Privacy Policy
Privacy Policy
Effective date: 1st July 2026
Last updated: 1st July 2026
1. Who We Are
CertLeaf ("we", "us", "our") is operated from Bangalore, Karnataka, India. We provide a digital certificate issuance and verification platform accessible at certleaf.com.
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), CertLeaf is the Data Fiduciary in respect of personal data collected directly from Issuers (registered account holders). For personal data that Issuers enter about their Recipients (names, email addresses, custom fields), CertLeaf acts as a Data Processor on the Issuer's behalf; the Issuer is the Data Fiduciary for that data.
Contact: [email protected]
2. Definitions
| Term | Meaning |
|---|---|
| Issuer | A registered user who creates and issues certificates through the platform. |
| Recipient | A person who receives a certificate. No account is required. |
| Public Verifier | Any person who visits a /verify/{slug} URL. No account is required. |
| Personal Data | Any data by which an individual can be identified, as defined under the DPDPA. |
3. Data We Collect
3.1 From Issuers (account holders)
| Data | How collected | Purpose |
|---|---|---|
| Email address | Sign-up / Google OAuth | Account authentication, transactional email |
| Display name | Settings page | Shown on verification pages and certificates |
| Logo image | Settings page | Embedded on issued certificates |
| Template assets (base images, signature images) | Template builder | Certificate generation |
| Credit transaction history | System-generated | Billing and balance accounting |
| Payment details (Razorpay order ID, payment ID, amount) | Razorpay checkout | Payment processing and receipting |
| Inferred country and display currency | Cloudflare location header | Localized pricing |
| IP address and browser metadata | Server logs | Security, abuse prevention |
We do not store raw card numbers, UPI credentials, or banking details. These are handled entirely by Razorpay.
3.2 From Recipients (entered by Issuers)
Issuers supply Recipient data either by typing directly, uploading a CSV, or via a public form they create. This data includes:
- Recipient name
- Recipient email address
- Any custom fields defined on the certificate template (e.g., course name, date, score)
CertLeaf processes this data solely on the Issuer's instruction to generate and deliver certificates. Issuers are responsible for having a lawful basis to share their Recipients' data with our platform.
3.3 From Public Verifiers
No personal data is collected from visitors to /verify/{slug} pages. We may log IP addresses for rate-limiting and security purposes; these logs are not linked to individuals.
4. How We Use Data
Issuers
- Provide, operate, and improve the platform.
- Authenticate sessions and maintain account security.
- Process credit purchases and send payment receipts.
- Send transactional emails (certificate issuance confirmations, payment receipts).
- Enforce usage limits and prevent abuse.
- Comply with applicable law.
Recipients
- Generate the certificate (PDF and/or PNG) specified by the Issuer.
- Send a delivery email containing a download link.
- For verifiable certificates: display the Recipient's name, certificate type, issued date, and expiry on the public
/verify/{slug}page. - Persistent storage in our database for the life of the certificate, so the verification URL remains functional.
We do not use Recipient data for advertising, profiling, or any purpose beyond certificate generation and delivery.
5. Public Verification Pages
For verifiable certificates, the /verify/{slug} URL is permanently accessible to anyone who holds it, without authentication. The page displays:
- Issuer name and logo
- Recipient name
- Certificate type, issue date, and expiry date (if set)
- A download link for the certificate PDF
The URL slug is a 12-character random identifier (effectively unguessable) but is not secret — it is embedded in the QR code printed on the certificate. Anyone who holds or scans the certificate can reach the verification page. Issuers are informed of this before issuing a verifiable certificate.
Verifiable certificates cannot be deleted by the Issuer once issued, because doing so would break existing verification URLs held by third parties (employers, institutions, etc.).
