Privacy Policy
Effective July 3, 2026 · Certibee, a service of Active Equities Inc.
In plain language: Your credential records are private to you by default. Nothing is shared until you create a share link, connect with someone, or share a credential into a team — and you can revoke those. We don't sell your data, and we don't let AI providers train on your documents.
Certibee is operated by Active Equities Inc., 421–7th Ave SW, Unit 1600, Calgary, Alberta T2P 4K9, Canada (“Certibee,” “we,” “us”). This Policy explains how we collect, use, share, and protect your information when you use the Certibee websites and mobile apps (the “Service”). We are accountable for personal information under our control; our designated Privacy Officer can be reached at privacy@certibee.com.
1. Information we collect
- Account data: your email address and, if you use a sign-in provider (Apple/Google), the identifier it shares with us.
- Credential data: the documents and images you upload and the fields associated with them (credential name, issuer, dates, license/credential numbers, holder name). This can include sensitive professional information — it is the point of the Service, and it stays under your control.
- Profile data: any display name, headline, bio, or photo you add.
- Sharing data: share links you create, connections you make, teams you join, credentials you grant to teams, and related access events.
- Billing data: your plan and subscription status. Card details go directly to Stripe (web) or Apple (iOS) — we never see or store full card numbers.
- Usage & device data: log data, device type, approximate location (from IP), and product-analytics events used to operate and improve the Service.
2. How we use information (our purposes)
We collect and use personal information only for these purposes: to provide and operate the Service; to extract data from documents you ask us to scan; to track expiries and send the reminders you enable; to power the sharing and team features you initiate; to process payments and manage subscriptions; to secure the Service and prevent fraud and abuse; to provide support; to improve features and understand usage; and to comply with law. We do not use your information for purposes incompatible with these without asking you first.
3. AI / document processing
When you scan a document, its contents are transmitted to our AI processor (currently Google’s Gemini API) to extract suggested fields, which are returned to you for review before anything is saved. Our processors are engaged under terms that restrict them to providing the service to us. We do not permit your credential documents to be used to train third-party AI models, and we do not use them to train models of our own.
4. Teams: what managers can see
If you join a team, its managers see your display name and role — and only the credentials you explicitly share (“grant”) to that team, including their name, issuer, expiry date, and status. Managers never see your other credentials or your documents unless you share them. You can revoke a grant at any time; revocation removes the credential from the team’s view going forward. The organization that runs a team is responsible for its own use of information members share with it.
5. When we share information
We do not sell your personal information, and we do not share it for third-party advertising. We share it only:
- At your direction — with recipients of your share links, your connections, and teams you share credentials into.
- With service providers (subprocessors) who operate parts of the Service under contract:
| Provider | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, authentication, file storage (encrypted) | United States (us-east-1) |
| Vercel | Website and application hosting | United States (global edge) |
| Google (Gemini API) | AI extraction of fields from documents you scan | United States |
| Stripe | Payment processing and subscription billing | United States / Canada |
| Apple | In-app purchases on iOS (when you buy through the App Store) | United States / your region |
| Resend | Transactional email (sign-in links, invites, expiry reminders) | United States |
| Credly (Pearson) | Badge verification — only when you import a Credly badge | United States |
- For legal reasons — to comply with applicable law or valid legal process, enforce our Terms, or protect rights and safety.
- In a business transfer — if Certibee is acquired or merged, subject to this Policy.
6. Storage, security & data location
Your data is stored in the United States (see the table above) and protected by encryption in transit and at rest, database row-level security (by default, only your account can read your records), private document storage with short-lived signed access URLs, and revocable, high-entropy share tokens. No system is perfectly secure and we cannot guarantee absolute security — but privacy-by-default is how the Service is built.
7. Retention & deletion
We keep your information while your account is active. You can delete individual credentials at any time, and you can delete your entire account from the Account page (or in the app) — deletion is self-serve and immediate: your credentials, documents, profile, share links, and team grants are erased, except records we must keep for legal, billing, or security purposes (kept no longer than needed). Recipients may retain copies of information you shared with them before revocation. Backups are purged on a rolling schedule.
8. Your rights & choices
You can access, correct, and export your data from the Service directly. Depending on where you live, you also have legal rights — under Canada’s PIPEDA and Alberta’s PIPA, the EU/UK GDPR, or US state laws (e.g., CCPA/CPRA) — to request access, correction, deletion, portability, or to object to or restrict certain processing, and to withdraw consent. Write to privacy@certibee.com; we respond within the time required by applicable law and will not discriminate against you for exercising your rights. If you are unsatisfied with our response, you may complain to your regulator — in Canada, the Office of the Privacy Commissioner of Canada (oipc.ab.ca for Alberta’s OIPC); in the EU/UK, your data-protection authority.
9. Breach notification
If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and report to the appropriate regulator (in Canada, the OPC) as required by law, and keep records of all breaches.
10. International transfers
We are a Canadian company and our processors store data primarily in the United States. Where the GDPR/UK GDPR applies to a transfer, we rely on appropriate safeguards such as Standard Contractual Clauses with our subprocessors.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
12. Cookies & analytics
We use only the cookies and local storage needed to keep you signed in and operate the Service, plus privacy-respecting product analytics to understand feature usage. We do not use advertising cookies or cross-site trackers. You can control cookies in your browser; signing in will not work without them.
13. Changes & contact
We may update this Policy; material changes will be notified in-app or by email before they take effect. Privacy Officer, Active Equities Inc. — privacy@certibee.com· 421–7th Ave SW, Unit 1600, Calgary, Alberta T2P 4K9, Canada.
See also our Terms of Service.