Privacy Policy
Last updated: May 22, 2026
cert2hire (“we”, “us”) helps individuals prepare for IT certification exams. This policy explains what data we collect, why we collect it, and what choices you have.
What we collect
- Account information: name, email address, password hash, and the list of certifications you select during onboarding.
- Study activity: exams you take, scores, time spent per question, flashcards reviewed, AI tutor messages, and certificates of completion.
- Purchases and subscriptions: we work with Stripe to process payments. We store the amount, currency, product, status, and the Stripe identifiers. We never receive or store your full card number.
- Technical data: IP address, browser user-agent, and pages visited — used for debugging, security, and aggregate analytics.
Why we collect it
- To operate the service — create your account, save your progress, deliver content you've purchased.
- To improve the service — anonymous aggregate analytics on which features are used, which questions are too hard or too easy, what content is most watched.
- To communicate — transactional emails for password reset, payment receipts, and exam confirmations. We do not send marketing emails without your explicit opt-in.
Who we share it with
We share the minimum necessary data with the following service providers:
- Supabase — hosts our database and authentication.
- Stripe — processes payments. They receive your name, email, and payment details directly.
- Anthropic — powers the AI tutor. Your tutor messages are sent to Claude for generating responses; they are not used to train models.
- Vercel — hosts the website.
We do not sell your data to third parties.
How long we keep it
We keep your account data for as long as your account is active. Study history is retained so you can see your progress over time. You can request deletion at any time (see Your rights below).
Your rights
Depending on where you live (notably the EU, UK, and California), you have the right to:
- Access — request a copy of the data we hold about you.
- Correct — update inaccurate or incomplete data through your profile page.
- Delete — request permanent deletion of your account and all related data.
- Object — opt out of any non-essential analytics processing.
- Portability — receive your data in a machine-readable format.
To exercise any of these rights, email privacy@cert2hire.com. We aim to respond within 30 days.
Cookies
We use cookies for the following purposes:
- Essential cookies — login session, security tokens, payment flow. Cannot be disabled.
- Analytics cookies — privacy-friendly aggregate stats on which pages are popular, signup conversion rate. No personal identifiers stored. You can opt out via the cookie banner.
Security
Passwords are hashed using industry-standard algorithms (bcrypt). All connections are HTTPS. Database access is restricted by row-level security policies. Backups are encrypted at rest.
If we ever experience a data breach affecting your account, we will notify you within 72 hours.
Children
cert2hire is intended for adults aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe a child has signed up, contact us and we will delete the account.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you via the email address associated with your account.
Contact
For any privacy-related question: privacy@cert2hire.com
For general support: support@cert2hire.com