1. Introduction & Scope
Welcome to CertFlow (“we,” “us,” “our,” or “the Platform”). CertFlow is an automated certificate generation, personalization, and email distribution web application built for event organizers, educators, academic institutions, hackathon conveners, and community leaders.
This Privacy Policy describes how CertFlow collects, uses, stores, retains, and protects personal data when you interact with our website, create or log in to an account, upload certificate templates and participant rosters, connect an optional email provider such as the Gmail API, and generate or distribute certificates.
This policy applies to all visitors, registered organizers, and administrative users of CertFlow. Please read this Privacy Policy carefully alongside our Terms of Use to understand our data practices.
2. India Privacy Framework (DPDP)
This Privacy Policy is drafted with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable notified Digital Personal Data Protection Rules, 2025 in mind.
Under this statutory framework, we structure our practices around foundational data protection principles:
- Data Minimization: Collecting only personal data strictly necessary to fulfill requested certificate generation and delivery operations.
- Purpose Limitation: Processing personal data solely for specified, lawful purposes disclosed in this policy.
- Storage Limitation: Providing configurable lifecycle schedules to avoid indefinite retention of generated certificate files.
- Security Safeguards: Implementing reasonable technical and organizational safeguards to prevent unauthorized access or disclosure.
Regulatory Notice: The DPDP framework includes phased enforcement and commencement schedules. CertFlow continually aligns its technical architecture and governance practices with notified rules and statutory milestones.
3. Information We Collect
CertFlow collects only the categories of information that are actually needed and processed within our system architecture:
A. Account & Organizer Information
- Registration Data: Your full name, email address, organization name (optional), and encrypted password credentials managed through Supabase Authentication.
- Profile Identifiers: Internal user identifier (UUID), account creation and update timestamps, and user profile role (strictly managed as
useroradmin). - User Preferences: Configured default sender display name, reply-to email address, and preferred retention duration.
B. Participant & Recipient Data (Imported by Organizers)
- Spreadsheet Data: Participant full names, email addresses, and optional designation/role fields (e.g., “Participant,” “Winner,” “Volunteer,” “Speaker”) parsed from organizer-uploaded CSV or Excel files (
.csv,.xlsx). - Validation Status: Record parsing and syntax validation flags generated during roster import.
C. Certificate Templates & Design Configurations
- Uploaded Templates: Certificate background images or single-page PDF files uploaded by organizers to our storage bucket (
certificate-templates). - Layout Settings: Canvas visual coordinates (X and Y percentage positions, width, height), font selection, font size, text alignment, and text color configurations.
D. Generated Certificate Deliverables
- Rendered PDF Certificates: Output PDF credentials generated by merging the organizer’s template with individual participant details, stored in our storage bucket (
generated-certificates).
E. Event & Batch Information
- Batch Metadata: Batch/event name, creation timestamp, generation status, recipient count, user-selected retention period (7, 10, 15, or 30 days), and calculated UTC expiration timestamp (
expires_at).
F. Email & Dispatch Information
- Gmail Connection Metadata: Connected Gmail address, OAuth authorization status, token expiration timestamp, and authorized scope.
- Sending Jobs: Delivery records in our database (
email_jobs) tracking recipient name, recipient email, dispatch status (pending, sending, sent, failed), delivery attempts, error diagnostic messages, and completion timestamps.
G. Technical & Session Information
- Authentication Tokens: JSON Web Tokens (JWT) issued by Supabase Auth stored locally in your browser to maintain your authenticated session.
- Operational Server Logs: Standard HTTP request logs generated by our hosting infrastructure (Render) containing request methods, response status codes, and timestamps for operational monitoring and troubleshooting. We do not use third-party behavioral trackers or sell telemetry.
4. Purpose of Processing
We process personal and operational data strictly for specified, legitimate purposes:
- Account Management & Authentication: To create, maintain, and authenticate your organizer account, verify profile roles, and maintain secure session states.
- Participant Management: To parse and validate participant rosters uploaded by organizers.
- Certificate Generation: To merge template graphics with participant names and metadata to render personalized PDF credentials.
