Privacy Policy
Last updated: 17 July 2026
Who we are
Crefora is operated by Mandalar Ltd, a company registered in England & Wales (company number 17167234). Mandalar Ltd is the data controller for personal data processed through this service. You can reach us at [email protected].
Data we collect
When you create an account we store your name, email address, and a hashed password (we never store passwords in plain text). While you use the service we keep your subscription tier, billing state, and monthly usage counters (documents generated, AI designs used). If you upload branding assets — logos, signatures, favicons — these are stored so they can be applied to your documents. Standard server logs (IP address, browser type, timestamps) are kept briefly for security and rate limiting.
Data that stays in your browser
Certificate design happens on your device. Recipient lists (CSV files), names, dates, and the documents you render are processed in your browser and are not sent to our servers, with two exceptions you control: if you generate a document with a verification QR code, the details shown on its public verification page (recipient name, document title, serial number, issuer) are stored so the page can display them; and if you use email delivery, the document and recipient email address are stored temporarily in order to send them.
How we use your data
We use your data to provide the service: authenticating you, enforcing plan limits, processing payments, sending transactional email (account verification, password resets, certificate delivery), and keeping the service secure. We do not sell personal data, and we do not use your data or your documents to train AI models.
Third-party processors
We share the minimum necessary with providers who help run the service: Stripe (payment processing — we never see your card number), Resend (email sending), Supabase (database hosting), Vercel (application hosting), Cloudflare (file storage for uploaded assets and temporarily stored documents), OpenAI (only the text prompt you type when generating an AI background design), and Sentry (error monitoring). Each receives only what it needs to perform its function.
Legal bases
We process your data under UK GDPR on the bases of contract (providing the service you signed up for), legitimate interests (security, fraud prevention, service improvement), and legal obligation (tax and accounting records for payments).
Retention and deletion
Account data is kept while your account is active. You can permanently delete your account and associated data at any time from your account settings — this removes your profile, branding assets, verification records, and delivery history. Payment records are retained as required by UK tax law (typically six years). Temporarily stored documents for email delivery are deleted after sending.
Your rights
Under UK GDPR you have the right to access, correct, export, restrict, object to the processing of, and erase your personal data. Most of these you can exercise directly from your account settings; for anything else, email [email protected] and we will respond within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office (ico.org.uk).
Cookies
We use only essential cookies: a session cookie to keep you signed in and a CSRF token to protect forms. We do not use advertising or cross-site tracking cookies.
Changes to this policy
If we make material changes we will update the date above and, where appropriate, notify you by email before the changes take effect.