Privacy Policy

Last updated: June 4, 2026

1. Information We Collect

Certack collects information necessary to provide and improve our infrastructure monitoring services. The types of information we collect include:

  • Account Information: Email address, name, and password when you create an account.
  • Monitoring Data: Domain names, URLs, and configuration details you add for SSL, DNS, and domain monitoring.
  • Incident Data: Downtime events, SSL expiry incidents, DNS change alerts, and other monitoring incidents recorded for your sites.
  • Team Member Data: Names and email addresses of team members you invite to your account on Team plan.
  • API Key Data: API keys (sp_ prefix) generated for programmatic access, including usage metadata such as last used timestamp and request counts.
  • Usage Data: How you interact with our service, including pages visited, features used, and browser/device information.
  • Payment Information: Billing details processed securely through our payment provider, Creem. We do not store credit card numbers on our servers.
  • Billing Identifiers: Your Creem customer ID used to link your account to payments and subscription events.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our monitoring services
  • Send you alerts and notifications about your monitored infrastructure
  • Process payments and manage subscriptions
  • Improve our service and develop new features
  • Communicate with you about your account, updates, and support
  • Detect and prevent fraud or abuse
PurposeGDPR Lawful BasisLegal Reference
Provide monitoring servicesContract performanceGDPR Art. 6(1)(b)
Send alerts and notificationsContract performanceGDPR Art. 6(1)(b)
Process paymentsContract performanceGDPR Art. 6(1)(b)
Improve service and develop featuresLegitimate interestGDPR Art. 6(1)(f)
Account communications and supportContract performanceGDPR Art. 6(1)(b)
Fraud and abuse preventionLegitimate interestGDPR Art. 6(1)(f)

3. Data Storage and Security

Your data is stored on secure servers with industry-standard encryption. Our primary infrastructure is hosted in the United States through Supabase (database and authentication), with the application served from Cloudflare's global edge network (application hosting and API endpoints). Cloudflare's edge network may process data transiently in various global locations. We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in the United States. We ensure such transfers are protected under Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms.

Data TypeRetention Period
Account dataWhile account is active + 30 days after deletion
Monitoring data (checks, results)30 days on all plans (older records are pruned)
Incident dataWhile account is active + 30 days after deletion
Application logs90 days
Payment recordsAs required by law (typically 7 years)
API key usage logs90 days
Email delivery records90 days (sent and failed records are pruned; pending messages are retained until delivered)

4. Third-Party Services

We use the following third-party services to operate our platform. Each service processes data only as necessary to perform its designated function:

  • Supabase — Database and authentication provider. Stores all account data, monitoring configurations, and check results. Data is hosted in the United States. Supabase's privacy policy applies to the infrastructure they operate.
  • Cloudflare Workers — Application hosting and deployment. Serves the Certack web application and API endpoints from Cloudflare's global edge network. Cloudflare's privacy policy applies to their infrastructure.
  • Cloudflare edge network — Network serving for monitoring checks. Monitoring request data is processed transiently at the edge and not stored persistently by Cloudflare.
  • Creem — Payment processing. Handles all payment transactions and stores billing information securely. We do not store credit card numbers on our servers. Creem's privacy policy applies to the payment data they process on our behalf.
  • Resend — Transactional email delivery. Sends alert notifications, account verification emails, and password reset messages on our behalf. Resend processes email addresses and email content necessary for delivery. Resend's privacy policy applies.
  • Upstash — Optional rate-limiting backend. When enabled, Upstash processes IP addresses and user identifiers transiently to enforce API rate limits; it does not store personal data persistently. Upstash's privacy policy applies when this integration is active.

We do not sell, trade, or otherwise transfer your personal information to third parties except as described in this policy. Where we engage third-party providers, they process data under our instructions and in compliance with applicable data protection laws, and we rely on each provider's published DPA / data processing terms.

5. Cookies

We use cookies and similar tracking technologies to enhance your experience. You can control cookie preferences through your browser settings. Disabling cookies may affect some features of our service.