- Certificate Delivery: To generate and transmit certificate emails via the organizer’s connected Gmail account when the organizer initiates a send job.
- Delivery Reporting & Auditing: To display batch statistics, delivery logs, sent/failed statuses, and enable retry of failed dispatches.
- ZIP Archive Downloads: To compile and deliver downloadable ZIP archives of generated certificates to the organizer.
- Retention Management: To calculate expiration dates and enforce user-selected lifecycle policies for generated certificates.
- Security & Abuse Prevention: To prevent unauthorized system access, enforce role authorization, prevent spam transmission, and protect system integrity.
- Operational Analytics: To provide aggregate usage summaries (batch counts, delivery statistics) to organizers and system administrators for capacity planning and troubleshooting.
5. Participant & Recipient Data (Organizers as Data Fiduciaries)
A critical distinction applies to information handled by CertFlow:
Organizer Fiduciary Responsibility
Account Holder vs. Participant: CertFlow accounts are held by event organizers. When an organizer imports participant rosters (names and email addresses), the organizer acts as the Data Fiduciary (or Data Controller) under applicable law.
Lawful Basis & Authority: The organizer is solely responsible for ensuring that they possess the necessary consent, institutional authority, or other lawful basis to:
- Collect participant names and email addresses;
- Upload participant data to CertFlow for certificate generation; and
- Instruct CertFlow to transmit certificate emails to those participant addresses.
CertFlow’s Processing Role: CertFlow acts strictly as a technical data processor on behalf of the organizer. CertFlow:
- Does NOT market to participants or send unsolicited communications.
- Does NOT sell, rent, or trade participant records.
- Does NOT use participant records to build commercial profiles or train artificial intelligence models.
- Does NOT add participants to marketing mailing lists.
6. Google Sign-In (Authentication)
Organizers may register for or log in to CertFlow using Google Sign-In, orchestrated through Supabase Authentication.
- Data Received: When you use Google Sign-In, Google shares basic profile identity data: your Google user ID, primary email address, full name, and avatar URL.
- Purpose: This information is used solely to authenticate your identity, establish your CertFlow account, and populate your organizer profile.
- Strict Separation: Google Sign-In authentication is completely independent of the optional Gmail certificate-sending integration described in Section 7. Signing in with Google does not grant CertFlow permission to send emails from your account.
7. Google and Gmail Integration
CertFlow provides an optional integration allowing organizers to send generated certificate emails directly through their own connected Gmail account using Google’s official Gmail API.
Google API Limited Use & Scope Disclosure
Requested OAuth Scope: https://www.googleapis.com/auth/gmail.send
CertFlow explicitly restricts its Gmail integration to the gmail.send scope. This permission is used exclusively to create and dispatch outgoing certificate emails that you, as the organizer, specifically instruct the platform to send.
What CertFlow NEVER Does with Google Data:
- CertFlow does not read, scan, view, index, or analyze your Gmail inbox, emails, threads, or drafts.
- CertFlow does NOT access your Google Contacts, Google Drive, Google Calendar, or other unrelated Google accounts.
- CertFlow does NOT use Google user data for advertising, retargeting, or commercial profiling.
- CertFlow does NOT transfer or sell Google user data to data brokers or third parties.
- CertFlow does NOT use Google user data to train artificial intelligence or machine learning models.
CertFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A. Server-Side Token Storage & Protection
When you authorize Gmail sending, Google issues an OAuth authorization code. CertFlow exchanges this code server-side for access and refresh tokens. These tokens are stored in our backend database table (gmail_tokens), accessible exclusively through service-role backend controls, and are never returned in any API response or stored in client-side web browsers.
B. Disconnection & Revocation
You retain complete, real-time control over your connected Gmail account:
- One-Click Disconnect in CertFlow: You can disconnect your Gmail account at any time in CertFlow Settings. Clicking “Disconnect” executes an immediate server-side deletion of your stored OAuth tokens from our database.
- Google Security Settings: You can revoke CertFlow’s access at any time through your Google Account Security Settings.
