← Back to home

Privacy Policy

Last updated: 3 October 2026

1. Who We Are

CertBox is operated by CertBox Ltd, a company registered in England and Wales (company no. 17463747). Our registered office is 66 Paul Street, London EC2A 4NA. We are registered with the Information Commissioner’s Office, registration number ZC240610. We are the data controller for your account data - the details you give us to open and run your account, and how you use the Service. Where you enter your own clients’ details into a certificate, property or job, you are the controller of that data and we act as your processor; see section 9 of the Terms. Contact: support@certbox.app.

2. Data We Collect

  • Account data: name, email address, phone number, role, country, company name
  • Property data: property addresses, postcodes, property types, owner information
  • Certificate data: certificate types, issue/expiry dates, form data, uploaded PDF files
  • Organisation data: organisation name, contact details, membership
  • Usage data: login times, features used, pages visited, and the IP address and browser details that our server records with each request
  • Qualification records (optional): the registration or qualification numbers you choose to save to your profile, and any copy of a qualification certificate you upload. A qualification certificate may itself show your date of birth or National Insurance number, so you may black out anything you would rather not store.

3. Lawful Basis for Processing

  • Contract: processing necessary to provide the Service you signed up for
  • Legitimate interests: improving the Service, preventing fraud, ensuring security
  • Consent: marketing communications (you may withdraw consent at any time)
  • Legal obligation: where required to comply with applicable law

4. How We Use Your Data

We use your data to: provide and maintain the Service; authenticate your identity; generate and store certificates; enable sharing of certificates via share links; send transactional emails; and improve the Service.

5. Data Sharing

We do not sell your personal data. We share data with:

If you enter your own clients' details into CertBox, you are their data controller and we act as your processor. The contract governing that is the Data Processing Agreement, which names the same recipients listed here.

  • Infrastructure providers: Hetzner (server hosting, Finland), Cloudflare (CDN and DNS, Web Analytics, and storage of our encrypted backups and security logs in Western Europe), Backblaze (a second encrypted copy of the same backups, in the Netherlands)
  • Supabase: database, authentication, and file storage (hosted on Hetzner, Finland)
  • Stripe: payment processing for paid subscriptions. If you connect Stripe to take card payments, Stripe also processes the payments your customers make on your invoices
  • Mailgun: sends our emails. Mailgun tells us when an email we send is delivered and when it is opened, including the IP address and device it was opened on
  • Apple: our email inbox is hosted on Apple's iCloud Mail. Emails you send to us are stored there, and so is a copy of each new certificate, which we look over by hand. Apple may store it outside the UK
  • Sentry: error monitoring. We send only your account's internal ID, never your name or email. If you have opted in to analytics, Sentry also records a replay of the screen around an error, with text and form inputs masked. See section 11
  • PostHog: product analytics and session replay, EU-hosted (only if you opt in, see Cookies below. Text and form inputs are masked in session recordings)
  • GitHub: bug reports and feature requests you send through the app, and support emails, may be filed as issues in our private GitHub repository so we can track them. The issue includes your name, email address and message. GitHub is in the United States
  • Xero and QuickBooks: only if you connect one of them to your account. When you send an invoice to it, the invoice and your client's name, email address and address are sent
  • Anthropic: only if you use BoardScan. The photograph you take of the consumer unit is sent to Anthropic's API (United States) to read the circuit labels, and the circuit list comes back to you. Nothing else on your account is sent, and nothing is sent at all unless you press Scan board
  • Postcodes.io: a UK postcode you type into the property finder, to look up the address. The postcode alone is sent, nothing else
  • Google: when you are not signed in, some pages load Google's sign-in script so we can offer sign-in with Google. Loading it sends your IP address and browser details to Google. If you sign in with Google, the sign-in exchange happens with Google directly. Google is in the United States. The fonts are served from this domain
  • Twilio and MessageBird: only if you send a customer an SMS. The recipient's phone number and the message text are sent to deliver it
  • Share link recipients: when you create a share link, the linked certificate data is accessible to anyone with the link

6. Data Retention

We retain your account and certificate data for as long as your account is active. When you delete your account, your records are deleted from our database straight away and from our database backups within 30 days, except where retention is required by law. Files such as certificate PDFs and photographs are not removed automatically. To have them deleted, email support@certbox.app. Shared certificate snapshots may persist until the share link expires. Security logs, which include IP addresses, are kept for 90 days.

Any qualification certificate you upload is stored privately and is visible only to you. We do not check it, attach it to any certificate you issue, send it to your customers, or show it on a verification page. You can delete it at any time from Account → Qualifications, and it is deleted with your account.

7. International Transfers

Your data is stored on Hetzner servers located in Finland (EU). Encrypted copies of our backups are held by Cloudflare in Western Europe and by Backblaze in the Netherlands. Static assets are served via Cloudflare's global CDN. Finland and the rest of the EU and EEA are covered by UK adequacy regulations. Where data is transferred outside the UK/EU, we rely on appropriate safeguards including Standard Contractual Clauses.

8. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

To exercise these rights, contact support@certbox.app. We will respond within one month.