Cookie NamePurposeDurationCategory
sb-*Supabase authentication sessionSessionEssential
NEXT_LOCALEStores your language preference1 yearEssential
__cf_bmCloudflare bot detection and security30 minutesEssential
cf_clearanceCloudflare challenge clearance1 yearEssential

We do not use third-party analytics cookies (such as Google Analytics). All cookies used by Certack are essential for the operation and security of the service. Your light/dark mode preference is stored locally in your browser (localStorage) and is never transmitted to our servers.

6. Data Retention

We retain your data only for as long as necessary to provide our services and comply with legal obligations. Specific retention periods by data type are outlined below:

Data TypeRetention PeriodNotes
Account informationActive + 30 days post-deletionDeleted within 30 days of account deletion request
Monitoring check results30 daysOlder check records are automatically pruned on all plans
SSL/DNS/domain check data30 daysSame as monitoring check results
Incident recordsWhile account is activeDeleted with the account
Application logs90 daysAutomatically purged after 90 days
Payment recordsAs required by lawTypically 7 years for tax and accounting compliance
API key usage logs90 daysAutomatically purged after 90 days
Email delivery records90 daysSent/failed records pruned; pending messages retained until delivered

If you delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or accounting purposes.

7. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Right of Access: Request and receive a copy of your personal data that we hold.
  • Right to Rectification: Correct inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
  • Right to Restrict Processing: Request that we limit how we process your data in certain circumstances.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON), and have the right to transmit that data to another controller without hindrance.
  • Right to Object: Object to the processing of your personal data for direct marketing or purposes based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise any of these rights, contact us at privacy@certack.com. We will respond to your request within 30 days. If you are located in the EEA, you also have the right to lodge a complaint with your local supervisory authority.

8. International Data Transfers

Certack is headquartered in the United States, and our primary data processing occurs on US-based infrastructure. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data may be transferred to and processed in the United States and other countries.

We ensure that international data transfers are protected through the following mechanisms:

  • Standard Contractual Clauses (SCCs): We have executed EU Standard Contractual Clauses (Module Two: Controller to Processor and Module Three: Controller to Controller, as applicable) with our third-party service providers who process data outside the EEA. These clauses are approved by the European Commission and provide legally binding guarantees that data transfers meet EU data protection standards.
  • Adequacy Decisions: Where the European Commission has issued an adequacy decision confirming that a country provides an equivalent level of data protection (e.g., the EU-US Data Privacy Framework), transfers may rely on such adequacy decisions.
  • Supplementary Measures: Where SCCs alone may not provide sufficient protection, we implement supplementary measures including encryption of data in transit (TLS 1.2+) and at rest (AES-256), access controls, and regular security assessments to ensure an essentially equivalent level of protection for transferred data.

For more details on the specific transfer mechanisms used with each service provider, please contact us at privacy@certack.com.

9. Automated Decision-Making

Certack does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Our monitoring services perform automated checks on infrastructure (domains, SSL certificates, DNS records) but do not make decisions about natural persons. All decisions regarding your account, data, or service access are made by human operators.

10. Data Processing Agreement

For enterprise customers who require a Data Processing Agreement (DPA) under the GDPR or other applicable data protection regulations, Certack makes a DPA available upon request. The DPA covers the scope, nature, and purpose of data processing, the types of personal data processed, and the obligations of both parties under applicable data protection laws.

To request a DPA, please contact us at legal@certack.com.

11. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:

  • Right to Know: You have the right to request that we disclose what personal information we collect, use, and disclose about you (categories and specific pieces), the purposes for which we use it, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request that we delete any personal information we have collected from you, subject to certain exceptions (such as completing transactions, detecting security incidents, or complying with legal obligations).
  • Right to Opt-Out of Sale: We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. There is nothing to opt out of because we do not engage in this practice.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny services, charge different prices, or provide a different level of service based on your exercise of these rights.

To exercise your CCPA rights, submit a request to privacy@certack.com. We will verify your identity and respond within 45 days, or notify you if an extension is needed. You may also designate an authorized agent to submit requests on your behalf.

12. Children's Privacy

Certack is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last updated” date. Your continued use of the service after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Email: privacy@certack.com

Legal inquiries: legal@certack.com