Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Quick Navigation
1 Overview
Issue Badge ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our certificate management platform.
Our Privacy Principles
- We collect only what we need to provide our services
- We never sell your personal information
- You have control over your data
- We use industry-standard security measures
2 Information We Collect
Personal Information
Information you provide directly:
- • Name and email address
- • Organization details
- • Payment information (processed securely by payment providers)
- • Certificate recipient information
- • Profile photo (optional)
Usage Information
Information collected automatically:
- • IP address and device information
- • Browser type and operating system
- • Pages visited and features used
- • Certificate creation and verification logs
- • API usage statistics
Third-Party Information
Information from integrated services:
- • OAuth profile information (if you sign in with Google/GitHub)
- • Analytics data from Google Analytics
- • Customer support interactions
3 How We Use Your Information
Service Delivery
- • Create and manage certificates
- • Process payments
- • Provide customer support
- • Send service notifications
Service Improvement
- • Analyze usage patterns
- • Develop new features
- • Optimize performance
- • Conduct research
Communication
- • Service updates
- • Security alerts
- • Marketing (with consent)
- • Feature announcements
Security & Compliance
- • Prevent fraud
- • Enforce terms of service
- • Comply with legal obligations
- • Protect user rights
5 Data Security
We implement comprehensive security measures to protect your information:
Technical Measures
- • 256-bit SSL encryption
- • Encrypted data storage
- • Regular security audits
- • DDoS protection
- • Secure API endpoints
Operational Measures
- • Access controls
- • Employee training
- • Incident response plan
- • Regular backups
- • Vendor assessments
Note: While we use industry-standard security measures, no method of transmission over the internet is 100% secure. We continuously work to protect your information but cannot guarantee absolute security.
6 Data Retention
We retain your information only as long as necessary to provide our services and fulfill the purposes outlined in this policy.
Active Accounts
Data is retained as long as your account is active and for legitimate business purposes.
Deleted Accounts
Personal data is deleted within 90 days of account closure, except where retention is required by law.
Certificate Data
Certificate records may be retained indefinitely for verification purposes, as agreed during issuance.
Legal Compliance
Some data may be retained longer to comply with legal obligations or resolve disputes.
7 Your Rights & Choices
You have several rights regarding your personal information:
Access
Request a copy of your personal data
Correction
Update or correct inaccurate data
Deletion
Request deletion of your data
Objection
Object to certain data processing
Portability
Export your data in a portable format
Opt-out
Unsubscribe from marketing emails
To exercise any of these rights, please contact us at support@issuebadge.com or through your account settings.
9 Children's Privacy
Issue Badge is not intended for use by children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@issuebadge.com.
10 International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:
International Transfers
We use appropriate safeguards including Standard Contractual Clauses for international data transfers.
Data Localization
Where required by law, we store data within specific geographic regions.
11 Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
How We'll Notify You
- Email notification for significant changes
- Dashboard notification when you log in
- Updated "Last Updated" date at the top
12 Google Workspace API & Limited Use Policy
This section applies specifically to users of IssueBadge for Google Sheets™ and IssueBadge for Google Forms™ (our Google Sheets and Google Forms add-ons listed on the Google Workspace Marketplace).
IssueBadge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data we access
When you install IssueBadge for Google Sheets™ or IssueBadge for Google Forms™, the add-on requests OAuth permission to access the following data — and only for the purposes listed below:
- • Google Sheets (spreadsheets.currentonly): Read the recipient name and email columns of the rows you choose to send from, and write the sending status, IssueBadge issue ID, and public certificate link back into columns of the same sheet. Limited to the spreadsheet you currently have open — the add-on cannot see any other file in your Drive.
- • Google Forms (forms.currentonly, Forms add-on only): Read the questions, quiz settings and quiz scores of the form you install the add-on in, and read the recipient name and email answers of each submitted response, in order to decide whether a certificate is due and to whom.
- • Run when you are not present (script.scriptapp, Forms add-on only): Install the on-form-submit trigger that runs the add-on when a respondent submits the form. Nothing else is scheduled or run in the background.
- • Add-on user interface (script.container.ui): Show the IssueBadge menu, sidebar, and settings dialog inside Google Sheets or Google Forms. No data is accessed through this permission.
- • Connect to an external service (script.external_request): Send certificate requests from the add-on to the IssueBadge API at
app.issuebadge.com. This is the only external host the add-on is permitted to contact. - • User email (userinfo.email): Identify your signed-in Google account so that your IssueBadge API key setting is stored for you alone and not shared with other users of the spreadsheet.
Neither add-on requests access to Google Drive, Gmail, Google Slides, Contacts, or Calendar. The Sheets add-on does not access Google Forms, and the Forms add-on does not access Google Sheets.
What is sent to IssueBadge, and why
The add-on issues certificates through your own IssueBadge account. When you click Send Certificates, for each selected row it transmits to the IssueBadge API:
- • the recipient's name and (if present) email address from that row;
- • the badge or certificate template ID you selected;
- • your IssueBadge API key, which authenticates the request to your account.
This data is used solely to create the certificate record in your IssueBadge account and deliver it to the recipient, exactly as if you had issued it from the IssueBadge web app. Once issued, the certificate is handled under Sections 1–11 of this Policy. No other spreadsheet contents are transmitted. Your API key is stored in Google's Apps Script user-properties storage for your Google account only; IssueBadge does not receive or store your Google credentials or OAuth tokens.
How we use Google user data — Limited Use compliance
✓ We do
- • Use data only to provide the certificate-issuing features you explicitly trigger
- • Read only the name and email cells of rows you choose to send from
- • Transmit only those recipient details to IssueBadge, over HTTPS, to your own IssueBadge account
- • Let you uninstall the add-on or revoke access at any time
✗ We never
- • Read spreadsheet data outside the columns and rows you selected, or any other file in your Drive
- • Sell, rent, or share Google user data with third parties
- • Use Google user data for advertising or to build ad profiles
- • Use Google user data to train AI or machine-learning models
- • Allow humans to read your data, except (a) with your explicit consent, (b) to fix a security issue, (c) to comply with applicable law, or (d) for anonymized aggregate operational metrics
Retention and deletion
IssueBadge does not keep a copy of your spreadsheet. The only data retained on our servers is the certificate record created in your IssueBadge account (recipient name, email, badge, issue date), which you can delete at any time from your IssueBadge dashboard or by contacting support@issuebadge.com. Deleting your IssueBadge account removes these records under Section 6 of this Policy.
Revoking access
You can revoke IssueBadge's access to your Google account at any time at myaccount.google.com/permissions, or uninstall the add-on from the Google Workspace Marketplace. After revocation, the add-on can no longer read or write your spreadsheet. Status columns already written to your sheet, and certificates already issued to your IssueBadge account, remain and are unaffected.
13 Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, we're here to help:
Privacy Team
Data Protection Officer
Mailing Address
Issue Badge Privacy Team
Your Privacy Matters
We're committed to protecting your data and respecting your privacy choices.
Manage Privacy Settings