Privacy Policy
Effective date:
1. Who We Are
ShareCerti ("we", "our", "us") operates the website sharecerti.com and provides cloud-based certificate and badge generation services. For privacy questions, contact us at support@sharecerti.com.
2. What Data We Collect
We collect data in the following ways:
Account data
- Name and email address when you register or sign in with Google.
- Profile photo (optional, via Google OAuth).
Payment and billing data
- When you buy a credit pack, your payment is processed by Razorpay. We do not store your card number, CVV, or bank account details.
- We store the Razorpay order ID, payment status, amount paid, and number of credits purchased.
- Razorpay may collect name, email, phone, and billing address during checkout. See Razorpay's Privacy Policy at razorpay.com/privacy-policy for details.
Certificate and usage data
- Recipient names and email addresses you upload for certificate issuance.
- Design data for templates and certificates you create.
- Files and images you upload to create certificates or badges.
- Usage logs such as issuance timestamps and credit deductions.
Technical data
- IP address, browser type, and device information for security and analytics.
- Session cookies managed by Better Auth for keeping you logged in.
3. How We Use Your Data
- To create and manage your account and deliver the service.
- To process payments and grant certificate issuance credits via Razorpay.
- To send certificates to your designated recipients via email.
- To send transactional emails such as payment receipts and service notices.
- To prevent fraud and enforce our Terms of Service.
- To improve the platform through aggregated, anonymised analytics.
4. Payment Processing via Razorpay
All payments on ShareCerti are processed securely through Razorpay, a PCI-DSS compliant payment gateway regulated by the Reserve Bank of India. ShareCerti never receives or stores your full card, UPI, or net banking credentials. By making a payment you also agree to Razorpay's Terms of Service and Privacy Policy.
5. Data Sharing
We do not sell your personal data. We share data only in these cases:
- Razorpay — to process payments (see Section 4).
- Resend / email providers — to deliver certificates and receipts.
- Cloud infrastructure providers (storage, database) — under confidentiality agreements.
- Legal authorities — if required by Indian law or a valid court order.
6. Data Retention
- Account and profile data is retained while your account is active.
- Payment transaction records are retained for 8 years as required by Indian financial regulations.
- Certificates and templates are retained until you delete them or close your account.
- You may request deletion of your account and data by emailing support@sharecerti.com.
7. Cookies
We use session cookies to keep you logged in. These are strictly necessary for the service to function. We do not use third-party advertising cookies. You can disable cookies in your browser settings, but this will prevent you from logging in.
8. Your Rights
Under India's Digital Personal Data Protection (DPDP) Act 2023 and applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request erasure of your data (subject to legal retention requirements).
- Withdraw consent for processing where consent is the legal basis.
- Lodge a complaint with the Data Protection Board of India.
To exercise any of these rights, email us at support@sharecerti.com.
9. Security
We use HTTPS for all data in transit, store passwords using bcrypt hashing, and restrict access to production data to authorised personnel only. Payment data is protected through Razorpay's PCI-DSS certified infrastructure.
10. Changes to This Policy
We may update this policy as the service evolves. Material changes will be communicated via email or a notice on the site at least 7 days before they take effect. Continued use of the service after changes means you accept the updated policy.
11. Contact
For privacy-related queries, write to us at support@sharecerti.com. We aim to respond within 5 business days.