Draft — pending legal review. This document is not yet final. Details in [brackets] are still to be filled in.
Privacy Policy
Effective: [EFFECTIVE DATE]
1. Who we are
HusayCert is operated by [OPERATOR NAME], [BUSINESS ADDRESS] (“we”, “us”). We are the personal information controller for the data described here, under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
Questions or requests about your data: our Data Protection Officer at [PRIVACY / DPO EMAIL].
2. What we collect
- Account details — your name, email address, and profile picture (if you sign in with Google or GitHub). If you sign up with email and password, we store your password only as a one-way hash, never the password itself.
- Sign-in data — session records, and the sign-in tokens Google or GitHub issue when you use them to sign in.
- Exam data — your attempts, answers, scores, how long you spent on each question, and any exam-rule violations detected during an attempt (for example, exiting full-screen), including the resulting lockouts.
- Certificates — the name printed on the certificate, the topic and level, your score, the issue date, and a credential ID.
- Purchases — orders, amounts, discount codes used, and wallet credit. Card and e-wallet details are handled by our payment provider; we don't store them.
- Referrals — who referred you (if anyone) and the rewards credited to referrers.
- Technical data — IP addresses and request details in our hosting logs. For abuse protection we also count requests per IP address and per email; these are stored only as one-way hashes and expire within hours.
- Messages you send us — for example, support requests, or the screenshots you email us for the social-follow discount.
3. Why we use it
- To provide the service (our contract with you): your account, exams, scoring, certificates, purchases, and referral rewards.
- To keep certificates trustworthy (our legitimate interest, and yours as a certificate holder): enforcing the exam rules, recording violations and lockouts, and preventing fraud and abuse.
- To keep the service secure: rate limiting, preventing account takeover, and investigating problems.
- To email you about your account — verification and password-reset emails. We don't send marketing email without your consent.
- To meet legal obligations, such as keeping transaction records.
4. What's public
Certificates are public by design. Anyone with a certificate's link, QR code, or credential ID can open its verification page, which shows the name on the certificate, the topic and level, your score, the issue date, and the credential ID. That is what lets an employer confirm it is genuine. Nothing else about your account is public.
5. Who we share it with
We don't sell your data. We share it only with service providers that process it for us, under agreements requiring them to protect it:
- Vercel — hosting the website and its logs.
- Neon — our database.
- Upstash — hashed counters for rate limiting.
- Resend — sending account emails.
- Google and GitHub — only if you choose to sign in with them.
- Our payment provider — to process purchases. [PAYMENT PROVIDER NAME]
Some of these providers store data outside the Philippines (for example, in the United States). Where they do, we rely on their contractual and security commitments to protect it to a standard comparable to Philippine law. We may also disclose data where required by law.
6. How long we keep it
- Account, exam, and purchase data — for as long as your account is open.
- Exam-rule violation records — for as long as your account is open, so lockouts and reviews stay consistent.
- Transaction records — as long as Philippine tax and accounting rules require.
- Rate-limit counters — a few minutes to a few hours.
- Issued certificates — kept so they stay verifiable. If you close your account, tell us whether you want your certificates kept verifiable or removed. [CONFIRM WITH LEGAL REVIEW]
7. Your rights
Under the Data Privacy Act, you have the right to:
- be informed about how your data is processed (this policy);
- access the personal data we hold about you;
- correct inaccurate data — including the name on your account;
- object to processing, and ask us to erase or block your data;
- receive your data in a portable format;
- be compensated for damages from unlawful processing; and
- file a complaint with the National Privacy Commission (privacy.gov.ph).
To use any of these rights, email [PRIVACY / DPO EMAIL]. We may need to confirm your identity first. Some data we may have to keep — for example, transaction records the law requires.
8. Cookies and local storage
We only use what the site needs to work:
- Sign-in cookies — keep you signed in and protect forms against forgery.
- Referral cookie — if you arrive through someone's referral link, remembers it for up to 30 days so they get credit if you sign up.
- Theme preference — your light/dark choice, stored in your browser only.
We don't use advertising or cross-site tracking cookies.
9. Security
Passwords are stored as salted one-way hashes, emailed links are single-use and expire, data is encrypted in transit, and access to production data is restricted. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the National Privacy Commission as the law requires.
10. Age
You must be at least 18 to create an account, or have the consent of a parent or legal guardian.
11. Changes
If we change this policy, we'll update the effective date above and, for significant changes, let you know by email or on the site. See also our Terms of Service.
See also: Privacy Policy · Terms of Service