Privacy Policy

We engineered Credinberg for organizations and enterprises that hold recipient trust to the highest standard. This policy provides full transparency into the data we process, our cryptographic safeguards, and your rights.

Effective: September 10, 2026·

Overview & Scope

Credinberg (“Credinberg,” “we,” “our,” or “us”) operates the digital credential issuance, management, and verification platform available at credinberg.com. This Privacy Policy governs our collection, processing, storage, and transfer of personal data when you interact with our website, application workspaces, public verification portals, and badge APIs.

In the context of international data protection frameworks, including the European Union General Data Protection Regulation (GDPR Art. 28) and the California Consumer Privacy Act (CCPA/CPRA):

  • Data Processor Role: When organizations, universities, and issuers upload recipient lists or issue badges, the customer is the Data Controller, and Credinberg acts strictly as the Data Processor carrying out verifiable credential baking and delivery under organization instruction.
  • Data Controller Role: For direct account holders (issuers, administrators, earner passport holders), Credinberg acts as the Data Controller solely for authentication, billing, account security, and service delivery records.

Information We Collect

We strictly enforce the principle of Data Minimization (GDPR Art. 5(1)(c)). We only gather personal data directly necessary to deliver cryptographically verifiable credentials and maintain service integrity.

  • Account & Identity Credentials: Legal name, business email address, job title, encrypted password hashes, and federated OAuth profile details.
  • Organization Profile: Organization name, website domain, custom handle, public contact email, and official branding logos.
  • Credential & Recipient Data: Recipient names, recipient email addresses, issue dates, expiration dates, achievement narratives, criteria rubrics, and skills tags uploaded by issuing organizations.
  • Billing Information: Payment transactions are handled securely by Stripe, Inc. We do not store full credit card numbers or banking secrets. We retain only Stripe Customer IDs and invoicing history.

How We Process Data

We process data solely to execute the core functionalities of the Credinberg platform:

  • Credential Minting & Baking: Injecting Open Badges 2.0 / 3.0 cryptographic metadata assertions directly into image files (PNG chunk injection / SVG metadata tags).
  • Public Verification Portals: Serving instant validation requests when third-party verifiers, employers, or organizations scan badge QR codes or open verification links.
  • Transactional Notifications: Transmitting credential claim invitations, credential expiry reminders, and security alerts via Resend.
  • Platform Security & Rate Limiting: Monitoring request volumes against Cloudflare WAF to prevent credential farming, brute force attacks, and system tampering.

Credinberg never sells, rents, or brokers your personal data to advertisers or third parties, and never trains public AI models on your organization’s recipient rosters, certificates, or educational records.

Cryptographic Identity Protection & Open Badges

In traditional credential platforms, publishing a certificate publicly on the web exposes the recipient’s plain-text email address to web scrapers and spammers. Credinberg eliminates this risk by implementing the open Open Badges Specification for cryptographic recipient hashing.

By applying a random 128-bit cryptographic salt and a one-way SHA-256 hash, relying third-party employers can mathematically prove that a given email matches the credential without the plain-text email ever being stored in public JSON-LD assertions.

Authorized Subprocessors & Cloud Infrastructure

To ensure zero-trust security and high availability, Credinberg partners with enterprise-tier infrastructure providers bound by strict Data Processing Addendums (DPAs):

SubprocessorPurposeRegionCertifications
Supabase, Inc. (AWS)Database hosting & Row-Level Security isolationUnited StatesSOC 2 Type II, ISO 27001
Cloudflare, Inc.R2 object storage for badge assets, edge caching & WAFGlobal Edge NetworkSOC 2 Type II, PCI-DSS
Vercel, Inc.Serverless compute runtime & edge deliveryGlobal EdgeSOC 2 Type II, ISO 27001
Stripe, Inc.Subscription billing and merchant payment settlementUnited StatesPCI-DSS Level 1
Resend, Inc.Transactional email delivery for badge claims & alertsUnited StatesSOC 2 Type II
PostHog, Inc.Product usage analytics & feature adoption (session recording disabled)United States / EUSOC 2 Type II, EU-US DPF
Microsoft CorporationMicrosoft Clarity UX telemetry & heatmaps with masked sensitive dataUnited StatesISO 27001, SOC 2 Type II
Google LLCGoogle Tag Manager script orchestration & telemetry containerizationUnited StatesISO 27001, SOC 2 Type II

Data Retention, Purging & Lifecycle

We store personal data strictly for as long as necessary to maintain active digital credentials or fulfill legal obligations:

  • Active Accounts: Credentials remain publicly verifiable while the issuing organization or earner account remains in good standing.
  • Deleted Workspaces: When an organization initiates deletion via account settings, associated templates, badges, and rosters are permanently removed in accordance with data lifecycle policies.
  • Disaster Backups: Encrypted database snapshots and transaction archives are retained on standard automated rolling backup schedules for disaster recovery.