8. Artificial Intelligence & Google Gemini Processing
CertFlow includes an optional AI-assisted feature to help organizers identify the candidate recipient name region on certificate templates.
Exact Data Sent to AI / Google Gemini
When an organizer uploads a certificate template, CertFlow may submit only the blank certificate background image (as a base64 inline image) and canvas dimensions to a Google AI service (Google Gemini) to detect visual coordinate boundaries for name placement.
Critical Privacy Confirmation:
- NO Participant Data is Sent: Participant names, participant email addresses, imported CSV/Excel rosters, and recipient records are NEVER sent to Google Gemini or any external AI model.
- Assistive Only: AI detection is purely an assistive layout suggestion. AI output can be imperfect or inaccurate. Organizers always have full visual control to inspect, drag, resize, or manually specify name coordinates on the interactive canvas before generating certificates.
9. Third-Party Service Providers
CertFlow relies on verified, enterprise-grade cloud service providers to operate its platform infrastructure. We share data with these providers solely as necessary to host, store, and execute the service:
- Supabase Inc.: Hosts our PostgreSQL database, session authentication system, and object storage buckets (
certificate-templatesandgenerated-certificates). - Google LLC: Provides Google Sign-In authentication, Google Gemini API for blank template coordinate detection, and the Gmail API for outgoing certificate email delivery.
- Render Services Inc.: Provides cloud application hosting, container execution, and server runtime infrastructure.
We do not partner with third-party ad networks, tracking aggregators, or behavioral advertising platforms.
10. Data Retention and Deletion
CertFlow incorporates user-configurable lifecycle controls to prevent unnecessary long-term storage of certificate deliverables:
- Configurable Batch Retention: When creating a batch, organizers choose a certificate retention duration of 7, 10, 15, or 30 days (default: 10 days).
- Calculated Expiration: The platform calculates an exact UTC expiration timestamp (
expires_at) based on the chosen window. - Current Operational Status (Marked Expired vs. Physically Deleted): When a batch reaches its expiration date, it is marked as “expired” in the database. Automated background physical purging of PDF files from object storage is controlled by the system setting
RETENTION_CLEANUP_ENABLED(which is currently set tofalsein production pending final audit validation). When this setting is inactive, expired batches remain marked expired, and physical deletion is performed during scheduled administrative maintenance or upon manual deletion. - Expiry Reminder Feature: When automated retention cleanup is enabled, the cleanup service is engineered to send an email notification to the organizer approximately 24 hours prior to expiration, reminding them to download their certificate ZIP archive before files are purged.
- Organizer Manual Deletion: Organizers can delete batches, participant lists, and uploaded templates directly from their workspace at any time.
- Audit Log Retention: Delivery audit logs, send timestamps, and error records may be retained in the database for operational troubleshooting, anti-abuse verification, and dispute resolution.
13. Operational & Admin Analytics
CertFlow includes internal administrative analytics to monitor platform health, capacity, and operational performance.
- Scope of Analytics: Analytics include aggregated counts of registered users, batches created, certificates generated, and email delivery statistics (sent vs. failed).
- No Secret Exposure: Administrative analytics never expose Google OAuth tokens, client secrets, passwords, or personal credentials.
- No Ad Targeting: Operational analytics are used solely for infrastructure scaling, troubleshooting, and abuse prevention, never for commercial profiling or advertising.
14. Technical & Security Safeguards
CertFlow employs reasonable technical, organizational, and administrative safeguards designed to protect personal data against loss, unauthorized access, alteration, or disclosure:
- Encrypted Transport: All data in transit is encrypted using Transport Layer Security (TLS/HTTPS).
- Server-Side Role Authorization: Administrative routes and sensitive endpoints are protected by server-side middleware (
requireAdmin) that independently validates profile roles against our database using service-role authentication. - Tenant Isolation: Database Row Level Security (RLS) policies and storage path isolation ensure that organizers can view and access only their own batches, templates, and participant records.
