CertLeaf IconCertLeaf

Privacy Policy

Privacy Policy

Effective date: 1st July 2026

Last updated: 1st July 2026

1. Who We Are

CertLeaf ("we", "us", "our") is operated from Bangalore, Karnataka, India. We provide a digital certificate issuance and verification platform accessible at certleaf.com.

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), CertLeaf is the Data Fiduciary in respect of personal data collected directly from Issuers (registered account holders). For personal data that Issuers enter about their Recipients (names, email addresses, custom fields), CertLeaf acts as a Data Processor on the Issuer's behalf; the Issuer is the Data Fiduciary for that data.

Contact: [email protected]

2. Definitions

TermMeaning
IssuerA registered user who creates and issues certificates through the platform.
RecipientA person who receives a certificate. No account is required.
Public VerifierAny person who visits a /verify/{slug} URL. No account is required.
Personal DataAny data by which an individual can be identified, as defined under the DPDPA.

3. Data We Collect

3.1 From Issuers (account holders)

DataHow collectedPurpose
Email addressSign-up / Google OAuthAccount authentication, transactional email
Display nameSettings pageShown on verification pages and certificates
Logo imageSettings pageEmbedded on issued certificates
Template assets (base images, signature images)Template builderCertificate generation
Credit transaction historySystem-generatedBilling and balance accounting
Payment details (Razorpay order ID, payment ID, amount)Razorpay checkoutPayment processing and receipting
Inferred country and display currencyCloudflare location headerLocalized pricing
IP address and browser metadataServer logsSecurity, abuse prevention

We do not store raw card numbers, UPI credentials, or banking details. These are handled entirely by Razorpay.

3.2 From Recipients (entered by Issuers)

Issuers supply Recipient data either by typing directly, uploading a CSV, or via a public form they create. This data includes:

  • Recipient name
  • Recipient email address
  • Any custom fields defined on the certificate template (e.g., course name, date, score)

CertLeaf processes this data solely on the Issuer's instruction to generate and deliver certificates. Issuers are responsible for having a lawful basis to share their Recipients' data with our platform.

3.3 From Public Verifiers

No personal data is collected from visitors to /verify/{slug} pages. We may log IP addresses for rate-limiting and security purposes; these logs are not linked to individuals.

4. How We Use Data

Issuers

  • Provide, operate, and improve the platform.
  • Authenticate sessions and maintain account security.
  • Process credit purchases and send payment receipts.
  • Send transactional emails (certificate issuance confirmations, payment receipts).
  • Enforce usage limits and prevent abuse.
  • Comply with applicable law.

Recipients

  • Generate the certificate (PDF and/or PNG) specified by the Issuer.
  • Send a delivery email containing a download link.
  • For verifiable certificates: display the Recipient's name, certificate type, issued date, and expiry on the public /verify/{slug} page.
  • Persistent storage in our database for the life of the certificate, so the verification URL remains functional.

We do not use Recipient data for advertising, profiling, or any purpose beyond certificate generation and delivery.

5. Public Verification Pages

For verifiable certificates, the /verify/{slug} URL is permanently accessible to anyone who holds it, without authentication. The page displays:

  • Issuer name and logo
  • Recipient name
  • Certificate type, issue date, and expiry date (if set)
  • A download link for the certificate PDF

The URL slug is a 12-character random identifier (effectively unguessable) but is not secret — it is embedded in the QR code printed on the certificate. Anyone who holds or scans the certificate can reach the verification page. Issuers are informed of this before issuing a verifiable certificate.

Verifiable certificates cannot be deleted by the Issuer once issued, because doing so would break existing verification URLs held by third parties (employers, institutions, etc.).

6. Third-Party Processors

We share personal data only with the following processors, strictly for the purpose stated:

ProcessorData sharedPurposeLocation
RazorpayPayment amount, order metadataPayment processingIndia
BrevoRecipient email address, Issuer email address, certificate download link, and transactional email contentTransactional email deliveryVaries by provider infrastructure
Google Fonts APINo personal dataFont catalog lookup for template builderUnited States
FrankfurterCurrency pair only; no personal dataReference exchange rates for localized pricingEuropean Union

Cross-border transfers: Data stored in Supabase may be processed and stored outside India. We rely on contractual safeguards with Supabase. The Central Government may in future restrict transfers to certain territories under Rule 15 of the DPDP Rules 2025; we will update this policy if such restrictions affect our operations.

We do not sell personal data to any third party.

7. Data Retention

DataRetention period
Issuer account dataUntil the Issuer deletes their account, plus 1 year for security logs as required under DPDP Rules, Rule 6(e).
Certificate records (simple certificates)Until the Issuer deletes the certificate, or until account deletion.
Verifiable certificate recordsIndefinitely, because the verification URL is permanent. Issuers are informed of this at issuance.
Bulk job records and uploaded CSVsDeleted from storage after the job completes and results are available for download; metadata retained for 1 year.
Payment records7 years, as required for financial record-keeping under Indian law.
Server access logs1 year.

When an Issuer closes their account, we delete or anonymise all account data and all non-verifiable certificate data within 30 days, subject to legal retention obligations.

8. Security

We implement the following safeguards, consistent with DPDP Rules, Rule 6:

  • All data is stored in Supabase with row-level security; each Issuer's data is logically isolated by their user ID.
  • All files in storage are in private buckets; downloads are served via short-lived signed URLs (15-minute TTL by default).
  • Authentication is handled by Supabase Auth (bcrypt password hashing, secure session tokens); Google OAuth is supported.
  • All data in transit is encrypted via TLS.
  • Access to production systems is restricted to authorised personnel.
  • Processing logs are retained for a minimum of 1 year for incident investigation.

In the event of a personal data breach, we will notify affected Data Principals without delay and report to the Data Protection Board of India within 72 hours of becoming aware, as required under DPDP Rules, Rule 7.

9. Children's Data

CertLeaf is not directed at individuals under 18 years of age. Issuers must not use the platform to issue certificates to minors without having obtained verifiable parental or guardian consent as required under Section 9 of the DPDPA and DPDP Rules, Rule 10. We do not knowingly collect personal data from children through the Issuer sign-up flow.

10. Your Rights

Under the DPDPA, Data Principals have the following rights. These rights apply to personal data for which CertLeaf is the Data Fiduciary (i.e., Issuer account data). For Recipient data, the relevant Data Fiduciary is the Issuer who collected and entered that data.

RightWhat it means
Right to accessRequest a summary of the personal data we hold about you and the purposes for which it is processed.
Right to correction and updatingRequest correction of inaccurate or incomplete personal data.
Right to erasureRequest deletion of your personal data where the purpose for which it was collected is no longer being served.
Right to withdraw consentWhere processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
Right to nominateNominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
Right to grievance redressalLodge a complaint with us, and subsequently with the Data Protection Board of India if unsatisfied.

To exercise any of these rights, email us at [email protected]. We will respond within 90 days as required under the DPDPA.

11. Grievance Officer

For any questions, complaints, or requests relating to this policy or your personal data:

Email: [email protected]

Location: Bangalore, Karnataka, India

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India through its designated portal.

12. Changes to This Policy

We will post updates to this policy on this page and update the "Last updated" date. For material changes, we will notify Issuers via email at least 7 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the revised policy.

13. Governing Law

This policy is governed by the laws of India, including the Information Technology Act, 2000, the DPDPA 2023, and the DPDP Rules 2025. Any disputes are subject to the jurisdiction of courts in Bangalore, Karnataka.

Back to home