Cookies & Local Storage Policy

Credinberg does not deploy third-party advertising cookies, cross-site trackers, or marketing pixels. We use essential storage exclusively:

  • Session Authentication: Cryptographically signed, HttpOnly, Secure, SameSite=Lax authentication cookies used strictly to authenticate user requests.
  • Client State (localStorage): Non-sensitive UI preferences including workspace view modes, dashboard table filters, and cross-tab session synchronization tokens.

Global Privacy Frameworks & Statutory Rights

Credinberg operates as a globally compliant verifiable credential infrastructure. We enforce universal privacy rights across all jurisdictions, ensuring sovereign data ownership regardless of where you reside.

European Union & United Kingdom (GDPR)EU / UK

Full compliance with EU Regulation 2016/679 and UK Data Protection Act 2018. Includes rights of access, rectification, erasure (“Right to be Forgotten”), data portability, and restriction of processing under lawful bases (Contract, Legitimate Interest, Consent).

California (CCPA / CPRA)USA

Notice at Collection & No Sale of Data: Credinberg does not sell personal information for monetary consideration. Under the California Consumer Privacy Act (CCPA/CPRA), the deployment of third-party performance analytics may be classified as a “share” of data. California consumers have the statutory right to opt out at any time by selecting “Do Not Sell or Share My Info” in our website footer or through our on-demand Cookie Preferences modal.

India (DPDP Act 2023)INDIA

Under the Digital Personal Data Protection Act, 2023, data principals have the right to access summaries of digital personal data, seek correction, easily withdraw consent at any time via cookie settings, and access grievance redressal mechanisms.

Brazil (LGPD - Law No. 13.709/2018)BRAZIL

Brazilian holders of personal data maintain sovereign rights under Article 18, including confirmation of processing, anonymization, blocking or elimination of unnecessary data, and information on shared entities.

Canada (PIPEDA)CANADA

Complies with fair information principles governing collection, use, disclosure, accuracy, and safeguards for commercial electronic transactions across Canadian provinces.

Asia-Pacific (PDPA Singapore & Sri Lanka No. 9/2022)APAC / LK

Adheres to Singapore Personal Data Protection Act and Sri Lanka's Personal Data Protection Act No. 9 of 2022. Legitimate processing standards, retention limitations, and transparent data subject access rights are enforced across all regional accounts.

Universal Self-Service Rights:

  • Right to Access & Portability: Download a machine-readable JSON-LD or CSV copy of all credentials and profile records directly from your Passport or Dashboard.
  • Right to Rectification: Correct inaccurate profile records or organization metadata through workspace settings.
  • Right to Erasure: Permanently delete your account and records via self-service account settings or by emailing privacy@credinberg.com.
  • Right to Restrict Processing: Badge earners may toggle credentials to “Private” inside their Passport, instantly delisting the assertion from public search.

Educational Records & Student Privacy

When educational organizations utilize Credinberg to issue credentials to students, Credinberg acts as a service provider processing records solely on behalf of the issuing organization to provide verifiable digital credentials. We do not sell or reuse student data for commercial advertising or marketing.

Direct account registration requires individuals to be at least 18 years of age. Organizations issuing badges to students under the age of majority must secure requisite student or parental consent in accordance with applicable education and child privacy laws.

Contact & Policy Updates

We review and update this Privacy Policy periodically. When material amendments occur, we provide notification via registered email or a banner in the dashboard.

Privacy Office & DPO: privacy@credinberg.com

General Legal Inquiries: legal@credinberg.com

Next Document

Terms of Service

Examine terms governing account registration, acceptable use, billing, and platform verification.

Read Terms of Service

Credinberg Global Governance & Compliance Office

Authoritative legal and privacy policy repository. Inquiries may be directed to legal@credinberg.com.