9. Browser extension

We publish a CertBox extension for Chrome. It shows your certificates and properties in a popup, and lets you save a property from a page you are looking at. It is optional and separate from the website, and this policy covers it. There is no second policy. If you have not installed it, nothing in this section applies to you.

  • Signing in: the extension has no sign-in of its own. A script that runs only on certbox.app reads the sign-in token your browser already holds for the site, and the extension keeps a copy (an access token and a refresh token) in the browser’s extension storage on your own device. That copy is not sent to us or to anyone else; it is what lets the popup read your account
  • Signing out: signing out of certbox.app removes the token from the site, and the extension deletes its copy. Signing out of the website signs you out of the extension too
  • What the popup shows: your own certificates and properties, read from CertBox with your account, the same records the website shows you. The extension talks to one address, api.certbox.app, and to nothing else. No other company receives anything from it
  • Saving a property from a page: only when you right-click a page and choose “Save to CertBox as Property”. At that point, and only then, the extension reads the visible text and the title of the page you are on to pick out an address and a UK postcode, and puts them in the popup for you to check and correct. Nothing reaches your account until you press Save Property, and what is saved is the address, postcode and property type you confirm, not the web address of the page, which is shown to you only so you can see where the details came from. The extension does not read pages on its own
  • Site access: it is installed with access to certbox.app and our API. Rightmove, Zoopla and OnTheMarket are listed as optional sites; Chrome grants an optional site only if you agree to it, and you can withdraw that at any time in Chrome’s extension settings
  • No tracking: the extension contains no analytics, no session recording and no advertising code, and it sends us nothing about where you browse

10. Newsletter (withdrawn)

We no longer operate a newsletter. Subscriptions closed on 24 August 2026 and no marketing emails are sent. If you subscribed before that date, this is what we hold and what happens to it:

  • Data held: email address, consent status, consent text, and timestamp of consent
  • Lawful basis: Consent (Article 6(1)(a) UK GDPR), given when you opted in
  • Use: None. The newsletter it was collected for is no longer sent, and this data is not used for any other purpose
  • Retention: A record of your email and unsubscribe date is kept for 12 months from unsubscribing, then deleted
  • Erasure: You can ask us to delete your subscriber record at any time by contacting support@certbox.app

11. Cookies

We use essential cookies required for authentication and Service functionality. We use Cloudflare Web Analytics to understand aggregate usage patterns. Cloudflare Web Analytics does not use cookies and does not track individual users across sessions or sites. No advertising or remarketing cookies are used.

We use PostHog to see which pages help people complete a certificate. It is off until you opt in: we ask once, and if you decline it is never loaded and sets nothing on your device. If you accept, PostHog sets a ph_ cookie to recognise a returning browser. It is hosted in the EU. PostHog records which buttons and links you click, and - since 21 August 2026 - a replay of your session, so we can see where people get stuck. PostHog collects page views and clicks only if you opt in. In a session recording, the text on the page and anything typed into a form are masked before they leave your browser, so a replay shows the layout, where you moved and what you clicked. Identifiers in page addresses, such as a certificate or property ID, are removed before anything is sent. We ran Google Analytics alongside PostHog until 5 August 2026; it has been removed and no longer receives anything. You can change your answer at any time:

We also count events in our own database - page views, certificate started, certificate finished - so we can tell whether the app is working. Before you sign in, the choice above controls that count fully: if you opt in, it carries an identifier stored on your device so we can follow one visit through to the end; if you decline, nothing is stored on your device and no identifier is sent, so the count is not tied to you or to any earlier visit. Once you are signed in, we also log which pages and features your account uses, in the same database, so we can fix things that are not working. That logging is tied to your account rather than to a cookie, so the choice above does not affect it - it is part of running the service, under our legitimate interest in keeping it working. You can ask us to stop by emailing support@certbox.app. We keep these counts for 24 months.

One more thing you should know about errors: if something breaks while you have opted in, our error-monitoring tool (Sentry, see section 5) records a short replay of what was on screen around the failure so we can reproduce it. Text and form inputs are masked and images and video are blocked before it leaves your browser, so the replay shows the shape of the screen. This only happens when an error occurs, and never at all if you have declined.

Analytics is off - you have not been asked yet.

12. Security

We implement appropriate technical and organisational measures to protect your data. All traffic is encrypted in transit using TLS. Access to your records is enforced at the database layer, so one account cannot read another's data. Passwords are stored only as salted hashes, never in readable form, and two-factor authentication is available on your account. Backups are encrypted before they leave our server. We review our security posture and dependencies regularly.

13. Children

The Service is not directed at individuals under 18. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notification.

15. Complaints

If you are unhappy with how we have handled your personal data, you can complain to us directly at support@certbox.app. Please tell us what happened and what you would like us to put right.

We will acknowledge your complaint within 30 days of receiving it. We will then investigate without undue delay, keep you informed of progress, and explain the outcome once we have concluded.

You do not have to complain to us first. You can contact the Information Commissioner's Office (ICO) at any time, and you keep that right whatever the outcome of our own investigation. The ICO can be reached at ico.org.uk, by phone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.