- OAuth Token Protection: Gmail OAuth tokens are stored in our backend database, accessible only via service-role server-side controls, and are never returned in API responses or transmitted to client browsers. Single-use cryptographic nonces and HMAC-signed state tokens protect OAuth callback flows against replay attacks and parameter tampering.
- Rate Limiting & Safety Allowances: Platform email sending allowances protect connected accounts and backend infrastructure from unauthorized bulk surges.
Security Notice: While we implement diligent, industry-standard measures, no online service or electronic storage system can guarantee absolute security or zero vulnerability. We urge organizers to maintain secure passwords and safeguard their account credentials.
15. Data Incident & Breach Notice
In the event of a verified security incident affecting personal data processed by CertFlow, we will take prompt remedial action to contain, assess, and mitigate the issue.
Where required under applicable Indian data protection laws and statutory regulations, CertFlow will notify affected users and competent regulatory authorities within prescribed timeframes, providing relevant details regarding the nature of the incident and recommended protective steps.
16. User Rights & Data Requests
Under applicable data protection principles, including India’s Digital Personal Data Protection (DPDP) Act, you have specific rights regarding your personal information:
- Right to Access: You may review your account information, batch records, and delivery history directly within your workspace.
- Right to Correction & Updating: You may update your profile name, organization, and preferences in Settings at any time.
- Right to Erasure: You can delete your batches, participant rosters, and certificate templates directly from your dashboard. To request complete account deletion, you may submit a request to privacy@getcertflow.in or support@getcertflow.in.
- Right to Withdraw Consent: You can disconnect your Gmail integration at any time with a single click in Settings, or revoke permissions in your Google Account security dashboard.
- Grievance Redressal: You have the right to submit privacy-related complaints and inquiries as detailed in Section 17.
Identity Verification: To safeguard your data, we may take reasonable steps to verify your identity before fulfilling sensitive data access or deletion requests.
17. Grievance Redressal
If you have concerns, inquiries, or grievances regarding CertFlow’s handling of your personal data, you may submit a grievance to our Data Protection & Grievance Desk at privacy@getcertflow.in.
Grievance Process:
- Submit your inquiry detailing the nature of your concern, your registered account email, and any relevant batch identifiers.
- Our team will acknowledge receipt of your request, verify your identity where appropriate, and conduct an internal review.
- We will provide a formal response or resolution within the timelines stipulated under applicable legal regulations.
18. Cloud & International Processing
CertFlow utilizes global cloud infrastructure provided by enterprise partners (including Supabase, Google, and Render). Depending on provider network routing and data center distribution, personal data may be hosted and processed in cloud facilities located outside India, subject to applicable laws, standard contractual protections, and enterprise security safeguards.
19. Children & Minors
Under India’s Digital Personal Data Protection Act, 2023, a “child” is defined as a person below the age of 18 years. CertFlow is intended for adult users aged 18 years or older. We do not knowingly solicit or accept account registrations from individuals below the age of 18, and we do not offer a parental consent mechanism for minors to register on the platform.
If we become aware that an account has been registered by a person under 18, we reserve the right to suspend or remove that account. Where an organizer uploads participant rosters that include student or minor names for institutional or event certificate generation, the organizer explicitly represents that they hold the necessary institutional authority, educational mandate, or other lawful basis to process and issue credentials to those individuals.
20. Policy Updates
We may update this Privacy Policy periodically to reflect enhancements to our features, operational practices, or evolving statutory requirements under Indian law.
When updates are made, the revised policy will be posted on this page with an updated “Last Updated” date at the top. For material changes that significantly impact your rights, we may provide prominent notice within the application or via email.
21. Contact & Inquiries
For privacy inquiries, data subject requests, or grievance redressal, please contact CertFlow:
CertFlow Privacy & Grievance Desk
For privacy inquiries, exercise of data principal rights, or grievance redressal, please contact our Data Protection & Grievance Desk:
Privacy & Data Requests: privacy@getcertflow.in
General Inquiries: info@getcertflow.in
Customer Support: support@getcertflow.in
Grievances and data requests are acknowledged and addressed in accordance with statutory response timelines under the Digital Personal Data Protection Act, 2023.