Privacy Policy
Effective Date: 31 July 2026
WealthCertifier ("we," "us," or "our") operates https://www.wealthcertifier.com (the "Site") and provides digital wealth certification services (the "Services"). We are the data controller for the personal data described here. This Privacy Policy explains what we collect, why, who we share it with, and what rights you have.
The short version: we collect the minimum needed to sign you in, print your certificate, and take your payment. We do not sell your data, we do not run advertising or cross-site tracking, and our analytics do not use cookies or identify you.
1. Information We Collect
Information you provide
We do not offer file or image uploads, and we do not ask for financial documents, bank details, or proof of net worth at any point.
- Account: your email address, and optionally your first name, last name, and country. We do not use passwords, so we never hold one.
- Certificate content: the title, first name, last name, and date of birth you choose to print on a certificate. This is content you author, and it does not have to be your own.
- Payments: billing details are collected by Stripe on their own hosted checkout page. We receive a Stripe customer reference, the amount, the currency, and the date. We never see or store card numbers.
- Communications: the name, email, and message you send through our contact form or by email to support.
- Shipping address: only if you buy the Gold Elite or Platinum Absurd Wealth tier, which includes a printed and framed certificate. We ask for the address by email after the payment, and we use it only to post that certificate to you. It is never collected at checkout and is not asked for on any other tier.
Information we collect automatically
- Server and security logs: IP address, user agent, requested URL, and timestamps, used to keep the Site running, enforce rate limits, and investigate abuse or errors.
- Analytics: aggregate page views and referrers, collected by our self-hosted Plausible Analytics instance. Plausible sets no cookies, stores no IP addresses, and does not build a profile of you or follow you across sites.
- Cookies: strictly necessary cookies only. See our Cookie Policy for the full list.
2. How We Use Your Information
We do not currently send marketing or promotional email. The only email we send is transactional: your sign-in link, and replies to messages you send us. If that ever changes, it will be opt-in and we will update this Policy first.
- Sign you in, either through Google or through a single-use email sign-in link.
- Generate, display, and let you download your certificate PDF.
- Process payments through Stripe and keep a record of the transaction.
- Show you your certificates and billing history on your dashboard.
- Answer support requests and contact-form messages.
- Keep the Site secure: rate limiting, fraud and abuse prevention, error diagnosis.
- Understand aggregate traffic so we can improve the Site.
- Meet our legal, tax, and accounting obligations.
3. Legal Bases for Processing (UK and EEA users)
- Performance of a contract: creating your account, generating your certificate, taking payment, supporting you.
- Legitimate interests: keeping the Site secure and available, preventing fraud and abuse, and measuring aggregate traffic in a way that does not identify you.
- Legal obligation: retaining transaction records for tax and accounting.
- Consent: not currently relied on, because we send no marketing and set no non-essential cookies. If we introduce either, we will ask first.
4. Who We Share Data With
We do not sell personal data and we do not share it for advertising. We use the following processors:
- Stripe: payment processing and checkout. Stripe is an independent controller for its own fraud and compliance purposes.
- Google: only if you choose to sign in with Google. Google tells us your email address and basic profile details.
- Resend: delivery of transactional email, such as your sign-in link.
- Our hosting and database provider: stores the Site and its data.
- Plausible Analytics: self-hosted by us, so aggregate analytics data is not shared with a third party at all.
We may also disclose data where required by law, to protect our rights, safety, or property, or in connection with a sale, merger, or reorganisation, with notice where the law requires it.
5. Cookies
We use only cookies that are strictly necessary to run the Site: your session, cross-site request forgery protection, the optional "remember me" cookie, and a cookie remembering whether your dashboard sidebar is open. We do not use advertising, profiling, or cross-site tracking cookies, which is why you are not asked to accept a cookie banner. Full detail is in our Cookie Policy.
6. Data Retention
- Account and certificates: kept while your account is open. When you delete your account, your profile and certificates disappear from the Site immediately and are permanently erased from our database 5 days later. The 5-day window exists so an accidental deletion can be undone if you contact us in time.
- Transaction records: retained for at least 6 years after the end of the relevant accounting period, as UK tax law requires. This applies even after you delete your account, and cannot be waived. Where you have made a purchase, we therefore keep the payment record rather than erase it, and instead strip out everything that identifies you: after the same 5 days your name, email address, country, payment-method details, and the name and date of birth printed on your certificate are all deleted, leaving an anonymous record of the amount, currency, tier, and date.
- Support messages: kept for as long as needed to handle the request and any follow-up.
- Server and security logs: kept for a short rolling period, then discarded.
7. Security
The Site is served over HTTPS with a content security policy, sign-in links are single-use and expire after 30 minutes, and sensitive actions are rate limited. Card data never touches our servers. We apply reasonable administrative and technical safeguards, but no system is completely secure. If a breach occurs that poses a risk to you, we will notify you and the Information Commissioner's Office as required by UK GDPR.
8. International Transfers
We are based in the United Kingdom. Some of our processors, including Stripe, Google, and Resend, operate servers outside the UK and EEA. Where personal data is transferred, it is protected by UK adequacy regulations or by standard contractual clauses with the UK International Data Transfer Addendum.
9. Children's Privacy
Our Services are for adults. You must be 18 or older to hold an account or make a purchase, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
10. Your Rights & Choices
Under UK GDPR and the EU GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data. Most of it you can edit yourself in your profile settings.
- Delete your data. You can delete your account yourself at any time, subject to the tax records noted above.
- Object to or restrict processing based on our legitimate interests.
- Receive your data in a portable format.
- Withdraw consent where we rely on it.
To exercise a right, email us at the address below. We may need to verify your identity, and we will respond within one month. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
California residents (CCPA/CPRA)
California residents have the right to know, delete, and opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we do not process it for cross-context behavioural advertising. To exercise your rights, email us using the details below.
11. Third-Party Links & Services
The Site links to third-party websites and redirects you to Stripe and Google for payment and sign-in. This Privacy Policy does not cover those services; review their privacy notices separately.
12. Changes to This Policy
We may update this Privacy Policy as our Services evolve. We will post the updated policy with a new Effective Date. Continued use of the Site after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our practices, contact:
Email: [email protected]
We aim to respond within 1-2 business days.