Privacy policy
What personal information Certale collects, why we need it, and the choices you have, whether you design and issue certificates, receive one, or scan a QR code to check that one is real.
- Last updated
- 10 October 2026
- Applies to
- certale.com, the Certale app and story pages
- Privacy contact
- privacy@certale.com
The short version
A plain-language summary. The full policy below is what counts.
- We collect what we need to run Certale: your account details, the certificates you design, and the recipient names and emails you upload.
- Recipient lists belong to the issuer. We process them on the issuer’s instructions, never sell them and never use them for our own marketing.
- Every certificate has a story page. Recipients decide whether it is Private, Shareable by link, or Public on the Wall of Tales.
- Children’s certificates are never public, never on the Wall of Tales and never in search results.
- We use trusted providers: Amazon Web Services for hosting and email, Stripe for payments, and Google Analytics only if you accept analytics cookies.
- You stay in control. Change most things yourself in Settings, or ask us at privacy@certale.com.
1. Who we are
Certale (“Certale”, “we”, “us”) is a product of PPT-Design Ltd (on the register as PPT-DESIGN LTD), a company registered in England and Wales under company number 16115606, with its registered office at 2nd Floor College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom.
For anything in this policy, including requests to use your data protection rights, email privacy@certale.com. For help with Certale, email help@certale.com.
Our role: controller and processor
PPT-Design Ltd is the controller of information about Certale account holders and their team members, website visitors, newsletter subscribers, and recipients who claim a certificate or set up a Certale profile.
When an organisation (an “issuer”) uploads or types in a list of recipients to create certificates, the issuer is the controller of that recipient data and PPT-Design Ltd acts as its processor, following its instructions. Issuers can ask for our Data Processing Agreement at help@certale.com. If you received a certificate and want to know why you have it, please contact the issuer first. We will help too.
When an issuer closes its Certale account, PPT-Design Ltd becomes the controller of the record we keep of each certificate it issued, so that the certificate can still be verified. See Closing your account.
2. What we collect
We collect only what we need to run Certale. The table shows each kind of information and where it comes from.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, email address, password (stored only as a one-way hash), language, notification settings and whether you chose to receive product news. If you set up a public profile: its address, a short bio and a profile picture. | You, when you sign up and in Settings |
| Google or Microsoft sign-in | Your name, email address and whether the provider has verified it, the provider’s identifier for your account and, from Google, a link to your profile picture. We never see your Google or Microsoft password. | Google or Microsoft, if you choose to use them |
| Issuer data | Organisation name, logo, brand colours and fonts, sender name, verified web domain, certificate designs and wording, and the names, emails and roles of your team members. | You and your team |
| Recipient data | Names, email addresses, award titles, dates and any other details the issuer puts on the certificate, and whether it was issued to an under-18. If the recipient claims the certificate: their account, their one-line message and their visibility choice. | The issuer; then the recipient |
| Payment data | Billing name and address, tax ID if you give one, plan, subscription status and invoices. Card details go straight to Stripe: we never see or store full card numbers. | You, through Stripe |
| Device and security data | The IP address and browser of each signed-in session, and short-lived counters by IP address that protect sign-in and other forms from abuse. | Your device, automatically |
| Certificate activity | When a story page is opened, scanned from its QR code, shared (and to which service), downloaded or applauded, and whether a certificate email was delivered, bounced or reported as spam. Visits are counted against the certificate: we don’t record who the visitor was. | Story pages and our email service |
| Analytics | Pages viewed, how you arrived, approximate location and type of device, measured by Google Analytics. Only if you accept analytics cookies. | Your browser, with your consent |
| Email choices | Your newsletter sign-up and its confirmation, the topics you chose, whether you unsubscribed, and a record of which emails we sent you. | You, and our email systems |
| Support messages | What you tell us when you email us, and our replies. | You |
When you upload a spreadsheet, it is read in your browser. We don’t keep the file: we store its name and the rows you issue, which become the certificates.
