Certifiable is operated by Certifiable, LLC, South Charleston, West Virginia. This policy is written for U.S. privacy law. Questions: hello@becertifiable.io.
Cookies are listed in the Cookie Notice. Organization customers also have the Data Processing Addendum.
What Certifiable is
Organizations upload a branded PDF, import a roster, and issue training, CE, or completion certificates. People retrieve a copy later with lookup. We are not a public search of other people’s credentials.
For organization account data (who signed up, billing), we decide how that is used — we are the “business” or “controller.” For names and emails on a roster, we process that on the issuing organization’s instructions — we are their “service provider” or “processor.” The organization is responsible for having a reason to collect and email those people.
What we collect
Organization accounts
When someone starts a subscription we store the owner’s name, email, password (stored hashed), job title, and company details they enter (name, legal name, address, phone, website, industry). Card payments are handled by our payment processor. We store subscription status and billing identifiers — not the card number.
Rosters and certificates
For each attendee the organization uploads, we store first name, last name, email, event, hours, and a unique identifier printed on the certificate. Copies are generated when someone with a valid code or link asks for them.
Lookup and sharing
Lookup: the attendee enters the email on the roster. We email a short-lived code to that address. The page does not say whether that email is in the system. After a correct code, they can view matching certificates for a limited time.
Share: a private link and a one-time code can be sent to another address. Both are required. The share expires and works once.
Email we send
Access codes, certificate links (not the PDF as an attachment), share codes, sign-in verification, and account mail such as welcome messages. Delivery status for certificate emails is stored so the organization can see whether a message was sent.
Sign-in and public forms
Organization sign-in uses a session cookie and extra verification. Public forms may include bot checks. Attendee lookup does not require an account.
Chat
The site may include a support chat. If you write there or to hello@, that conversation is support mail, not a certificate record.
Site analytics
Public pages load a traffic analytics script so we can see which pages are visited. That service sets cookies and receives your IP address, browser, and page URL. It is not used to look up certificates. Details are in the Cookie Notice.
How we use it
- to run the product: accounts, templates, rosters, certificates, lookup, and sharing
- to bill the subscription and send account mail
- to fix problems and keep the service secure
- to understand how public pages are used
- to comply with law or a valid legal request
Who sees it
- The issuing organization sees its own events, roster, and certificates.
- An attendee sees certificates for the email they verified with a code.
- A share recipient sees only the certificates on that share, after the one-time code.
- Certifiable staff may access an organization account to fix a real support problem. That is logged. We do not change that org’s password or 2FA while helping.
Processors
We use third parties to help run the product. They only get what they need for that job:
- Stripe — card payments and subscriptions
- Mailgun — sending certificate, lookup, share, and account email
- Google Analytics — traffic measurement on public pages
- Tawk.to — optional support chat
- Cloudflare Turnstile — bot checks on public forms
We do not sell personal information. We do not share it for cross-context behavioral advertising.
What we do not keep
We do not keep a public index of attendees. We do not store card numbers. Demo pages under /demo are fiction (Town of Amity) and are not live attendee records. Do not upload Social Security numbers, medical records, or other sensitive data we do not need to print a name on a certificate.
How long, and deletion
Organization and attendee records stay for as long as the account uses Certifiable to issue and look up certificates. The organization can delete certificates and related attendee rows from its admin. Attendees who want a record removed should ask the issuing organization, or email hello@becertifiable.io and we will work with that issuer. Closing an organization account is handled by us on request. We may keep limited billing and log records as the law requires.
Security
Passwords are stored hashed. Organization sign-in can use extra verification. Lookup and share use short-lived codes, not a public name search. Staff access to an organization for support is logged. See certificate security for how lookup and sharing work. No method of transmission or storage is perfectly secure.
Children
The marketing site and organization accounts are not directed at children under 13. An organization may issue certificates to minors (a school or youth program). That organization is responsible for having a basis to collect those names and emails. We process that roster as their processor. We do not knowingly collect personal information from children under 13 for our own marketing. If you think we have, write us and we will delete it.
U.S. state privacy rights
Depending on where you live (including California and other states with comprehensive privacy laws), you may have the right to know what personal information we have, to correct it, to delete it, to obtain a copy, and to opt out of sale or sharing. We do not sell or share personal information as those laws define those terms. We will not discriminate against you for exercising those rights.
To make a request, email hello@becertifiable.io. We will need enough information to verify you. If you are on a roster, start with the issuing organization — they control that record. You may use an authorized agent where the law allows.
Contact
Certifiable, LLC
South Charleston, West Virginia
hello@becertifiable.io