PRIVACY

Your register is your business.

Who operates this service

Aidan Maguire · Founder & CEO

Aidan Maguire trading as CertKeep (sole trader). Business address and contact details.

[email protected]

What is stored

Certkeep stores the person names, team names, course details, dates and references you enter, along with record identifiers, update times and the identifier of the account that owns them. We also record the terms version, account identifier and time of your explicit acceptance to keep a record of the service agreement. For native email sign-in, we store a generated account identifier, email address and creation time. One-use login links and session identifiers are stored as hashes. Email codes are protected with a keyed hash and a limit of five attempts per request, alongside expiry times and a browser-binding hash. Codes are entered on the page that requested them; the email can be read on any device. Codes and links expire after 15 minutes; sessions expire after 7 days. Expired login entries are removed after a one-day grace period on the next login request; expired sessions are removed on the next login request. Rate-limit entries use keyed hashes for email/browser identifiers and expire within 32 days, with cleanup on the next login request. We do not store passwords. If you choose the optional ChatGPT sign-in, we receive its account identifier and email instead. The two account types are separate; matching email addresses do not automatically link records. If you use paid billing, we store a Stripe customer identifier. Payment card details are handled by Stripe and are not stored in the register. Stripe’s billing portal lets you update billing name, email, address and phone details. It currently also offers shipping and tax-ID fields; CertKeep does not need these for the training register, and you should leave them blank unless genuinely required for your billing circumstances. Those optional billing fields are not copied into CertKeep’s database.

How it is used

Records are used to show your register, calculate expiry statuses and produce exports. Your account identifier separates your records from other accounts. Email may be supplied to Stripe to create your billing account. Native sign-in uses user-requested transactional emails through Resend when email sign-in is enabled. This version does not send marketing or renewal emails and uses optional, consent-based daily page/action counts and short visit funnels grouped by broad traffic source. The visit funnel uses a hashed random identifier; it does not include account IDs, email addresses or staff records. It does not use advertising trackers. Counts are not unique visitor or customer numbers and may include repeat visits, repeated actions and test activity. They do not prove a payment or marketing conversion. Requests identifying as common bots, crawlers, headless browsers or CertKeep monitoring checks are excluded, but this heuristic cannot reliably identify every bot.

Service providers and access

Hosting is provided through Sites; structured application data is stored using Cloudflare D1. Native email sessions are managed by CertKeep, Resend delivers sign-in codes and optional same-browser links when enabled, and ChatGPT supplies the optional provider sign-in. Registers are restricted by account and are not displayed in the public demo. The demo uses fictional examples. We do not claim UK-only storage. Stripe handles payments when enabled. Authorised service operators and infrastructure providers may access data to run, maintain or troubleshoot the service. The operator must confirm applicable processing arrangements and retention policies before commercial launch.

Control over your data

You can export all your records as CSV, edit them or delete individual records. Cancelling a subscription does not delete records. They remain available in your account unless you delete them. Contact the operator for account-level deletion and billing-record queries. Infrastructure backups or provider billing records may remain subject to their retention arrangements.

Free tools and spreadsheet drafts

The expiry planner, Labourer-card renewal calculator, single-record starter and spreadsheet register checker process your entries in the browser. Single-record starter entries stay in the current page until you choose Review & save; a refresh before that clears them. Its save action uses the same temporary draft and private review described below. The Labourer calculator keeps entered dates and a person/ID in the current page only until you choose to save. Its save action uses the same temporary browser draft and private review described below. Only the printed expiry is saved as a certificate date, not the one-year renewal boundary. Excel/CSV files and pasted cells stay in the browser during a free preview. If you choose to save a preview to your account, the selected rows are kept in local browser storage as a temporary draft, so they survive navigation and sign-in in another tab of the same browser. After sign-in, the rows are sent to CertKeep to check duplicates and account space; they are added to the private register only when you confirm the selection. The draft is usable for 30 minutes from creation. Expired drafts are removed when CertKeep is next open; a closed browser cannot run cleanup. Successfully saved selections are removed from the draft, while unselected rows remain until expiry or explicit discard. A draft is tied to this browser, not a signed-in identity: use a trusted device, check the destination account and discard the draft before sharing the device. The spreadsheet checker also keeps the assessed rows, date edits, review date, filters and correction notices in session storage for the current browser tab, for 30 minutes after the last preview change. This lets you refresh or return to the page without starting again. It does not keep the original workbook, other worksheets or raw pasted cells, and does not send preview data to the server. Fictional examples are not kept. Clear removes the tab preview. Expired copies are removed while the page is open or when CertKeep is next opened in that tab; a closed browser cannot run cleanup. Browser session restoration can restore tab storage, so use Clear on a shared device. Keeping the tab preview is not saving to an account. Calendar, CSV and printed/PDF exports remain on your device or paper under your control. The draft storage supports your requested save operation and is separate from optional analytics. Optional tool action counts use fixed labels only; certificate details, file names and result contents are not included.

