How we collect, use, protect, and respect your data
VerifyCertificate.online ("we", "our", "us", or "the Platform") is a digital certificate verification service that enables registered educational institutes, training providers, and certification bodies ("Institutes") to publish and manage certificates, and allows any person ("Verifier") to verify the authenticity of such certificates by entering a unique certificate number.
We operate as both a Data Controller (for platform usage data and account data) and a Data Processor (for certificate data uploaded by registered Institutes).
Our registered correspondence address and data controller contact details are provided in Section 20 of this Policy.
This Privacy Policy applies to:
This Policy does not apply to third-party websites linked from our platform. We encourage you to review the privacy policies of any third-party sites you visit.
When an Institute registers and uses our platform, we collect:
When a person performs a certificate verification, we collect:
We automatically collect certain technical information when you access our platform:
| Data Type | Purpose | Retention |
|---|---|---|
| IP Address | Security, fraud prevention, abuse detection | 90 days |
| Browser & Device Info | Platform optimization and compatibility | 90 days |
| Session Cookies | Authentication and session management | Session end |
| Access Logs | Security auditing and debugging | 180 days |
| Verification Logs | Audit trail for certificate access | 3 years |
We do not collect or process:
We use the information collected for the following purposes:
For users in the European Economic Area (EEA) and United Kingdom, we process personal data under the following legal bases as defined in the General Data Protection Regulation (GDPR) and UK GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Certificate verification queries | Legitimate interests (Article 6(1)(f)) |
| Institute account management | Performance of a contract (Article 6(1)(b)) |
| Certificate data uploaded by Institutes | Legitimate interests / Contract (Article 6(1)(b)(f)) |
| Security logging and fraud detection | Legitimate interests (Article 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Article 6(1)(c)) |
| Marketing communications (if opted in) | Consent (Article 6(1)(a)) |
Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
We do not sell, rent, or trade personal data. We may share data only in the following limited circumstances:
Institutes can view the verification logs for certificates they have uploaded, including the date, time, and approximate location of verification attempts. This helps Institutes monitor certificate usage and detect misuse.
We engage trusted third-party processors to assist in operating our platform. All processors are bound by Data Processing Agreements (DPAs) and are prohibited from using your data for any purpose other than providing services to us. These include:
We may disclose personal data if required to do so by law, court order, or government authority under applicable national or international law, including GDPR Article 6(1)(c) or equivalent legislation.
In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections. We will notify affected users before any such transfer.
We may share your data in any other manner with your explicit prior consent.
We retain personal data only for as long as necessary for the purposes described in this Policy or as required by law:
| Data Category | Retention Period | Reason |
|---|---|---|
| Certificate data (active Institutes) | Duration of Institute subscription + 1 year | Service delivery |
| Certificate data (closed accounts) | 3 years after account closure | Legal & dispute resolution |
| Verification logs | 3 years | Audit trail & fraud prevention |
| Institute account data | Duration of account + 2 years | Contractual obligations |
| IP address / access logs | 90–180 days | Security monitoring |
| Payment records | 7 years | Tax and accounting law |
| Support communications | 2 years | Service quality |
After the applicable retention period, data is securely deleted or anonymized in accordance with our data destruction policy.
We implement comprehensive technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, or destruction:
We use a minimal and privacy-respecting approach to cookies:
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
| PHPSESSID | Essential | Session management and authentication | Session |
| csrf_token | Essential | Cross-site request forgery protection | Session |
| vc_pref | Functional | User interface preferences (if any) | 30 days |
We do not use:
Essential cookies cannot be disabled as they are strictly necessary for the platform to function. You may disable functional cookies through your browser settings, but this may affect your experience.
Depending on your location and applicable law, you may have the following rights regarding your personal data:
Regardless of your location, you have the right to:
Submit a request to privacy@verifycertificate.online with your name, contact details, and a description of your request. We will respond within 30 days (or 72 hours for urgent security matters). We may require identity verification before processing your request.
VerifyCertificate.online does not knowingly collect personal data directly from children under the age of 13 (or under 18 where required by local law).
Certificate data for minors (e.g., school students) may be uploaded by registered Institutes acting as the data controller for such information. In such cases, it is the sole responsibility of the Institute to ensure they have obtained appropriate parental or guardian consent as required by applicable law before submitting such data to our platform.
If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take immediate steps to delete such data. If you believe a child's data has been submitted without consent, please contact us immediately at privacy@verifycertificate.online.
Our primary servers are located in a secure data centre. If you are accessing our platform from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, please be aware that your data may be transferred to and processed in the country where our servers are hosted.
For international transfers of personal data, we implement appropriate safeguards including:
By using our platform, you consent to the transfer, storage, and processing of your data in the countries where our infrastructure and service providers operate, subject to the protections described in this Policy.
Registered Institutes using our platform act as independent Data Controllers for the certificate and student data they upload. By registering on VerifyCertificate.online, Institutes agree to:
VerifyCertificate.online is not liable for data uploaded by Institutes in violation of applicable law or our Terms of Service. However, we reserve the right to remove any data that we reasonably believe to be unlawful, inaccurate, or in violation of our policies.
If your personal data appears on a certificate published on our platform and you wish to:
VerifyCertificate.online does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals as defined under GDPR Article 22.
The certificate verification result (Valid / Invalid / Expired / Not Found) is a direct database lookup — not an AI-driven decision — and is based solely on the data entered by the issuing Institute. No inference, scoring, or profiling of any individual is performed during the verification process.
If you believe a verification result is incorrect, you may contact the issuing Institute or submit a dispute to us at support@verifycertificate.online.
Our platform may contain links to third-party websites, Institute portals, or external resources. These links are provided for convenience only. We have no control over and accept no responsibility for the content, privacy practices, or data handling of any third-party site.
We use the following limited third-party services that may process certain data:
We do not embed social media buttons, tracking pixels, or third-party advertising scripts on our platform.
We have appointed a Grievance Officer to handle privacy complaints and data-related concerns from users worldwide. If you have an unresolved privacy concern that has not been addressed satisfactorily, please contact our Grievance Officer:
Any user may submit a grievance regarding the processing of their personal data. We will acknowledge receipt within 48 hours and resolve the complaint within 30 days. Users who remain unsatisfied after our grievance process may escalate to their national data protection authority or relevant regulatory body.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
To exercise any of these rights, submit a verifiable consumer request to privacy@verifycertificate.online. We will respond within 45 days. You may designate an authorized agent to submit requests on your behalf.
Categories of Personal Information Collected (past 12 months): Identifiers (IP address), Internet or network activity (access logs), Certificate data submitted by Institutes (name, course, certificate number). We have not sold any personal information in the past 12 months.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of VerifyCertificate.online after the effective date of any updated Policy constitutes your acceptance of the revised Policy. If you do not agree with the updated Policy, you should discontinue use of our platform and may request deletion of your data as described in Section 10.
We encourage you to review this Policy periodically. All previous versions of this Policy are archived and available upon request.
For any privacy-related questions, requests, or concerns, please contact us through any of the following channels. We aim to respond to all enquiries within 2 business days.