Certifiable is operated by Certifiable, LLC, South Charleston, West Virginia. Questions: hello@becertifiable.io.
What Certifiable is
Organizations upload a branded PDF, import a roster, and issue training or CE certificates. Attendees retrieve a copy later with lookup. We are not a public search of other people’s credentials.
What we collect
Organization accounts
When someone starts a subscription we store the owner’s name, email, password (hashed), job title, and company details they enter (name, legal name, address, phone, website, industry). Stripe handles the card. We store Stripe customer and subscription IDs, plan, price, and status — not the card number.
Rosters and certificates
For each attendee the organization uploads, we store first name, last name, email, event, hours, and a unique hash. That hash is a random identifier we generate and print on the PDF. It is not a digest of the file. Certificate PDFs are built when someone with a valid code or link asks for them. We keep the template, field layout, and attendee record — not a folder of finished PDF files.
Lookup and sharing
Lookup: the attendee enters the email on the roster. We email a 6-digit code that lasts 10 minutes. The page does not say whether that email is in the system. After a correct code, the browser session can view matching certificates for about an hour.
Share: the attendee (or org) can send a private link and a one-time 6-digit code to another address. Both are required. The share lasts 24 hours and works once.
Email we send
Access codes, certificate links (not the PDF as an attachment), share codes, login two-factor codes, and account mail such as welcome messages. Delivery status for certificate emails is stored so the organization can see whether a message was accepted. Mailgun processes those messages and may record opens and clicks on certificate mail.
Login security
Sessions are stored in a cookie. Optional two-factor uses email codes, a passkey, or backup codes. A trusted-device cookie can skip a repeat code for a limited time. Login also uses Cloudflare Turnstile.
Chat
The site chat is Tawk.to. If you write there or to hello@, that conversation is support mail, not a certificate record.
Who sees it
- The issuing organization sees its own events, roster, and certificates.
- An attendee sees certificates for the email they verified with a code.
- A share recipient sees only the certificates on that share, after the one-time code.
- Certifiable staff may access an organization account to fix a real support problem. That is logged. We do not change that org’s password or 2FA while helping.
Processors
We use Stripe (billing), Mailgun (email), Tawk.to (chat), and Cloudflare (Turnstile on login). Each of those companies processes data under its own terms. We do not sell personal information.
What we do not keep
We do not keep a public index of attendees. We do not store card numbers. We do not keep issued certificates as files on disk in the main product. Demo pages under /demo are fiction (Town of Amity) and are not live attendee records.
How long, and deletion
Organization and attendee records stay for as long as the account uses Certifiable to issue and look up certificates. The organization can delete certificates and related attendee rows from its admin. Attendees who want a record removed should ask the issuing organization, or email hello@becertifiable.io and we will work with that issuer. Closing an organization account is handled by us on request.
Contact
Certifiable, LLC
South Charleston, West Virginia
hello@becertifiable.io