Installing CertKeep

You can add CertKeep to a supported phone or computer from the installation page. It uses the same account and saved register as the website. This version needs an internet connection. Its service worker does not store copies of private pages or staff records, and does not queue offline edits. Browser installation stores the app’s name, icon and launch details on your device. Existing sign-in cookies, temporary drafts and preferences still follow the rules described here. A new installed-app context may have separate browser storage, so save an unfinished preview in the browser where you started it before switching. Removing the app shortcut does not delete your account. Optional install events count a shown prompt or a browser-reported installation, not a unique customer or a return visit.

Cookies and analytics choices

Sign-in uses essential cookies. While you sign in, the current browser tab temporarily keeps your email address, request reference and expiry in session storage so refreshing the page preserves the code form. The code itself is never stored there. These details are cleared on successful sign-in or when you change email, close the tab, or next open the page after expiry. Local preferences remember your analytics choice and whether you have paused decorative motion. The motion preference stays on your device and does not identify you. Optional page counts store a date, an approved page path and a total. Optional action counts store a date, a fixed action label (such as demo opened, terms accepted or record created), a broad source label (such as LinkedIn, search or a shared link) and a total. Both are retained for up to 90 days with cleanup on the next counted request. A temporary source label is kept in session storage for the current browser tab after you opt in, so navigating within CertKeep does not lose that label; it is removed when you decline optional counts. The source label comes from an approved campaign tag or the referring site’s domain. We do not store full campaign values, IP addresses, user agents, referring URLs, account identifiers or record contents in these counts. Earlier consent is not reused for the expanded visit funnel; we ask again. After you accept, an optional Secure, SameSite cookie holds a random visit identifier for 30 minutes. We retain only its hash, first approved page path, first broad source, timestamps and progress flags (sign-in, account created, record saved and free limit) for up to 30 days, with cleanup on the next counted request. The identifier is not linked to a name or account in the analytics table. We cap new visit rows at 2,000 per day, so excess visits may be missing. Your browser also stores your consent choice; declining clears the visit cookie. Confirmed owner accounts and browsers marked internal are excluded from new counts. An owner exclusion preference lasts one year on that browser, including when signed out. Historical aggregate totals cannot be reliably stripped of earlier tests. The private owner dashboard separately reads operational account/record counts and read-only Stripe subscription totals; these are not advertising analytics and do not expose staff records. Hosting providers may retain separate operational logs. Do Not Track and Global Privacy Control disable these optional counts. Use Cookie preferences at the bottom of any page to change your choice.

Optional Google Analytics

Google Analytics is a separate, unticked choice in Cookie preferences. Earlier permission for CertKeep’s own counts does not enable it. If you opt in, Google’s tag loads on public information pages and uses analytics cookies to measure page use. Google receives browser/device information and network information needed to receive the request. We configure a 30-day cookie expiry, disable advertising signals, and send page locations without query strings or fragments. We do not send staff records, account identifiers, emails or sign-in codes as analytics events. The tag is excluded from private workspaces, sign-in, the owner dashboard, the interactive demo and tools that accept staff entries, including the calculator embedded in the Labourer guide. Google’s retention and processing settings are managed in the Analytics property; its processing may occur outside the UK. You can withdraw permission in Cookie preferences, which disables further measurement and clears the Google analytics cookies available to this site. Do Not Track, Global Privacy Control and the internal-browser exclusion disable loading. Google’s privacy policy.

Billing events

To prevent duplicate checkout requests, we retain one checkout-attempt entry per account: the chosen price, random request key, creation time and temporary processing lock. We retain Stripe event identifiers, event types and receipt times for up to 30 days, with cleanup when the next event arrives. We do not store webhook payloads or card data.

Use only necessary information

You may use initials or an internal staff identifier instead of a full name. Team and reference fields are optional. Do not enter medical information, identity documents, passwords or other sensitive details. Store a certificate reference rather than the certificate document. Use the service only for records you are authorised to manage.