← Back to home

Privacy Policy

Last updated: 13 September 2026

1. Who We Are

CertBox is operated by Paddy Dewhurst, a sole trader based in England. We are the data controller for your account data — the details you give us to open and run your account, and how you use the Service. Where you enter your own clients’ details into a certificate, property or job, you are the controller of that data and we act as your processor; see section 9 of the Terms. Contact: support@certbox.app.

2. Data We Collect

  • Account data: name, email address, phone number, role, country, company name
  • Property data: property addresses, postcodes, property types, owner information
  • Certificate data: certificate types, issue/expiry dates, form data, uploaded PDF files
  • Organisation data: organisation name, contact details, membership
  • Usage data: login times, features used, pages visited
  • Qualification records (optional): the registration or qualification numbers you choose to save to your profile, and any copy of a qualification certificate you upload. A qualification certificate may itself show your date of birth or National Insurance number, so you may black out anything you would rather not store.

3. Lawful Basis for Processing

  • Contract: processing necessary to provide the Service you signed up for
  • Legitimate interests: improving the Service, preventing fraud, ensuring security
  • Consent: marketing communications (you may withdraw consent at any time)
  • Legal obligation: where required to comply with applicable law

4. How We Use Your Data

We use your data to: provide and maintain the Service; authenticate your identity; generate and store certificates; enable sharing of certificates via share links; send transactional emails; and improve the Service.

5. Data Sharing

We do not sell your personal data. We share data with:

If you enter your own clients' details into CertBox, you are their data controller and we act as your processor. The contract governing that is the Data Processing Agreement, which names the same recipients listed here.

  • Infrastructure providers: Hetzner (server hosting, Finland), Cloudflare (CDN and DNS, Web Analytics, and storage of our encrypted database backups in Western Europe)
  • Supabase: database, authentication, and file storage (hosted on Hetzner, Finland)
  • Stripe: payment processing (for paid subscriptions)
  • Mailgun: transactional email delivery
  • Sentry: error monitoring. We send only your account's internal ID, never your name or email. If you have opted in to analytics, Sentry also records a replay of the screen around an error, with text and form inputs masked. See section 12
  • PostHog: product analytics and session replay, EU-hosted (only if you opt in, see Cookies below. Text and form inputs are masked in session recordings)
  • GitHub: bug reports and feature requests you send through the app, and support emails, may be filed as issues in our private GitHub repository so we can track them. The issue includes your name, email address and message. GitHub is in the United States
  • Xero and QuickBooks: only if you connect one of them to your account. When you send an invoice to it, the invoice and your client's name, email address and address are sent
  • Anthropic: only if you use BoardScan. The photograph you take of the consumer unit is sent to Anthropic's API (United States) to read the circuit labels, and the circuit list comes back to you. Nothing else on your account is sent, and nothing is sent at all unless you press Scan board
  • Postcodes.io: a UK postcode you type into the property finder, to look up the address. The postcode alone is sent, nothing else
  • Google: when you are not signed in, some pages load Google's sign-in script so we can offer sign-in with Google. Loading it sends your IP address and browser details to Google. If you sign in with Google, the sign-in exchange happens with Google directly. Google is in the United States. The fonts are served from this domain
  • Twilio and MessageBird: only if you send a customer an SMS. The recipient's phone number and the message text are sent to deliver it
  • Share link recipients: when you create a share link, the linked certificate data is accessible to anyone with the link

6. Data Retention

We retain your account and certificate data for as long as your account is active. When you delete your account, your records are deleted from our database straight away and from our database backups within 30 days, except where retention is required by law. Files such as certificate PDFs and photographs are not removed automatically. To have them deleted, email support@certbox.app. Shared certificate snapshots may persist until the share link expires.

Any qualification certificate you upload is stored privately and is visible only to you. We do not check it, attach it to any certificate you issue, send it to your customers, or show it on a verification page. You can delete it at any time from Account → Qualifications, and it is deleted with your account.

7. International Transfers

Your data is stored on Hetzner servers located in Finland (EU). Encrypted copies of our database backups are held by Cloudflare in Western Europe. Static assets are served via Cloudflare's global CDN. Finland and the rest of the EU and EEA are covered by UK adequacy regulations. Where data is transferred outside the UK/EU, we rely on appropriate safeguards including Standard Contractual Clauses.

8. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

To exercise these rights, contact support@certbox.app. We will respond within one month.

9. Location data

If you allow your device to share its location, CertBox can record where you are while you are working on a job, so your employer can see your team’s positions:

  • Data collected: latitude, longitude, the accuracy of that reading, and a timestamp, linked to your user account, your employer’s organisation, and the job you are working on
  • Control: nothing is recorded unless you grant your device’s location permission to CertBox. You can withdraw it at any time in your browser or phone settings, and recording stops
  • Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR) — showing an employer where their engineers are during working hours
  • Retention: Location history is deleted after 30 days, automatically
  • Your rights: You can ask for your location history at any time, or ask for it to be deleted sooner, by contacting support@certbox.app

10. Browser extension

We publish a CertBox extension for Chrome. It shows your certificates and properties in a popup, and lets you save a property from a page you are looking at. It is optional and separate from the website, and this policy covers it — there is no second policy. If you have not installed it, nothing in this section applies to you.