We don’t need sensitive information, such as health details, religion or government ID numbers, and we ask issuers not to put it in certificate fields or spreadsheets.
3. How we use your information
- To provide Certale: create your account, save your designs, generate certificates, deliver them by email on the issuer’s behalf, and host their story pages.
- To verify certificates: show anyone who scans a QR code or opens a story page who issued the certificate, when, and whether it is still valid.
- To show issuers how their certificates are doing: opens, scans, shares, downloads, applause and email delivery, in the app and in notifications.
- To take payments and keep the tax and accounting records the law requires.
- To keep Certale safe: detect abuse, fraud and spam, limit repeated attempts, and protect accounts.
- To support you and send service emails, such as sign-in codes, receipts, security notices, changes to your plan and, for issuers, getting-started tips you can turn off.
- To improve the product, using totals from our own records and, if you accept analytics cookies, Google Analytics.
- To send product news and the Certale Journal, only if you opt in. Every one has an unsubscribe link.
We do not sell personal information or share it for advertising. We never use recipient data uploaded by issuers for our own marketing: receiving a certificate never puts you on a mailing list. We do not use your content, including certificate text and recipient lists, to train machine-learning models.
4. Legal bases (UK GDPR and GDPR)
Where data protection law in the UK or the European Economic Area applies, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Providing Certale to account holders, including billing and service emails | Contract (Article 6(1)(b)) |
| Processing recipient data uploaded by an issuer | We act on the issuer’s instructions; the issuer decides its own legal basis |
| Showing a certificate’s details to people who open its story page or scan its QR code | Legitimate interests in letting people confirm a certificate is genuine (Article 6(1)(f)) |
| Making a story page Public, and the recipient’s own line | Consent of the recipient (Article 6(1)(a)), withdrawn at any time by changing visibility or removing the line |
| Certificate activity for issuers, security, fraud prevention and product improvement | Legitimate interests (Article 6(1)(f)) |
| Getting-started tips for issuers | Legitimate interests (Article 6(1)(f)); you can turn them off at any time |
| Keeping a certificate verifiable after its issuer closes its Certale account | Legitimate interests of the recipient and of people checking the certificate (Article 6(1)(f)) |
| Tax, accounting and responding to lawful requests | Legal obligation (Article 6(1)(c)) |
| Newsletter, product news and analytics cookies | Consent (Article 6(1)(a)), withdrawn at any time |
5. Story pages and visibility
Every certificate has its own web address, reached by its QR code or link, that opens its story page. A story page shows the certificate, the recipient’s name, the issuer, the date and whether the certificate is valid, and, when the recipient adds them, a one-line message and applause from visitors.
There are three visibility levels:
Recipients are in control. Once they claim a certificate, recipients can change who sees its page and edit or remove their line at any time, and can ask the issuer or us to take the page down. Only the recipient can make a page Public: an issuer can suggest it, but the page stays Shareable until the recipient agrees.
Issuers choose the starting visibility (Private or Shareable). On the Business plan they can also revoke a certificate or give it an expiry date. A revoked or expired certificate’s page says clearly that it is no longer valid, and applause, sharing and downloads stop.
Applause is anonymous. If you applaud without signing in, a cookie holds a random ID so you can only applaud once; we store a one-way hash of that ID, never your name.
Children’s certificates are never public. When an issuer marks a certificate as issued to an under-18, its page can only be Private or Shareable, never appears on the Wall of Tales, and is always hidden from search engines. See Children.
We may hide a story from the Wall of Tales, or revoke a certificate, if it breaks our Terms of service.
6. Emails we send
- Service emails, such as sign-in codes, receipts, security notices, team invitations and updates about your batches, go to account holders whenever they are needed.
- Certificate emails are sent on the issuer’s behalf, with the issuer’s name, to the recipients the issuer chose. Receiving one does not subscribe you to anything.
