This policy explains how Simple Certificate Tracker ("we", "us") collects and uses personal data when you use Simple Certificate Tracker from the United Kingdom.
Who is responsible for your data?
You are the data controller for employee and certificate data you enter. You decide what to record, how long to keep it, and whether it is accurate.
Simple Certificate Tracker acts as a data processor when storing and processing that data on your behalf to provide the service.
Questions: hello@simplecertificatetracker.com. For a formal data processing agreement, see our DPA page.
What we collect
- Account data: name, email address, password hash, organisation name.
- Employee records you enter: names, optional email, job role, department.
- Certificate records: certificate names, types, issue and expiry dates, notes, reference numbers.
- Documents (Premium): files you upload (PDF, JPG, PNG).
- Technical data: IP address and basic usage analytics (no certificate content in analytics events).
- Payment data: handled by Stripe — we do not store card numbers.
Why we process it
- To provide certificate tracking, dashboards, reminders, and exports.
- To authenticate you and secure your account.
- To send expiry reminder emails you enable.
- To process Premium subscriptions.
- To improve the product (aggregated analytics only).
Legal basis (UK GDPR)
- Contract: processing necessary to provide the service you signed up for.
- Legitimate interests: security, fraud prevention, and product improvement.
- Consent: where required for optional marketing (we do not sell your data).
Sub-processors
We use third-party providers to run the service. See the full sub-processor list:
- Vercel — Application hosting and edge delivery
- Neon — PostgreSQL database (employee and certificate records)
- Resend — Transactional email (verification, password reset, reminders)
- Stripe — Payment processing (Premium subscriptions)
- PostHog — Product analytics (no certificate content in events)
International transfers
Some providers may process data outside the UK. Where this applies, we rely on appropriate safeguards (such as UK IDTA or provider DPAs). Contact us if you need details for your organisation's records.
How long we keep data
- Employee and certificate records are kept while your account is active and you choose to retain them.
- Deleted employees and certificates are soft-deleted and excluded from dashboards; records may be retained for recovery until permanently removed.
- On account deletion request, we delete or anonymise personal data within 90 days unless we must retain limited records for legal obligations.
- Uploaded certificate documents (Premium) are deleted when the parent certificate is deleted or when your organisation data is removed.
Your rights
Under UK GDPR you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Request erasure (subject to legal exceptions).
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent where processing is consent-based.
- Lodge a complaint with the ICO (ico.org.uk).
Exporting your data
- Printable status report and compliance pack (free on all plans) — PDF via browser print
- CSV export of certificate records (Premium)
- CSV export of audit log (Premium)
- Contact us for a full data export before account closure
Sharing
We do not sell your data. We share data only with sub-processors needed to operate the service, or when required by law.
Children
The service is for businesses tracking employee records. It is not intended for use by children under 16.
Changes
We may update this policy. Material changes will be reflected on this page with an updated date.