Legal

Privacy Policy

Highlighted items are placeholders the CertificateChaser operator must complete before launch. This document is a practical starting point and is not legal advice — have it reviewed by a professional.

This Privacy Policy explains how CertificateChaser ("we", "us") collects and uses personal data. CertificateChaser is operated by Certificate Chaser, [REGISTERED ADDRESS]. Privacy enquiries: JackHartshorn@outlook.com. Last updated June 2026.

1. Two kinds of personal data — and two roles

Business users (our customers). When a business signs up we are the data controller for the account holder's data: name, business name, email, phone, address, website, logo, VAT/company numbers, bank details you choose to show on invoices, login credentials (passwords are stored only as bcrypt hashes), subscription status and activity within the app.

The business's own customers. Businesses enter details about their customers (names, company names, emails, phones, addresses, service due dates, bookings, notes, invoices, payments). For that data the business is the data controller and CertificateChaser acts as a data processor, processing it only on the business's instructions to provide the service (storing records, sending reminders, booking confirmations and invoices the business has configured). Businesses are responsible for having a lawful basis to enter and contact their customers.

2. What we collect and why

  • Account & profile data — to create and secure your account and operate the service (contract).
  • Customer, service, job, booking, invoice and payment records you enter — to provide the service (contract / processor instructions).
  • Email delivery data — recipient, subject, time and success/failure of reminders, booking confirmations and invoice emails, kept as an activity history so you can see what was sent (contract, legitimate interests).
  • Booking data — when your customer books via a booking link we record the chosen slot and any note they add (processor instructions).
  • Files — business logos uploaded by you, stored in cloud object storage (contract).
  • Billing data — your CertificateChaser subscription is handled by Stripe; we store your Stripe customer ID and subscription status, never full card details (contract, legal obligation).
  • Technical data — server logs (IP address, request path, timestamps) for security and troubleshooting (legitimate interests).

3. What we do NOT do

  • We do not process your customers' invoice payments. Customers pay you directly by bank transfer, cash or other means you agree with them; we only record the payment status you enter.
  • We do not use analytics, advertising or tracking cookies (see Cookie Policy).
  • We do not sell personal data or use your customers' data for our own marketing.

4. Who we share data with (processors)

  • Hosting & database — cloud infrastructure provided via the Emergent platform (application servers and MongoDB database).
  • Object storage — Emergent object storage for uploaded logos.
  • Email delivery — Resend (via Emergent's managed email service) to deliver reminders, confirmations, invoices and account emails.
  • Payments for your subscription — Stripe Payments Europe Ltd / Stripe Inc. (card details are entered on Stripe's own pages).

These providers act under contract and may process data outside the UK (for example in the EU or US). Where they do, transfers rely on the UK International Data Transfer Agreement / Addendum or UK adequacy regulations. [CONFIRM HOSTING REGION WITH YOUR PROVIDER BEFORE LAUNCH]

5. Retention

  • Active account data — for as long as your account is open.
  • Invoices, payments and subscription/billing records — 6 years after the end of the relevant tax year (UK accounting/tax law), even after account closure.
  • Customer, job, booking and reminder history — kept while your account is open so you have a complete service history; deleted or anonymised within 30 days of a verified account-deletion request, except records covered above.
  • Server logs — up to 90 days.
  • Archived/lost jobs remain as history; they are not deleted automatically.

6. Security

All traffic is encrypted (HTTPS). Passwords are hashed with bcrypt. Every account is isolated — each request is authorised server-side against the signed-in business, so one business can never read another's customers, jobs, invoices, files or settings. Public booking and invoice pages use long random, unguessable links and show only the information needed for that booking or invoice. Access to production systems is restricted.

7. Your rights (UK GDPR)

You have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. In the app go to Settings → Privacy & data to download a full export of your account data, submit a privacy request, or request account deletion. You can also email JackHartshorn@outlook.com. We respond within one calendar month. If your data was entered by a business using CertificateChaser, please contact that business first — they are the controller; we will assist them.

8. Complaints

If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, helpline 0303 123 1113.

9. Changes

We will post any changes here and update the date above. Material changes will be notified by email to account holders.