- Getting-started tips go to people who issue certificates, until they turn them off.
- The Certale Journal and product news go only to people who asked for them: by ticking the box (unticked to start with) when signing up, by turning them on in Settings, or by confirming a newsletter sign-up through the link we email.
Every newsletter and marketing email has a one-click unsubscribe link and a link to your email preferences, where you can choose topics or stop them all.
If an email to an address bounces permanently or is reported as spam, we add the address to a suppression list and stop sending certificate and marketing emails to it. Sign-in codes and receipts you ask for still go out. We don’t put tracking pixels in our emails.
9. International transfers
Certale is hosted by Amazon Web Services in its us-east-2 region (Ohio, United States), so your information is stored and processed in the United States. Content delivery uses AWS edge locations around the world, and Stripe, Google and Microsoft may process data in the United States and other countries.
When personal information goes from the UK or the European Economic Area to a country without an adequacy decision, we rely on recognised safeguards: for these providers, the UK Extension to the EU–US Data Privacy Framework where the provider is certified, or the International Data Transfer Addendum to the EU Standard Contractual Clauses (with the Clauses themselves for data from the European Economic Area). You can ask us about the safeguards that apply at privacy@certale.com.
10. How long we keep it
We keep personal information only as long as we need it for the purposes above.
| Information | How long we keep it |
|---|---|
| Account details | For as long as your account exists, then 30 more days after you delete it (so you can change your mind) before we erase them. See “Closing your account” below. |
| Sign-in sessions (IP address and browser) | Until you sign out, or until the session expires after 30 days without use. Expired sessions are deleted every day. |
| Sign-in codes and abuse counters | One-time codes, stored only as hashes, are deleted a day after they are used or expire. Counters by IP address are deleted within two days. |
| Certificates and story pages | For as long as the issuer’s organisation has its account, so that certificates can keep being verified, unless the issuer asks us to remove them or we remove one at the recipient’s request. If the issuer closes its account, we keep a record of each certificate it issued, without the recipient’s email address or its activity, so it can still be verified (see “Closing your account”). A revoked certificate stays on record, marked “Not valid”, so it can’t be passed off as genuine. |
| Uploaded spreadsheets | The file itself is not kept. Its name and the rows you issue stay with the batch and its certificates. |
| Batch downloads (ZIP files and link sheets) | With the batch, for as long as the organisation has its account. |
| Rendered certificate images | Deleted 30 days after they were made; they are made again when needed. |
| Certificate activity and applause | For as long as the certificate exists. You can take back your applause at any time. |
| Payment and invoice records | For as long as UK tax law requires us to keep accounting records (normally six years), including after you close your account: Stripe keeps the invoices, and we keep only the Stripe reference and plan against a record of the closed organisation. Stripe keeps its own records under its policy. |
| Email choices, newsletter sign-ups and the suppression list | For as long as we need them to respect your choices, so that we never email you after you unsubscribe or send again to an address that bounced. When you delete your account, your address stays on this list, marked “no marketing”, so we never send you marketing again. |
| Audit log | Important changes, such as plan changes, revoked certificates and actions by Certale staff, with the time, who made them and, where available, the IP address. Kept as a security record, without a fixed deletion date. When an account is erased, its entries lose the person’s ID, IP addresses and email addresses. |
| Server logs | 30 days. |
| Support emails | For as long as we need them to deal with your request and any follow-up. |
Database backups are kept for 7 days, and earlier versions of stored files for 30 days, so information we delete leaves our backups within that time.
Closing your account
You can delete your account yourself in Settings → Profile → Delete account. To make sure it’s you, we email a 6-digit code to the address on the account (whether you sign in with a password, Google or Microsoft) and ask you to type DELETE. Then:
- Straight away, you are signed out everywhere and nobody can sign in to the account. Your Public certificates become Shareable, and we stop all newsletters and product news.
