1. Information We Collect
CertiSecure collects minimal personal and operational data necessary to deliver secure bulk certificate generation:
- Account Information: Name, email address, password hash (Bcrypt), subscription plan status, and monthly certificate usage counts.
- Security Audit Logs: IP address, browser user-agent, timestamp, and authentication events (logged strictly for security monitoring).
- Temporary Processing Data: Uploaded CSV recipient name lists and background certificate template images.
2. 24-Hour Automated Data Deletion (Zero Long-Term Storage)
We do not store your CSV recipient lists or generated certificate images permanently. Exactly 24 hours after batch processing completes, our automated cron cleanup engine hard-deletes all uploaded files, rendered PNG/PDF images, and ZIP packages from disk.
3. Password Security & Anti-User Enumeration
To protect administrator privacy and prevent email enumeration attacks:
- We do not disclose whether an email address belongs to an administrator during password reset requests.
- All password reset requests for invalid, unregistered, or administrator emails display the exact same generic error message: "No account found with this email address. Please check your email or register a new account."
- Password reset requests are rate-limited to a maximum of 3 requests per 24 hours.
4. Two-Factor Authentication (2FA) & Cookie Usage
We use essential cookies and session security tokens:
- Session Cookie (`PHPSESSID`): Encrypted session identifier to maintain your logged-in portal state.
- Trusted Device Cookie (`certisecure_device_token`): An HTTP-only, secure, SameSite=Lax cookie set when you mark a browser as trusted. Valid for 30 days to skip 2FA challenges on that specific device.
- 2FA Passcodes: One-time 6-digit verification codes are hashed using SHA-256 before storage and automatically expire after 10 minutes.
5. Unused Certificate Credit Vault Privacy
Information regarding your unused certificate credit rollovers and claim requests is private to your account and accessible only by system administrators for audit verification.
6. Third-Party Payments
Payments are processed directly via Razorpay API Checkout. CertiSecure does not store or process credit card, debit card, or bank account credentials on our servers.
7. Privacy Inquiries
If you have any questions or data deletion requests, contact our privacy team via our Support Inquiry Page.