This document is an operational draft and requires review by qualified counsel before you rely on it as a binding policy. Missing legal-entity fields are left blank on purpose.
Legal entity fields (company name, address, jurisdiction) are not configured. This draft uses placeholders instead of inventing a company.
Privacy Policy
Operator: Weblicious AB. Support: support@sslcertificates.io.
Data we collect
Account name, email, hashed password, organization membership, API request metadata, hostnames, certificate public material, encrypted private keys when you choose platform-generated keys, webhook URLs, and support messages. See docs and the privacy data map in the repository.
Purpose
To operate the certificate API, isolate tenants, bill (when configured), send transactional mail, and respond to support.
Processors
Listed at /legal/subprocessors. Let’s Encrypt receives hostnames and public keys when ACME is used.
Retention and deletion
You may export organization data from the dashboard and request deletion. Certificates may be retained for audit for a configurable period. Platform-generated private keys are deleted with the certificate row unless a legal hold is configured.
Contact
Privacy contact: support@sslcertificates.io.
Cookies
See the cookie policy. We do not sell personal information.