
To make a request, email legal@thecertitrack.com. We will verify your identity before acting on the request and respond within 30 days, or sooner if the law requires. You may use an authorized agent where the law allows. If you are in the EEA, UK, or Switzerland, you may also complain to your local data protection authority.
If your request concerns Customer Data (for example, you are a vendor of one of our customers), we will pass it to that customer and help them respond.
10. International data transfers
We and our service providers may process information in the United States and other countries whose data protection laws may differ from those where you live. Where required, we use appropriate safeguards for these transfers, such as the Standard Contractual Clauses approved by the European Commission.
11. Children’s privacy
The Services are for businesses and are not directed to anyone under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, email legal@thecertitrack.com and we will delete it.
12. Links to other websites
The Services may link to other websites and services, such as Stripe’s checkout and billing pages. Their privacy practices are governed by their own policies, not this one.
13. Changes to this policy
We may update this policy from time to time. We will post the new version on this page and update the “Last updated” date. If the changes are material, we will also notify account owners by email or in the application before they take effect.
14. Contact us
Questions or requests about this policy or our data practices:
- Email: legal@thecertitrack.com