Privacy Policy

Last updated: 2025-06-15

← Back to CertiPing

CertiPing ("we," "us," or "our") helps shops and warehouses avoid costly safety-certification fines by tracking expiry dates and sending automated reminders. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use certiping.com, the CertiPing web application, and related services (collectively, the "Service").

California Notice: This policy is designed to satisfy the California Consumer Privacy Rights Act (CPRA, Cal. Civ. Code §1798.100 et seq.). It also meets the core transparency requirements of GDPR Art. 13/14. Where CPRA affords you additional rights, we highlight them in bold.

1. Information We Collect

Category (CPRA §1798.140) Examples Source Purpose
Identifiers Work-email, name, phone number You (signup, CSV import) Account creation, login, email/SMS reminders
Employment-related data Job title, company name You Display in dashboard, reminder context
Internet activity IP address, browser agent, pages visited, error logs Automatic Security, debugging, analytics
Certification records ("Professional or employment information") Cert type, expiry date, PDF scans You Display dashboard, send reminders, generate compliance reports

We do not collect sensitive personal information as defined by CPRA (e.g., SSN, precise geo, biometric, medical, or financial account numbers).

2. Why We Use Your Information

  1. Provide and maintain the Service (create accounts, display dashboards).
  2. Send reminder emails and SMS notifications requested by your organization.
  3. Generate PDF compliance reports.
  4. Provide customer support and resolve technical issues you report.
  5. Improve reliability (debugging, analytics, error logging).
  6. Produce anonymized, aggregated statistics (e.g. number of certificates managed) to improve our service and communicate product trends.
  7. Security / fraud prevention (rate-limiting, detecting abuse).
  8. Comply with legal obligations (OSHA record retention, accounting).

We rely on the following lawful bases: performance of contract, legitimate interest (service improvement & security), and legal obligation.

3. How We Share Information

We never sell or rent personal information. We disclose data only to service providers under CPRA-compliant agreements:

Service Provider Purpose Location
Supabase Database, authentication, storage USA / EU (user-selectable)
Vercel Application hosting / CDN USA / global
Postmark Transactional email delivery USA
Twilio SMS notification delivery USA
Cloudflare Edge network, security, status page Global

Service providers may access data solely to provide services and must delete/return data upon termination.

We may also share data if required by law, to protect rights, or in connection with a corporate reorganization.

4. Cookies & Tracking

We use essential cookies for authentication and session management, plus optional analytics cookies (Google Analytics 4) if you consent via our banner. You can disable non-essential cookies at any time.

5. SMS Communications & Consent

SMS Opt-In Process

For Professional and Enterprise plan subscribers, we offer SMS notifications for certification expiration reminders. SMS notifications are optional and require explicit consent:

SMS Message Types

SMS Opt-Out

You can opt-out of SMS notifications at any time by:

SMS Data & Rates

6. Your CPRA Rights

California residents have the right to:

  1. Know the categories and specific pieces of personal information we collect.
  2. Delete personal information we hold (subject to OSHA retention requirements).
  3. Correct inaccurate personal information.
  4. Opt-out of "sale" or "sharing" of personal data (we do neither).
  5. Limit use of sensitive personal information (not collected).
  6. Non-discrimination for exercising any of these rights.

Exercise Your Rights

Email [email protected] or use the "Privacy" link in your account settings. We will verify your identity via your work-email and respond within 45 days.

7. Data Retention & Deletion

Upon account closure we delete all data within 30 days, except where legal retention applies.

8. Security Measures

9. International Transfers

Data may be processed in the United States or the European Union. We rely on Standard Contractual Clauses (SCCs) for EU transfers.

10. Children's Privacy

The Service is not intended for anyone under 16. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Policy. We will post the new version and notify account owners via email 30 days before changes take effect.

12. Contact Us

Questions or requests? Email [email protected] or write to:

Wittyfairy Productions LLC (D.B.A. CertiPing)
1401 21st St Ste 8014
Sacramento, CA 95811 USA

Thank you for trusting CertiPing to keep your workforce compliant and your data secure.