Back to Home
CertFlow

Privacy Policy

Last Updated: July 23, 2026

1. Overview & Commitment

CertFlow ("we," "our," or "us") is committed to protecting your privacy. CertFlow is an offline-first event attendance management and certificate generation platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and services.

2. Information We Collect

To provide event management and certificate issuance services, we process the following types of information:

  • Google Account Data: When you sign in via Google OAuth, we receive your primary email address, full name, and profile picture URL.
  • Event & Attendee Data: Attendee names, email addresses, payment status, and verification logs that event organizers upload via Google Sheets or input into CertFlow.
  • Google OAuth Access Tokens: Encrypted tokens required to access authorized Google Sheets and send emails via the Gmail API on behalf of event organizers.
  • Attendance Logs: Timestamps and session IDs recorded during offline or online QR code scanning.

3. Google API Services User Data Policy Compliance

CertFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Gmail API Access (`gmail.send`): Used strictly to send event QR tickets, receipts, and completion certificates directly from the organizer's email address. We never read, scan, store, or analyze your personal emails.
  • Google Sheets API Access (`spreadsheets`): Used strictly to sync attendee lists and update verification statuses in spreadsheets chosen explicitly by the organizer.
  • No AI Model Training: Google Workspace user data obtained through Google APIs is never used to train, develop, or improve AI/ML models.
  • No Transfer or Sale: User data obtained via Google APIs is never sold, rented, or transferred to third parties for advertising or tracking purposes.

4. How We Use Your Information

We use the collected information exclusively to:

  • Authenticate users and manage organization access control (RBAC).
  • Sync attendee rosters with connected Google Spreadsheets.
  • Generate and issue unique QR codes and PDF certificates.
  • Dispatch event passes and certificates via Gmail API.
  • Anchor anonymized SHA-256 certificate hashes on the Polygon blockchain for public verifiability.

5. Data Storage & Security

We implement industry-standard security measures to safeguard user data:

  • OAuth tokens and sensitive credentials are encrypted at rest using strong cryptographic standards.
  • Client-side QR scanning operates offline using IndexedDB mirrors, ensuring data persists securely until synced.
  • All network transport is secured using TLS/HTTPS encryption.

6. Data Sharing & Third Parties

We do not sell your personal data. We only share data with service providers essential to running CertFlow (such as PostgreSQL database hosting, serverless infrastructure, and blockchain nodes for hash anchoring).

7. Your Rights & Data Deletion

You have full control over your data. You may:

  • Disconnect CertFlow's access to your Google Account at any time via your Google Security Settings.
  • Request full export or hard deletion of your workspace data by contacting our support team.

8. Contact Us

If you have questions, feedback, or data privacy requests regarding this Privacy Policy, please contact us at:

Email: support@certflow.app

CertFlow © 2026 — Reliability-First Event Infrastructure