Effective August 8, 2026 · Version 1.0
Privacy Policy
Part of the Oricert Group, Inc. Terms of Service, Privacy Policy & Data Processing Notice. Original section numbers from that document are preserved.
4. Privacy Policy
4.1 Scope
This Privacy Policy explains how Oricert Group, Inc. collects, uses, stores, protects, shares, and retains personal information (“personal data” or “PII”) in connection with the oricert.com platform and all Oricert services.
This Policy applies to:
- Sellers who create accounts and purchase Oricert Trusted Seals
- Buyers or verifiers who visit public verification pages
- Business partners, MFI institutions, and API users
- All visitors to oricert.com
Oricert Group, Inc. is the data controller for all personal data processed through the platform, as defined under the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
4.2 What Personal Data We Collect
The table below provides a complete disclosure of all personal data Oricert collects, the purpose of collection, the legal basis for processing, and how long we retain it.
| PII Category | Data Collected | Purpose | Legal Basis | Retention |
|---|---|---|---|---|
| Identity | Full name | Issue certificate, verify ownership | Consent (Art. 6(1)(a) GDPR) | Life of seal + 7 years |
| Contact | Email address | Deliver certificate PDF, service notices | Consent / Contract | Life of seal + 7 years |
| Financial | Payment method (processed by Stripe — Oricert never stores card data) | Process payment | Contract (Art. 6(1)(b)) | Stripe retains per their policy |
| Blockchain Identity | Polygon wallet address (0x...) | Anchor seal on-chain, enable transfers | Consent / Legitimate interest | Permanent (pseudonymous, on-chain) |
| Item Evidence | Up to 10 photos of the certified item | Visual evidence of item condition at certification | Consent | Life of seal (deletable on request) |
| Item Description | Brand, model, serial number, manufacture date, country of origin, material, color, dimensions, condition, appraisal value, provenance notes | Populate certificate fields; anchored in SHA-256 hash on Polygon | Consent | Life of seal (deletable on request) |
| Technical | IP address hash (not raw IP), browser type, timestamp of consent | Security, fraud prevention, consent record | Legitimate interest (Art. 6(1)(f)) | 90 days |
| Usage | Pages visited, actions taken within oricert.com | Platform improvement, debugging | Legitimate interest | 12 months |
4.3 Data We Do NOT Collect
Oricert does not collect or store:
- Payment card numbers, CVV codes, or full bank account details (processed exclusively by Stripe)
- Government-issued identification numbers (SSN, passport, driver’s license)
- Biometric data of any kind
- Health or medical information
- Raw IP addresses (we hash IP addresses before storage for security purposes)
- Data from children under 13. The platform is not intended for users under 18.
4.4 How We Use Your Personal Data
We use your personal data for the following specific, disclosed purposes only:
- Certificate Issuance: To generate and deliver your Oricert Certificate of Authenticity, including your name, item details, and issue date on the certificate
- Blockchain Anchoring: To compute the SHA-256 hash of your certificate data (including a unique per-seal salt stored off-chain) and record that hash on the Polygon blockchain. Your name, email, and raw item data never touch the blockchain.
- Evidence Storage: To securely store your item photos encrypted on AWS S3 using AES-256 server-side encryption with customer-managed AWS KMS keys
- Verification Service: To display item details, photos (via time-limited presigned URLs), and blockchain proof on the public verification page when a buyer or verifier accesses it
- Communication: To email you the certificate PDF, service updates, and administrative notices. We do not send marketing emails without separate opt-in.
- Platform Security: To detect fraud, abuse, and unauthorized access using hashed IP addresses and access logs
- Legal Compliance: To maintain records required by applicable law, respond to lawful legal process, and enforce our Terms of Service
4.5 Cryptographic Architecture — How PII Stays Off-Chain
Oricert’s architecture is designed to protect your privacy while providing immutable blockchain proof. Here is exactly how it works:
- Step 1 — Your data is collected off-chain. All PII (name, email, photos, item description) is stored in encrypted off-chain systems (PostgreSQL via Supabase, AWS S3) under your sole-use AES-256 encryption key.
- Step 2 — A SHA-256 hash is computed. All certificate fields are combined with a unique per-seal random salt (stored only off-chain) and hashed. The result is a 64-character fingerprint: e.g., 0x503977c8...97a0.
- Step 3 — Only the hash is recorded on Polygon. The smart contract records: seal_id (pseudonymous), cert_hash (not PII), owner_wallet (pseudonymous), and block timestamp. No names, emails, photos, or descriptions ever touch the blockchain.
