Certly

Privacy Policy

Last updated: May 25, 2026

Plain-language summary: Certly only collects what merchants and their customers explicitly give us — Shopify session info, uploaded resale certificates, and the data extracted from them. We don't sell data, we don't share it with advertisers, and merchants can delete a shop's data at any time by uninstalling.

1. Who we are

Certly is a Shopify app that helps B2B merchants collect and manage US resale and exemption certificates. This policy describes how we collect, use, and protect personal data when merchants install the Certly app on their Shopify store and when their customers upload certificates through Certly.

For privacy questions, contact us at privacy@certly.app.

2. What we collect

From merchants (you), via Shopify:

From your customers, when they upload a certificate:

We do not collect payment information from customers — Certly never handles credit cards. Merchant subscription payments are processed by Shopify.

3. How we use the data

We do not use customer data for advertising, profiling, or any purpose unrelated to the service. We do not sell data.

4. Sub-processors we share data with

To operate Certly, we share data with the following providers:

5. Where data is stored

Application data and uploaded files are stored in the United States. We use industry-standard encryption in transit (HTTPS) and at rest. Certificate files are stored with hashed filenames and access is restricted to authenticated requests on behalf of the owning merchant.

6. Data retention

7. Your rights (and your customers' rights)

Depending on your jurisdiction, you and your customers may have the right to access, correct, delete, or export personal data we hold, and to object to or restrict its processing.

8. Cookies

Certly uses a session cookie from Shopify to authenticate merchant users inside the Shopify admin. We don't use any third-party tracking or analytics cookies on the merchant admin pages.

9. Children

Certly is a B2B tool used by businesses and their business customers. We don't knowingly collect data from anyone under 16.

10. Changes

We'll post a notice on this page when we make material changes to this policy and update the "last updated" date above.

Disclaimer: This privacy policy is a working draft provided as a starting point. Before launching publicly, have a qualified attorney review it against your jurisdiction's requirements (GDPR, CCPA, US state privacy laws, etc.).