  • Signing in: the extension has no sign-in of its own. A script that runs only on certbox.app reads the sign-in token your browser already holds for the site, and the extension keeps a copy — an access token and a refresh token — in the browser’s extension storage on your own device. That copy is not sent to us or to anyone else; it is what lets the popup read your account
  • Signing out: signing out of certbox.app removes the token from the site, and the extension deletes its copy. Signing out of the website signs you out of the extension too
  • What the popup shows: your own certificates and properties, read from CertBox with your account — the same records the website shows you. The extension talks to one address, api.certbox.app, and to nothing else. No other company receives anything from it
  • Saving a property from a page: only when you right-click a page and choose “Save to CertBox as Property”. At that point, and only then, the extension reads the visible text and the title of the page you are on to pick out an address and a UK postcode, and puts them in the popup for you to check and correct. Nothing reaches your account until you press Save Property, and what is saved is the address, postcode and property type you confirm — not the web address of the page, which is shown to you only so you can see where the details came from. The extension does not read pages on its own
  • Site access: it is installed with access to certbox.app and our API. Rightmove, Zoopla and OnTheMarket are listed as optional sites; Chrome grants an optional site only if you agree to it, and you can withdraw that at any time in Chrome’s extension settings
  • No tracking: the extension contains no analytics, no session recording and no advertising code, and it sends us nothing about where you browse

11. Newsletter (withdrawn)

We no longer operate a newsletter. Subscriptions closed on 24 August 2026 and no marketing emails are sent. If you subscribed before that date, this is what we hold and what happens to it:

  • Data held: email address, consent status, consent text, and timestamp of consent
  • Lawful basis: Consent (Article 6(1)(a) UK GDPR), given when you opted in
  • Use: None. The newsletter it was collected for is no longer sent, and this data is not used for any other purpose
  • Retention: A record of your email and unsubscribe date is kept for 12 months from unsubscribing, then deleted
  • Erasure: You can ask us to delete your subscriber record at any time by contacting support@certbox.app

12. Cookies

We use essential cookies required for authentication and Service functionality. We use Cloudflare Web Analytics to understand aggregate usage patterns. Cloudflare Web Analytics does not use cookies and does not track individual users across sessions or sites. No advertising or remarketing cookies are used.

We use PostHog to see which pages help people complete a certificate. It is off until you opt in: we ask once, and if you decline it is never loaded and sets nothing on your device. If you accept, PostHog sets a ph_ cookie to recognise a returning browser. It is hosted in the EU. PostHog records which buttons and links you click, and — since 21 August 2026 — a replay of your session, so we can see where people get stuck. PostHog collects page views and clicks only if you opt in. In a session recording, the text on the page and anything typed into a form are masked before they leave your browser, so a replay shows the layout, where you moved and what you clicked. Identifiers in page addresses, such as a certificate or property ID, are removed before anything is sent. We ran Google Analytics alongside PostHog until 5 August 2026; it has been removed and no longer receives anything. You can change your answer at any time:

We also count events in our own database — page views, certificate started, certificate finished — so we can tell whether the app is working. Before you sign in, the choice above controls that count fully: if you opt in, it carries an identifier stored on your device so we can follow one visit through to the end; if you decline, nothing is stored on your device and no identifier is sent, so the count is not tied to you or to any earlier visit. Once you are signed in, we also log which pages and features your account uses, in the same database, so we can fix things that are not working. That logging is tied to your account rather than to a cookie, so the choice above does not affect it — it is part of running the service, under our legitimate interest in keeping it working. You can ask us to stop by emailing support@certbox.app. We keep these counts for 24 months.

One more thing you should know about errors: if something breaks while you have opted in, our error-monitoring tool (Sentry, see section 5) records a short replay of what was on screen around the failure so we can reproduce it. Text and form inputs are masked and images and video are blocked before it leaves your browser, so the replay shows the shape of the screen. This only happens when an error occurs, and never at all if you have declined.

Analytics is off — you have not been asked yet.

13. Security

We implement appropriate technical and organisational measures to protect your data. All traffic is encrypted in transit using TLS. Access to your records is enforced at the database layer, so one account cannot read another's data. Passwords are stored only as salted hashes, never in readable form, and two-factor authentication is available on your account. Database backups are encrypted before they leave our server. We review our security posture and dependencies regularly.

14. Children

The Service is not directed at individuals under 18. We do not knowingly collect personal data from children.

15. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notification.

16. Complaints

If you are unhappy with how we have handled your personal data, you can complain to us directly at support@certbox.app. Please tell us what happened and what you would like us to put right.

We will acknowledge your complaint within 30 days of receiving it. We will then investigate without undue delay, keep you informed of progress, and explain the outcome once we have concluded.

You do not have to complain to us first. You can contact the Information Commissioner's Office (ICO) at any time, and you keep that right whatever the outcome of our own investigation. The ICO can be reached at ico.org.uk, by phone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.