- Step 4 — On erasure request, the salt is deleted. Deleting the off-chain salt permanently breaks the linkage between the on-chain hash and any personal data. The hash remains on Polygon but is now a disconnected string referencing nothing — satisfying GDPR Article 17 and CCPA right to deletion.
EDPB Compliance Note
5. Who We Share Your Data With
Oricert does not sell, rent, or trade your personal data. We share it only with the following categories of third parties, each bound by a Data Processing Agreement (DPA) and contractual privacy obligations:
5.1 Data Processors (Vendors)
| Vendor | Service | What They Receive | Their Privacy Policy |
|---|---|---|---|
| AWS (Amazon Web Services) | Encrypted file storage (S3) + encryption key management (KMS) | Encrypted item photos, certificate PDFs (never decrypted by AWS without your KMS key) | aws.amazon.com/privacy |
| Supabase | Managed PostgreSQL database | User account data, seal records, encrypted PII columns | supabase.com/privacy |
| Stripe, Inc. | Payment processing | Email address, transaction amount (card data goes directly to Stripe, never to Oricert) | stripe.com/privacy |
| SendGrid (Twilio) | Transactional email delivery | Email address, certificate PDF attachment | sendgrid.com/privacy |
| Render.com | FastAPI backend hosting | No raw PII; processes API requests | render.com/privacy |
| Vercel, Inc. | Next.js frontend hosting | No raw PII; serves web pages | vercel.com/legal/privacy-policy |
| Alchemy | Polygon RPC provider | Seal ID, cert hash, wallet address (all pseudonymous) | alchemy.com/privacy |
| Sentry | Error monitoring | Anonymized error logs, no PII | sentry.io/privacy |
5.2 Public Blockchain
The Polygon PoS blockchain is a public, decentralized network. Once a transaction is confirmed, it is visible to anyone who queries the blockchain. The only information recorded on Polygon is: (a) the pseudonymous seal ID, (b) the salted SHA-256 cert hash, (c) the pseudonymous wallet address, and (d) the block timestamp. No names, emails, or item descriptions are recorded on-chain.
5.3 Legal Disclosure
We may disclose personal data to law enforcement, government agencies, or courts when required to do so by applicable law, legal process, subpoena, or court order. Where permitted by law, we will notify affected users before disclosing their data. We will contest requests that we believe are unlawful or overbroad.
5.4 Business Transfers
If Oricert Group, Inc. is acquired, merges with another entity, or transfers substantially all of its assets, your personal data may be transferred as part of that transaction. We will notify you by email and update this Privacy Policy before any such transfer occurs. You will have the right to request deletion of your data before the transfer.
6. Your Privacy Rights
6.1 Rights Under GDPR (EU / EEA / UK Residents)
If you are a resident of the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation:
- Right to Access (Art. 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / ‘Right to be Forgotten’ (Art. 17): Request deletion of your personal data. We will delete your off-chain data and destroy the per-seal encryption key, rendering the on-chain hash permanently disconnected.
- Right to Restrict Processing (Art. 18): Request that we stop using your data for certain purposes while a dispute is resolved.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format (JSON export available on request).
- Right to Object (Art. 21): Object to processing based on legitimate interest, including profiling.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent for data processing at any time, without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your national data protection supervisory authority. For EU residents: edpb.europa.eu. For UK residents: ico.org.uk.
6.2 Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended by CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the third parties with whom it has been shared.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale: Oricert does not sell personal information. This right is therefore not applicable, but we disclose it for completeness.
- Right to Non-Discrimination: Oricert will not discriminate against you for exercising any CCPA right. You will receive the same quality of service regardless.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for any purpose beyond what is necessary to provide the service.
To submit a CCPA request, email privacy@oricert.com with subject line “CCPA Request — [Your Request Type].” We will verify your identity before processing the request.
6.3 How to Exercise Your Rights
Submit all privacy rights requests to:
Email: privacy@oricert.com
Subject line: “Privacy Request — [Access / Deletion / Correction / Portability / Objection]”
Include: your email address on file, your Seal ID(s) if applicable, and a description of your request.
We will acknowledge your request within 3 business days and fulfill it within 30 days (extendable to 60 days for complex requests with notice). Identity verification is required before we fulfill deletion or access requests.
7. Data Security
Oricert implements industry-standard security measures to protect your personal data:
- Encryption at rest: All S3 objects and database records containing PII are encrypted with AES-256 using AWS KMS customer-managed keys. Each seal has its own dedicated KMS key.
- Encryption in transit: All data transmitted between your browser, our servers, and third-party processors is encrypted using TLS 1.3.
- Zero raw IP storage: We never store raw IP addresses. We store only a one-way SHA-256 hash of the IP address for fraud detection.
