Last updated: 1 September 2026
1. What we collect
From you, as an account holder: your name, email address, and the organisation details you choose to enter. Billing details are handled by our payment provider — card numbers never reach our servers.
From you, about recipients: whatever you upload to issue credentials — typically a name, an email address, and the achievement being certified.
Automatically: how the service is used — pages viewed, features used, approximate location derived from IP, browser and device type. Our visitor statistics are self-hosted and store no raw IP address.
When you sign in with Google or Microsoft: only your name, email address and profile picture. See section 8.
2. What we use it for
- Running the service: creating, rendering, signing, delivering and verifying credentials; taking payment; sending the emails you ask us to send.
- Keeping it working: diagnosing faults, measuring performance, planning capacity.
- Keeping it safe: detecting fraud, abuse and unauthorised access. Credential fraud is the specific risk this platform exists to reduce, so we look for it.
- Talking to you: account notices, invoices, security alerts and replies to your support requests.
We do not sell personal data, and we do not use recipient data for our own marketing — ever.
3. Recipient data, and who is responsible for it
When you upload a list of recipients, you are the data controller and CertTrigger is the data processor. You decide who receives a credential and what it says; we process that data only to carry out your instructions.
That means you are responsible for having a lawful basis to give us those details, and for telling recipients what you are doing. We are responsible for handling the data securely, only for the purposes you set, and for deleting it when you tell us to — subject to the credential limit in section 6.
6. How long we keep it, and the one thing deletion cannot undo
We keep account and recipient data for as long as the account exists, and delete it within 30 days of closure — except where we must keep records to meet a legal or accounting obligation, which we keep no longer than that obligation requires.
The exception that matters: credentials you have already issued remain verifiable after you delete your account or your data. This is deliberate. A credential is a promise made to the person holding it, and someone may need to check it years later; withdrawing it because the issuer closed an account would break that promise on the recipient's behalf. A verification page carries the recipient's name and the achievement, and never their email address.
If a credential must stop being relied upon, the mechanism is revocation, not deletion: the credential continues to resolve and publicly reads as revoked. If you believe a credential should not exist at all — because it was issued in error, or because a recipient has a legal right to erasure that overrides it — contact us at privacy@certtrigger.com and we will assess it individually.
7. How we protect it
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form, and second-factor authentication is available and recommended for any account that can issue. Signing keys are encrypted at rest and never leave the server. Access is scoped by workspace and by role, so one organisation cannot read another's data. We keep an audit trail of security-relevant events, back up the database on a schedule, and hold copies off-site.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your data we will tell you and the relevant authority as required by law, with what we know and what we are doing about it.
8. Your rights
Depending on where you are, you may have the right to access your personal data, correct it, delete it, object to or restrict how we use it, receive a copy in a portable form, or complain to a data protection authority.
To exercise any of these, email privacy@certtrigger.com. We will respond within 30 days. We may need to confirm your identity first, which protects you rather than us.
If you are a recipient of a credential rather than an account holder, the organisation that issued it is the controller of your data. Contact them first; if you cannot reach them, contact us and we will help.
9. Where data is held
The platform runs on dedicated servers in Germany, within the European Union, on infrastructure whose provider holds ISO/IEC 27001:2022 certification for its information-security management. That certificate is the provider's and covers their operations, not ours. Some service providers we use — payment processing and email delivery among them — may process data elsewhere. Where data moves across borders we rely on the safeguards the law requires, including standard contractual clauses with those providers.
10. Signing in with Google or Microsoft
Sign-in with Google or Microsoft is optional. We receive only the basic profile information needed to create and secure your account — your name, email address, and profile picture — and request the minimum permissions to do that. We never request access to your emails, files or contacts, and signing in never requests permission to send email on your behalf.
The Google gmail.send and Microsoft Mail.Send permissions are requested only if you separately connect a sending mailbox, so that certificates are sent from your own address. They are used solely to send the messages you ask us to send, and you can disconnect the mailbox at any time. CertTrigger's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
11. Google API Services User Data Policy
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
What we ask Google for. If you connect a Google sending mailbox, CertTrigger requests one Gmail permission: https://www.googleapis.com/auth/gmail.send. That scope is send-only. It does not permit reading, listing, searching, modifying or deleting messages, drafts, threads, labels or settings, and CertTrigger does not attempt any of those. We receive no messages, no contacts and no mailbox content from Google — only the confirmation that a message we composed was sent. Signing in with Google requests no Gmail permission at all.
Google user data and AI. Google user data is never used to develop, improve or train artificial-intelligence or machine-learning models, whether ours or anyone else's, and is never transferred to any third-party AI service. No token, address, message or any data derived from a Google API is sent to an AI provider under any circumstance.
CertTrigger does include an AI design assistant, and we would rather describe it plainly than leave it to be inferred. It turns a description you type into a certificate design, and can draft the covering email. It runs on one third-party model-hosting provider, DeepInfra, which executes two open-weight models on its own infrastructure — DeepSeek-V4-Flash and MiniMax-M2.7-Turbo. No request is sent to the models' authors, and DeepInfra's privacy policy states that data submitted to its inference service is not stored, sold or used for training without the customer's explicit consent, which we do not give. The assistant receives only what you type into CertTrigger: your design instructions and the names of the placeholder fields your template uses, such as "Name" or "Course". It never receives placeholder values, recipient lists, email addresses, credentials or anything obtained from a Google API. The code that talks to this provider has no access to mailbox tokens or contact records.
Tokens. The OAuth tokens for a connected mailbox are encrypted at rest. They are used for one purpose: sending the certificate emails you initiate. They are never shared with third parties, never used to read anything, and are deleted when you disconnect Google from account settings or delete your account. Disconnecting also revokes the token with Google, so access ends at Google's end as well as ours.
12. Changes to this policy
We may update this policy. For changes that materially affect how we handle your data we will give notice by email or in the product before they take effect, and the date at the top of this page always reflects the current version.
13. Contact
CertTrigger — privacy@certtrigger.com
For questions about this policy, to exercise your rights, or to raise a concern about how data is handled.