Legal

Privacy Policy

Last updated: May 20, 2026

CertProof is operated by Nxtwise IT Private Limited. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the CertProof platform at certproof.in.

1. Information We Collect

Account Information

When you register an organization on CertProof, we collect your name, email address, organization name, and password. Organization administrators may also provide a website URL, phone number, and address.

Certificate Data

Organizations provide student or recipient names, email addresses, certificate titles, and other custom fields when issuing certificates. This data is stored to generate verifiable digital certificates.

Usage Data

We automatically collect information about how you interact with the platform — including pages visited, features used, timestamps of actions, and device/browser information. This helps us improve the product.

Payment Information

When you upgrade to a paid plan, payment is processed by Razorpay (operated by Razorpay Software Private Limited). CertProof does not store your card or bank details. We only receive a payment confirmation and transaction ID.

Email Delivery

If you use the certificate email feature, recipient email addresses are shared with Resend (our email delivery provider) solely for the purpose of delivering the certificate email. We do not use recipient emails for any other purpose.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your organization account
  • Issue, store, and display digital certificates
  • Enable public certificate verification
  • Send transactional emails (certificate delivery, account notifications)
  • Process subscription payments and billing
  • Provide customer support
  • Improve platform features and fix bugs
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising.

3. Data Storage and Security

CertProof uses Google Firebase (Firestore and Firebase Storage) to store all platform data. Data is stored on Google Cloud infrastructure with encryption at rest and in transit.

We use Firebase Security Rules to ensure that organization data can only be accessed by authorized users. Certificate verification pages are intentionally public — this is the core purpose of the platform.

While we take reasonable measures to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

4. Sharing of Information

We share your information only in these circumstances:

Service Providers

We share data with Google Firebase (storage), Resend (email delivery), and Razorpay (payment processing) — solely to operate the platform. These providers have their own privacy policies.

Public Certificate Verification

Certificate data (student name, certificate title, issue date, status) is publicly accessible via the verification URL. This is by design — organizations issue certificates knowing they will be publicly verifiable.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process (court orders, government requests).

5. Cookies and Tracking

CertProof uses session cookies and browser local storage to keep you logged in and maintain your preferences. We use Firebase Analytics to understand aggregate usage patterns. We do not use third-party advertising cookies.

6. Data Retention

We retain your account and certificate data for as long as your organization account is active. If you delete your account, we will delete your organization data within 30 days, except where we are required to retain it for legal or compliance purposes.

Certificate records may be retained for a longer period if they have been publicly shared and verified, to maintain the integrity of the verification record.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data via your Settings page
  • Delete your account and associated data by contacting us
  • Withdraw consent for email communications by contacting us

To exercise any of these rights, contact us at support@certproof.in.

8. Children's Privacy

CertProof is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered organizations of significant changes by email or via a notice in the dashboard. The "Last updated" date at the top of this page reflects the most recent revision.

10. Contact Us

If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us:

Nxtwise IT Private Limited

Email: support@certproof.in

Website: certproof.in