- Organisations: if you are the only member of an organisation, it closes with your account: it can’t issue or send anything more, and its paid plan is cancelled immediately (payments already made aren’t refunded automatically). If others are members, you leave it and they keep it. If you are its only owner, make someone else an owner, or remove the other members, first.
- After 30 days, we erase your personal data: your profile, sign-in methods, settings, sessions, codes and email history, and the data of any organisation that closed with your account (designs, batches and their downloads, logos, team invitations and certificate activity). Until then you can change your mind by emailing help@certale.com.
- We keep only what the law or other people need: invoices for tax records (see the table above), your email address on our “no marketing” list, audit log entries without your ID, IP address or email address, and a record of each certificate a closed organisation issued (below).
- Certificates you received stay with the organisations that issued them (they control that data), but are no longer linked to you: your public profile goes, and your lines on them are removed. Applause you gave stays anonymous.
Certificates issued by a closed organisation
Recipients rely on their certificates long after they receive them, and an issuer leaving Certale doesn’t make an award untrue. So when an organisation closes, we don’t delete or revoke the certificates it issued. We keep only what verification needs (the certificate as issued, with the recipient’s name, the issuer’s name and the date) and delete the recipient’s email address and the certificate’s activity, the issuer’s logo, description and verified domain. The story page then says the certificate was issued by that organisation on that date, that the organisation has since closed its Certale account, and that nobody can revoke or update the certificate any more. These pages are never on the Wall of Tales and never in search results.
We keep these records on the basis of legitimate interests, the recipients’ and those of people checking their certificates, for as long as Certale runs. A recipient, or a parent or guardian for an under-18, can ask us at privacy@certale.com to remove one, and we will.
11. Your rights
Depending on where you live, you have the right to:
- Access the information we hold about you.
- Correct anything that is wrong or incomplete.
- Delete your information, unless we must keep it.
- Restrict how we use it while a concern is resolved.
- Export your data in a common, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, for example by changing visibility.
- Complain to a data protection authority.
You can change much of this yourself: your name, email address, sign-in methods and notifications in Settings, your email topics on the email preferences page, each claimed certificate’s visibility and line on its story page, and deleting your account in Settings. For anything else, email privacy@certale.com. We reply within one month and may need to confirm your identity first. If your request is about recipient data that an issuer uploaded, we will pass it to the issuer and help them respond.
You can also complain to a data protection authority, such as the UK Information Commissioner’s Office (ico.org.uk), or the data protection authority in your EU country. We would appreciate the chance to put things right first.
12. Security
We encrypt data in transit (HTTPS, including between our servers and the database) and at rest (the database and file storage). The database runs in a private network and can’t be reached from the internet. Passwords are hashed with Argon2, and session tokens and one-time codes are stored only as hashes. A web application firewall and rate limits protect sign-in and other forms.
Our staff back office is open only to a short, named list of Certale staff. Every change made there needs a reason and is recorded in the audit log.
No system is perfectly secure. If a breach affects your information, we will tell you and the relevant authorities as the law requires.
13. Children
Certale accounts are for adults and organisations. You must be 18 or over to open an account, or be acting with the authority of the organisation you represent. People under 18 can receive certificates without an account.
Schools, clubs and other organisations may issue certificates to children. They are responsible for having the right to do so and for giving parents or guardians any notices required. When an issuer marks certificates as issued to under-18s:
- the story page can be Private or Shareable, never Public, and never appears on the Wall of Tales or on a public profile;
- the page is always hidden from search engines, and link previews show no picture or description;
- we never load Google Analytics on it;
- a parent or guardian can ask the issuer, or us at privacy@certale.com, to remove the page.
14. Changes to this policy
We will update this page when our practices change and change the “Last updated” date at the top. If a change is significant, we will tell account holders by email or in the app before it takes effect.
15. Contact us
Questions, requests or concerns about privacy? Get in touch.