Privacy Policy

Information Collection & Use

We collect information to operate the CertaLink website (https://certalink.app) and Chrome Extension effectively.

  • Chrome Extension Data: The CertaLink Chrome Extension operates within the Gmail environment (mail.google.com). We do not read, manage, or interact with Google’s cookies. To provide our core functionality, the extension utilizes Supabase for secure user authentication, storing JSON Web Tokens (JWTs) securely in your browser’s Local Storage or chrome.storage. Although the extension operates within the Gmail environment, CertaLink does not read, collect, transmit, or store your email content, draft text, recipient email addresses, or personal communications.
  • Website Visitors: When you leave comments on the site, we collect the data shown in the comments form, your IP address, and browser user agent string to help detect spam. An anonymized string (hash) from your email may be sent to Gravatar (see their policy: https://automattic.com/privacy/).
  • Media & Registration: If you upload images to the website, you should avoid including embedded location data (EXIF GPS). If you register on our site, we store the personal information provided in your user profile.

Chrome Web Store Compliance & Data Sharing

To comply with Google’s requirements and protect your privacy, we adhere to strict data sharing guidelines regarding the CertaLink Chrome Extension:

  • No Sale of Data: We absolutely do not sell your personal data or extension data to third parties. We do not use your data for advertising purposes.
  • Limited Use Policy: CertaLink’s use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
  • Third-Party Service Providers: We do not share your data with third parties except to provide our core services (e.g., Supabase for backend database and authentication, and Stripe for payment processing) or as strictly required by law.

Cookies, Local Storage & Third-Party Services

Our website and extension use local storage and cookies to enhance your experience and ensure security:

  • Extension Authentication: The CertaLink Chrome extension does not directly set or rely on its own custom cookies. Instead, it maintains your secure login session by storing authentication tokens in your browser’s Local Storage.
  • Payment Processing (Stripe): Billing and subscription management are handled securely by Stripe. When you access the billing portal, you are redirected to Stripe’s secure environment, which utilizes cookies for fraud prevention, security, and session management.
  • Website Comment & Login Cookies: If you comment on our site, you may opt-in to saving your name and email in cookies (lasts 1 year). Login cookies save your session and display choices (lasts 2 days to 1 year).
  • Website Editing Cookies: Editing or publishing an article on our site sets a temporary cookie indicating the post ID (expires after 1 day).
  • Embedded Content: Articles on this site may include embedded content (e.g., videos, images). This content behaves exactly as if you visited the source website, which may collect data, use cookies, or monitor your interaction.

Data Retention, Storage & Your Rights

Your data privacy and security are our priority. All user data stored by the CertaLink app is securely housed in a USA-based datacenter.

If you leave a comment on our website, the comment and its metadata are retained indefinitely to approve follow-up comments automatically. Registered website users can see, edit, or delete their personal information at any time (usernames cannot be changed). Website administrators can also view and edit this information.

If you have an account or have left comments, you have the right to request an exported file of the personal data we hold about you. You can also request that we erase any personal data we hold, excluding data we are obliged to keep for administrative, legal, or security purposes.