- Presigned URLs with expiry: Item photos on the verification page are served via time-limited AWS S3 presigned URLs. There are no permanent public links to your photos.
- Access controls: Database access is restricted to application service accounts with least-privilege permissions. No human employee has routine access to production user data without an access log entry.
- Audit logging: All access to PII — by the system, by your account, and by verifiers — is recorded in an immutable audit log.
- Breach notification: In the event of a data breach affecting your personal data, we will notify you within 72 hours of discovery, as required by GDPR Article 33. CCPA-affected California residents will be notified in accordance with California Civil Code § 1798.82.
8. Data Retention
We retain your personal data for the shortest period necessary to fulfill the purpose for which it was collected:
- Seal records and associated PII: Retained for the active life of the seal plus 7 years after the seal is last transferred or the seller account is closed. This retention period is required for legal recordkeeping and dispute resolution.
- Item photos and certificate PDFs: Retained as long as the seal is active. Deleted immediately upon a valid erasure request.
- Payment records: Retained by Stripe per their data retention policy. Oricert retains only transaction IDs and amounts for accounting purposes (7 years per IRS recordkeeping requirements).
- Hashed IP addresses: Retained for 90 days for fraud detection, then permanently deleted.
- Usage analytics: Retained for 12 months, then aggregated and anonymized.
- Consent records: Retained for the life of the user relationship plus 5 years, as required to demonstrate compliance.
Upon expiry of the retention period, data is permanently deleted from all off-chain systems. The SHA-256 hash on the Polygon blockchain is not deleted (as it is technically impossible), but becomes permanently disconnected from any personal data upon deletion of the associated encryption salt.
9. Cookies and Tracking
Oricert uses minimal cookies necessary to operate the platform:
- Session cookies: Required to maintain your login session. Deleted when you close your browser.
- Authentication tokens (NextAuth.js): Required to maintain your logged-in state. Expire after 30 days or on logout.
- CSRF protection tokens: Required for security. Not used for tracking.
On public marketing pages (homepage, signup, categories, pricing, privacy, terms, and seal verification), we use privacy-oriented analytics to understand how visitors use the site:
- Google Analytics 4: Aggregated page views and traffic sources. Google may set cookies such as
_ga. See Google's Privacy Policy. - Contentsquare (Hotjar): Session recordings and heatmaps on a sample of visits to improve the marketing experience. Contentsquare may set cookies for session replay. See Contentsquare's Privacy Policy.
We do not load Google Analytics, Contentsquare, or similar tools on pages that require authentication (dashboard, certify, My Seals, account settings, or admin). We do not use advertising cookies, Facebook Pixel, or behavioral profiling for ad targeting.
Public verification pages (oricert.com/verify/...) accessible without login do not set any cookies.
10. International Data Transfers
Oricert Group, Inc. is based in the United States. If you are located in the European Union, United Kingdom, or another jurisdiction with data transfer restrictions, your personal data is transferred to and processed in the United States.
We rely on the following legal mechanisms for international transfers:
- Standard Contractual Clauses (SCCs): We have executed SCCs with all EU/UK data processors where required.
- AWS Data Processing Agreement: AWS operates under the EU–US Data Privacy Framework and has executed SCCs with Oricert.
- Your consent: For users who are EU residents, your explicit consent at checkout (Section 3) constitutes a legal basis for the transfer of your data to the US under GDPR Article 49(1)(a).
11. Children’s Privacy
The Oricert platform is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If we discover we have collected information from a minor, we will delete it immediately. If you believe a minor has submitted information to Oricert, please contact privacy@oricert.com.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will:
- Post the revised Policy on oricert.com with a new effective date
- Email all registered users at least 14 days before material changes take effect
- Require re-consent for any new uses of previously collected personal data
Your continued use of the platform after the effective date of changes constitutes acceptance of the revised Policy. If you do not agree to the revised Policy, you must stop using the platform and may request deletion of your data.
13. Contact and Data Protection Officer
For all privacy-related inquiries, data subject requests, or questions about this Policy, contact:
Privacy Officer — Oricert Group, Inc.
Email: privacy@oricert.com
General inquiries: Infobox@oricert.com
Web: oricert.com/privacy
Address: Oricert Group, Inc., Addison, Texas 75001, United States
We will respond to all privacy inquiries within 3 business days. For GDPR data subject requests, we will acknowledge within 3 days and fulfill within 30 days (extendable to 60 with notice for complex requests).
For unresolved privacy concerns, EU residents may contact their national Data Protection Authority. A list of EU DPAs is available at: edpb.europa.eu/about-edpb/board/members_en.