What we collect
Account email and name from sign-up (including when you use Sign in with Google); organization profile you fill in during onboarding; vendor contact data you upload; the PDFs you or your vendors send us; extraction metadata (cost, latency, confidence, model version) so we can debug bad verdicts; audit events for every document, verdict, and message; IP address and user-agent on every request for abuse and rate-limit control. Billing information is collected by Paddle, not by us — we never see full card numbers.
How we use it
To provide the service you paid for and nothing else. Extract fields from COIs, run compliance checks, send chase emails to your vendors, generate reports for you, and keep the workspace working. We do not use your data or your vendors' documents to train AI models — the extraction models we use are commercial APIs, not ours, and are configured with the no-training option enabled. We do not sell or rent personal data. We do not run behavioural advertising.
Google sign-in
If you choose Sign in with Google, we receive your Google account email and basic profile name solely to create or look up your CertShield workspace account and keep you signed in. We do not access Gmail, Drive, Calendar, or Contacts. CertShield's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access in your Google Account settings at any time.
Where data lives
Data is stored in the United States (Supabase / AWS + Vercel). TIN/SSN on W-9s are field-level encrypted and masked. See Security for subprocessors.
Who we share it with (subprocessors)
The vendors below process personal data on our behalf, each contractually bound to only use it to deliver their service. A full list with locations and purposes lives on the Subprocessors page: Vercel (hosting, US), Supabase (Postgres + storage, US), OpenRouter / Anthropic (AI extraction, US), Resend (outbound email, US), Postmark (inbound email — deferred until requested), Paddle (billing, merchant of record, US/UK), Cloudflare (DNS + email routing, global), Sentry (error tracking, US), Inngest (background jobs, US), Intercom (in-app support chat for signed-in users, US).
Your rights
You can access, export, correct, or delete your workspace data from Settings, or by emailing hello@getcertshield.app. California residents (CCPA/CPRA), EU/UK residents (GDPR), and Canadian residents (PIPEDA) have the same rights and we honour them the same way — no jurisdictional obstacle. We will not discriminate against you for exercising any privacy right. Response target: 30 days.
Cookies and tracking
We set functional cookies only — session, CSRF, theme, and org-context. No third-party ad cookies, no cross-site tracking pixels. If we add basic first-party analytics later we will disclose it here and add a consent banner in EU jurisdictions.
Data retention & deletion
Active workspace data is retained while your subscription is active. After cancellation, tenant data is deleted within 90 days by default. Records we must keep for legal, tax, or billing-dispute reasons (invoices, receipts, chargeback evidence) are retained for the shorter of the statutory minimum or 7 years. You can request faster deletion via email.
Children
CertShield is a B2B product; we do not knowingly collect data from anyone under 16. If we learn we have, we delete it immediately.
Changes to this policy
Material changes are announced by email to the workspace owner at least 14 days before they take effect. Older versions are available on request.
Privacy requests: hello@getcertshield.app. Also see Terms and Security.