CertReports processes as little personal data as an evidence index can. This notice explains what we collect, why, and where it lives.
What we collect
- Account data: your email address and workspace membership, when you sign in. Sign-in is by email magic link or Google.
- Billing data: handled by Stripe. We store the Stripe customer and subscription identifiers, never card details.
- Submissions: the content of claims, disputes and evidence uploads, and the email address used to submit them.
- Analytics: Plausible, which is cookieless and aggregates page views without identifying you. No consent banner is needed because no tracking cookies are set.
- Server logs: IP address and user agent for security and rate limiting, retained for 30 days.
Vendor data
Vendor pages contain company information, not personal data, except where a registry or a vendor page publishes a named contact (for example a FedRAMP point of contact or an auditor). We show those only where the source already publishes them and remove them on request.
Where data is hosted
Servers run in the EU on Hetzner (Germany and Finland) behind Cloudflare at the edge. Email is sent through Resend. Payments are processed by Stripe. See the subprocessors page for the full list.
Your rights
You can access, correct, export or delete your account data by emailing [email protected]. We answer within 30 days. UK and EU residents can complain to the ICO or their supervisory authority.
Retention
Accounts are kept until deleted. Submissions are kept as part of the audit trail for the evidence they changed. Logs are kept for 30 days.