Privacy Notice · September 13, 2026

Plain-language data handling.

This notice describes the current CertifyPreflight service. It does not invent certifications or imply government affiliation.

What we collect

Service-fit inquiry details you submit without an account; account identifiers supplied by the sign-in service; application and support details you submit; product documents and the information extracted from them; workspace activity, access decisions, and optional feedback; payment status identifiers supplied by Stripe; and, with your permission, anonymous website usage information supplied through Google Analytics.

Why we use it

To screen and manage access, provide the requested preparation service, store and retrieve your workspace records, support customers, improve the product, prevent misuse, and maintain operational and billing records.

Where information is handled

The service uses hosted site infrastructure for application records and private document storage. Stripe collects and processes payment-card details on its hosted checkout page. CertifyPreflight does not need to store full card numbers.

Optional AI Guide

The AI Guide is used only after you submit a question. Your question is sent to OpenAI to generate a response. If you separately choose Use my current workspace checklist, CertifyPreflight also sends a limited summary of application and checklist values. Uploaded file bytes, document text, evidence quotations, identity, and payment details are excluded. CertifyPreflight does not save an AI chat history, and API responses are requested without OpenAI application-state storage. OpenAI may retain limited abuse-monitoring logs under its API data policy.

Analytics and campaign measurement

CertifyPreflight records campaign labels included in a visit, such as UTM parameters and Google click identifiers, so a fit check or application can be connected to the campaign that produced it. Google Analytics and Google Ads campaign measurement load only after you choose Allow analytics. A successful fit check or application may send an anonymous conversion signal, but we do not send names, email addresses, business summaries, product descriptions, uploaded documents, or payment-card details to Google, and advertising-personalization signals are disabled.

Who can see it

The signed-in customer can access their own workspace records. Designated CertifyPreflight operators can review service-fit inquiries, applications, support requests, access records, and customer feedback. Service providers may process information only to operate the product. We do not claim that CPSC or CBP receives your workspace data; the beta submission route is disabled.

Retention and deletion

Beta records are kept while needed to provide the service, resolve disputes, secure the product, and meet legitimate business or legal obligations. Customers can permanently delete individual uploaded documents from their authenticated workspace. Submit an account-wide Data access or deletion request through Support; verified requests are handled manually, with a target of 30 days unless retention is required.

Your choices

Do not upload information you are not authorized to share. You may request access, correction, or deletion of your information through Support. You can revisit optional analytics consent at any time using Analytics choices in the footer. Optional survey feedback is private by default, and quote follow-up consent never publishes a testimonial automatically.

Questions: Use the private Support form. Do not send passwords, API keys, payment-card details, or sensitive product files by email.