Last updated: 13 September 2026
CertBox is operated by Paddy Dewhurst, a sole trader based in England. We are the data controller for your account data — the details you give us to open and run your account, and how you use the Service. Where you enter your own clients’ details into a certificate, property or job, you are the controller of that data and we act as your processor; see section 9 of the Terms. Contact: support@certbox.app.
We use your data to: provide and maintain the Service; authenticate your identity; generate and store certificates; enable sharing of certificates via share links; send transactional emails; and improve the Service.
We do not sell your personal data. We share data with:
If you enter your own clients' details into CertBox, you are their data controller and we act as your processor. The contract governing that is the Data Processing Agreement, which names the same recipients listed here.
We retain your account and certificate data for as long as your account is active. When you delete your account, your records are deleted from our database straight away and from our database backups within 30 days, except where retention is required by law. Files such as certificate PDFs and photographs are not removed automatically. To have them deleted, email support@certbox.app. Shared certificate snapshots may persist until the share link expires.
Any qualification certificate you upload is stored privately and is visible only to you. We do not check it, attach it to any certificate you issue, send it to your customers, or show it on a verification page. You can delete it at any time from Account → Qualifications, and it is deleted with your account.
Your data is stored on Hetzner servers located in Finland (EU). Encrypted copies of our database backups are held by Cloudflare in Western Europe. Static assets are served via Cloudflare's global CDN. Finland and the rest of the EU and EEA are covered by UK adequacy regulations. Where data is transferred outside the UK/EU, we rely on appropriate safeguards including Standard Contractual Clauses.
Under UK GDPR, you have the right to:
To exercise these rights, contact support@certbox.app. We will respond within one month.
If you allow your device to share its location, CertBox can record where you are while you are working on a job, so your employer can see your team’s positions:
We publish a CertBox extension for Chrome. It shows your certificates and properties in a popup, and lets you save a property from a page you are looking at. It is optional and separate from the website, and this policy covers it — there is no second policy. If you have not installed it, nothing in this section applies to you.
We no longer operate a newsletter. Subscriptions closed on 24 August 2026 and no marketing emails are sent. If you subscribed before that date, this is what we hold and what happens to it:
We use essential cookies required for authentication and Service functionality. We use Cloudflare Web Analytics to understand aggregate usage patterns. Cloudflare Web Analytics does not use cookies and does not track individual users across sessions or sites. No advertising or remarketing cookies are used.
We use PostHog to see which pages help people complete a certificate. It is off until you opt in: we ask once, and if you decline it is never loaded and sets nothing on your device. If you accept, PostHog sets a ph_ cookie to recognise a returning browser. It is hosted in the EU. PostHog records which buttons and links you click, and — since 21 August 2026 — a replay of your session, so we can see where people get stuck. PostHog collects page views and clicks only if you opt in. In a session recording, the text on the page and anything typed into a form are masked before they leave your browser, so a replay shows the layout, where you moved and what you clicked. Identifiers in page addresses, such as a certificate or property ID, are removed before anything is sent. We ran Google Analytics alongside PostHog until 5 August 2026; it has been removed and no longer receives anything. You can change your answer at any time:
We also count events in our own database — page views, certificate started, certificate finished — so we can tell whether the app is working. Before you sign in, the choice above controls that count fully: if you opt in, it carries an identifier stored on your device so we can follow one visit through to the end; if you decline, nothing is stored on your device and no identifier is sent, so the count is not tied to you or to any earlier visit. Once you are signed in, we also log which pages and features your account uses, in the same database, so we can fix things that are not working. That logging is tied to your account rather than to a cookie, so the choice above does not affect it — it is part of running the service, under our legitimate interest in keeping it working. You can ask us to stop by emailing support@certbox.app. We keep these counts for 24 months.
One more thing you should know about errors: if something breaks while you have opted in, our error-monitoring tool (Sentry, see section 5) records a short replay of what was on screen around the failure so we can reproduce it. Text and form inputs are masked and images and video are blocked before it leaves your browser, so the replay shows the shape of the screen. This only happens when an error occurs, and never at all if you have declined.
We implement appropriate technical and organisational measures to protect your data. All traffic is encrypted in transit using TLS. Access to your records is enforced at the database layer, so one account cannot read another's data. Passwords are stored only as salted hashes, never in readable form, and two-factor authentication is available on your account. Database backups are encrypted before they leave our server. We review our security posture and dependencies regularly.
The Service is not directed at individuals under 18. We do not knowingly collect personal data from children.
We may update this policy from time to time. We will notify you of material changes via email or in-app notification.
If you are unhappy with how we have handled your personal data, you can complain to us directly at support@certbox.app. Please tell us what happened and what you would like us to put right.
We will acknowledge your complaint within 30 days of receiving it. We will then investigate without undue delay, keep you informed of progress, and explain the outcome once we have concluded.
You do not have to complain to us first. You can contact the Information Commissioner's Office (ICO) at any time, and you keep that right whatever the outcome of our own investigation. The ICO can be reached at ico.org.uk, by phone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.