6. Third-Party Processors
We share personal data only with the following processors, strictly for the purpose stated:
| Processor | Data shared | Purpose | Location |
|---|---|---|---|
| Razorpay | Payment amount, order metadata | Payment processing | India |
| Brevo | Recipient email address, Issuer email address, certificate download link, and transactional email content | Transactional email delivery | Varies by provider infrastructure |
| Google Fonts API | No personal data | Font catalog lookup for template builder | United States |
| Frankfurter | Currency pair only; no personal data | Reference exchange rates for localized pricing | European Union |
Cross-border transfers: Data stored in Supabase may be processed and stored outside India. We rely on contractual safeguards with Supabase. The Central Government may in future restrict transfers to certain territories under Rule 15 of the DPDP Rules 2025; we will update this policy if such restrictions affect our operations.
We do not sell personal data to any third party.
7. Data Retention
| Data | Retention period |
|---|---|
| Issuer account data | Until the Issuer deletes their account, plus 1 year for security logs as required under DPDP Rules, Rule 6(e). |
| Certificate records (simple certificates) | Until the Issuer deletes the certificate, or until account deletion. |
| Verifiable certificate records | Indefinitely, because the verification URL is permanent. Issuers are informed of this at issuance. |
| Bulk job records and uploaded CSVs | Deleted from storage after the job completes and results are available for download; metadata retained for 1 year. |
| Payment records | 7 years, as required for financial record-keeping under Indian law. |
| Server access logs | 1 year. |
When an Issuer closes their account, we delete or anonymise all account data and all non-verifiable certificate data within 30 days, subject to legal retention obligations.
8. Security
We implement the following safeguards, consistent with DPDP Rules, Rule 6:
- All data is stored in Supabase with row-level security; each Issuer's data is logically isolated by their user ID.
- All files in storage are in private buckets; downloads are served via short-lived signed URLs (15-minute TTL by default).
- Authentication is handled by Supabase Auth (bcrypt password hashing, secure session tokens); Google OAuth is supported.
- All data in transit is encrypted via TLS.
- Access to production systems is restricted to authorised personnel.
- Processing logs are retained for a minimum of 1 year for incident investigation.
In the event of a personal data breach, we will notify affected Data Principals without delay and report to the Data Protection Board of India within 72 hours of becoming aware, as required under DPDP Rules, Rule 7.
9. Children's Data
CertLeaf is not directed at individuals under 18 years of age. Issuers must not use the platform to issue certificates to minors without having obtained verifiable parental or guardian consent as required under Section 9 of the DPDPA and DPDP Rules, Rule 10. We do not knowingly collect personal data from children through the Issuer sign-up flow.
10. Your Rights
Under the DPDPA, Data Principals have the following rights. These rights apply to personal data for which CertLeaf is the Data Fiduciary (i.e., Issuer account data). For Recipient data, the relevant Data Fiduciary is the Issuer who collected and entered that data.
| Right | What it means |
|---|---|
| Right to access | Request a summary of the personal data we hold about you and the purposes for which it is processed. |
| Right to correction and updating | Request correction of inaccurate or incomplete personal data. |
| Right to erasure | Request deletion of your personal data where the purpose for which it was collected is no longer being served. |
| Right to withdraw consent | Where processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal. |
| Right to nominate | Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. |
| Right to grievance redressal | Lodge a complaint with us, and subsequently with the Data Protection Board of India if unsatisfied. |
To exercise any of these rights, email us at [email protected]. We will respond within 90 days as required under the DPDPA.
11. Grievance Officer
For any questions, complaints, or requests relating to this policy or your personal data:
Email: [email protected]
Location: Bangalore, Karnataka, India
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India through its designated portal.
12. Changes to This Policy
We will post updates to this policy on this page and update the "Last updated" date. For material changes, we will notify Issuers via email at least 7 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the revised policy.
13. Governing Law
This policy is governed by the laws of India, including the Information Technology Act, 2000, the DPDPA 2023, and the DPDP Rules 2025. Any disputes are subject to the jurisdiction of courts in Bangalore, Karnataka.