1. Who controls your information
CertiChecker is the controller for personal information used to operate this service. Contact us at info@certichecker.com or 07522 780029.
2. Information we use
- Account information: name, organisation, email address, phone number, password hash, account status and preferences.
- Personal profile information: postal address, profile photo, biography, location, skills, work history, qualifications, references and selected public contact details.
- Certificate information: learner or holder name, certificate title, issuer, dates, identifiers, status, uploaded certificate files and verification evidence.
- Billing information: plan, subscription status, renewal dates and Stripe customer or subscription identifiers. Payment-card details are handled by Stripe and are not stored by CertiChecker.
- Service and security information: session data, support messages, email delivery records, webhook events and limited technical information such as IP address, browser details and referring page where needed for security or support.
3. Why we use it
- To create accounts, authenticate users and deliver requested platform features under our contract with you.
- To store, display and manage certificates and Learning Passport content under our contract and legitimate interests in operating a reliable credential service.
- To process subscriptions, keep financial records and meet legal obligations.
- To prevent fraud, investigate misuse, secure the platform and maintain audit records under our legitimate interests and legal obligations.
- To respond to enquiries and support requests under our contract and legitimate interests.
- To send service messages. Marketing messages are sent only where permitted, and you can opt out at any time.
4. Public information and verification
Issuer certificate verification records are designed to be publicly checked using an identifier, link or QR code. A public result may display the holder name, certificate details, issuer, dates and status. Existing issuer-issued records remain publicly verifiable after the issuer cancels or stops paying, unless a record must be restricted or removed for a legal, security or accuracy reason.
Personal Learning Passports are private by default unless the holder chooses public visibility. A holder controls the profile fields they publish. Holder-uploaded information is not the same as issuer verification; the interface identifies review or verification status where applicable.
5. Who receives information
We use service providers for hosting and infrastructure, email delivery, payment processing through Stripe, file storage, security and technical support. They receive only the information needed to provide their service and must protect it. We may also disclose information where required by law, to protect rights and safety, or as part of a properly managed business transfer.
Some providers may process information outside the UK. Where this happens, we require an appropriate UK transfer safeguard or rely on another lawful transfer mechanism.
6. How long we keep it
We keep information only for as long as it is needed for the purposes described here, including certificate verification, account operation, security, financial record-keeping and legal claims. The detailed schedule is in our data retention policy.
7. Your data rights
Depending on the circumstances, you can ask for access, correction, deletion, restriction, objection or portability of your personal information. Where processing relies on consent, you can withdraw it. Some rights are not absolute, particularly where information remains necessary for public certificate integrity, legal obligations or legal claims.
Email info@certichecker.com to make a request. We may need to verify your identity. You can also complain to the UK Information Commissioner’s Office at ico.org.uk.
8. Security and children
We use access controls, password hashing, secure sessions, validation, restricted uploads and other technical and organisational measures designed to protect information. No online service can promise absolute security.
Account holders must be at least 18. Issuers may create records relating to younger learners only where they have appropriate authority and have provided any required privacy information.