Privacy
Privacy policy
Last updated 29 September 2026
Certware (certware.xyz) is run by ASX, with the software built by Radar and Evora. This page explains what we collect when you use the site, the seller desk, the download hub or the API — and nothing more than we need to run them.
What we collect
- Your account: name, email address and a hash of your password (never the password itself). If you connect Discord or Google, we keep that account's id, username or email and avatar.
- Sellers: the details on your application (shop name, website, Discord, contact email and the sales figures you give us), your balance and ledger, orders, the keys you buy, your branding, API keys (stored only as a hash) and webhook endpoints (signing secrets are encrypted).
- Customers on the download hub: the Discord account a key is redeemed on, HWID reset history and download events.
- Security records: IP address and browser (user agent) for signed-in sessions, rate limits and an audit log of account and staff actions.
Why we use it
- To run the service: sign you in, deliver and manage keys, keep balances and show your history.
- To keep it safe: stop fraud, key sharing and abuse (rate limits, bot checks, the audit log).
- To contact you about your account — application decisions, top-ups, custom work and security notices. We don't send marketing email.
Who processes it for us
We don't sell your data. These providers process it only to run Certware:
- Cloudflare — network, security (including the Turnstile bot check) and file storage.
- Evora — the license server that issues and checks keys.
- Resend — delivers our transactional email.
- Discord and Google — only when you choose to sign in with them.
Cookies
We use a sign-in cookie that keeps you logged in, and Cloudflare sets cookies needed for security checks. No advertising or third-party tracking cookies.
How long we keep it
Account data stays while your account is open. Orders, ledger entries and the audit log are kept as long as we need them for accounting, refunds and fraud prevention. Sessions expire after two weeks of inactivity, and one-time links in emails are deleted from our records once sent.
Your choices
You can see and change your account details in the desk, remove connected sign-in methods and sign out other devices. To get a copy of your data or ask us to delete it, email partners@certware.xyz. We'll keep only what we must for records like completed orders.
Security
Everything is served over HTTPS. Passwords are hashed, API keys are stored as hashes, secrets are encrypted at rest and staff must use two-factor authentication.
Changes
If this policy changes in a way that matters, we'll update the date above and tell sellers on the desk.
