Legal

Privacy Policy

Version 1.0 — Effective July 15, 2026

This policy explains how CertForge collects, uses, and protects your information.

1 Who We Are

CertForge, LLC is a Colorado limited liability company that provides certificate lifecycle governance software. Our registered address is in Parker, Colorado, USA. We operate the Service at certgov.app.

For data protection purposes, CertForge acts as the data processor for certificate and operational data you upload to the Service, and as the data controller for account and usage data described in this policy.

For questions about this policy, contact us at privacy@certforge.xyz.

2 Information We Collect

Account information: When you create an account, we collect your email address and (optionally) your organization name. We store a hashed version of your password — we never store it in plaintext.

Certificate and configuration data: Data you upload to the Service, including certificate files, private key references (if stored), domain names, CA configurations, and approval workflow records. This data is yours and is processed only to provide the Service.

Usage data: Information about how you interact with the Service, including log entries, feature usage, approval actions, and audit trail events. This helps us operate, secure, and improve the Service.

Payment information: Payment details for paid subscriptions are collected and stored by our payment processor (Stripe). CertForge does not store full card numbers.

Communications: If you contact us for support or otherwise, we retain the content of those communications.

3 How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service
  • Authenticate users and secure accounts
  • Send transactional emails (email verification, certificate expiry alerts, approval notifications)
  • Process payments and manage subscriptions
  • Respond to support requests and communications
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not use your certificate data or Customer Data to train machine learning models or for any purpose unrelated to providing the Service.

4 Legal Basis for Processing (EU / UK Users)

Where the GDPR or UK GDPR applies, we process personal data under the following legal bases:

  • Contract performance: Processing your account information and Customer Data to provide the Service you have subscribed to.
  • Legitimate interests: Operating, securing, and improving the Service; fraud prevention; and communicating service updates.
  • Legal obligation: Retaining records as required by applicable law.
  • Consent: Where we send optional marketing communications (you can opt out at any time).

5 How We Share Information

We do not sell your personal data. We share information only in the following circumstances:

  • Service providers (sub-processors): Trusted third parties who help us operate the Service, such as cloud hosting providers (Akamai/Linode), email delivery services, and payment processors (Stripe). These parties process data only under our instruction and are subject to our DPA.
  • Certificate authorities: When you use the Service to request certificates from a public or private CA, the CA receives your CSR (certificate signing request), which includes domain names and organization details. This is inherent to the certificate issuance process.
  • Legal requirements: Where required by law, court order, or to protect the rights and safety of CertForge, our customers, or the public.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you in advance of any such transfer and provide opt-out options where required by law.

6 Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. When you close your account:

  • Account, certificate, and configuration data is deleted within 90 days
  • Aggregated or anonymized usage data may be retained for up to 12 months for service improvement
  • Billing records may be retained for up to 7 years for accounting and legal compliance

You can export your data at any time via the Service before closing your account.

7 Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Password hashing using bcrypt
  • Tamper-evident audit logging for all certificate and approval actions
  • Role-based access controls and API key scoping
  • Regular backups with integrity verification

No security measure is perfect. If we become aware of a security incident affecting your data, we will notify you without undue delay in accordance with our Data Processing Agreement.

8 International Data Transfers

CertForge is based in the United States. If you are located outside the US, your data may be transferred to and processed in the US. We take steps to ensure such transfers comply with applicable data protection law, including using EU Standard Contractual Clauses where required for EU/UK personal data.

EU region customers who select the EU deployment region have their data stored on infrastructure located in the European Economic Area (Frankfurt, Germany). Certain operational data (e.g., billing, email delivery) may still be processed by US-based sub-processors under appropriate safeguards.

9 Your Rights

Depending on your location, you may have rights regarding your personal data, including:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data, subject to legal retention obligations
  • Portability: Receive your data in a machine-readable format
  • Objection / Restriction: Object to or request restriction of certain processing activities
  • Opt out of marketing: Unsubscribe from any optional marketing communications at any time

To exercise any of these rights, email us at privacy@certforge.xyz. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

10 Cookies and Analytics

The CertForge application uses essential session cookies required for authentication. We do not use third-party advertising cookies in the application.

The marketing website (certgov.app) uses Google Analytics to understand visitor behavior in aggregate. You can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.

11 Children's Privacy

The Service is intended for business users and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will promptly delete it.

12 Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the Service at least 30 days before the changes take effect. The effective date at the top of this page reflects when the current version was last updated.

Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

Questions about your privacy?

Contact our privacy team — we'll respond within 2 business days.

privacy@certforge.xyz