Skip to content

This document is an operational draft and requires review by qualified counsel before you rely on it as a binding policy. Missing legal-entity fields are left blank on purpose.

Legal entity fields (company name, address, jurisdiction) are not configured. This draft uses placeholders instead of inventing a company.

Privacy Policy

Operator: Weblicious AB. Support: support@sslcertificates.io.

Data we collect

Account name, email, hashed password, organization membership, API request metadata, hostnames, certificate public material, encrypted private keys when you choose platform-generated keys, webhook URLs, and support messages. See docs and the privacy data map in the repository.

Purpose

To operate the certificate API, isolate tenants, bill (when configured), send transactional mail, and respond to support.

Processors

Listed at /legal/subprocessors. Let’s Encrypt receives hostnames and public keys when ACME is used.

Retention and deletion

You may export organization data from the dashboard and request deletion. Certificates may be retained for audit for a configurable period. Platform-generated private keys are deleted with the certificate row unless a legal hold is configured.

Contact

Privacy contact: support@sslcertificates.io.

Cookies

See the cookie policy. We do not sell personal information.