Effective Date: October 3, 2026 · Last updated: October 3, 2026 · Version 2026-10-03
The version identifies our Terms and Conditions of Use and Privacy Policy together as one set: both documents carry the same version, and it changes whenever either of them is revised. A document's Effective Date changes only when that document's own text changes — so where the Effective Date above is older than the version, this document is unchanged since that date and the other one was revised.
IMPORTANT NOTICE: This Privacy Policy explains how Technologies Certgio Inc., a Quebec société par actions ("Certgio", "we", "us", or "our"), domiciled at 12252 rue Filion, Montréal, Quebec H4J 1T8, collects, uses, and discloses information from you ("User", "you", or "your") when you access or use our services. By accessing or using our platform or website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these terms, please do not use our services.
Certgio is a technology platform that simplifies the management of Certificates of Insurance (COIs) by acting as a communication bridge and translator. We enable businesses, brokers, agents, and individuals to collect, verify, store, and distribute insurance certificates efficiently and compliantly. Our services leverage artificial intelligence and integrations with third-party providers to automate and enhance COI workflows.
This Privacy Policy applies to all personal information collected, used, stored, or disclosed by Certgio in connection with:
This Policy applies to all users, including business clients, insurance brokers, agents, individual users, and visitors, regardless of whether they have created an account or are simply visiting our website.
Jurisdictional Note: Certgio is a Quebec enterprise. Depending on your location, additional or different privacy rights and protections may apply. Please refer to the jurisdiction-specific sections of this Policy for more information.
We collect several categories of personal information depending on how you interact with us and the services you use. "Personal information" means any information that identifies or can reasonably be used to identify you or your organization.
We collect information that identifies you as an individual, including but not limited to:
When you use Certgio on behalf of a business or organization, we collect:
As a COI management platform, the core of our service involves handling insurance-related information, including:
Financial Data Notice (GLBA): Insurance information and related financial data collected by Certgio may constitute "nonpublic personal information" under the Gramm-Leach-Bliley Act (GLBA).
Our platform allows users to upload, store, and share documents. These may include:
We process uploaded documents using automated tools, including AI-powered extraction and verification technology, to parse information and populate data fields within the Platform.
We automatically collect certain technical information when you use our Platform:
We collect information you provide directly when you:
We collect limited usage and technical data automatically when you interact with our website or Platform. Analytics of this kind is off unless you turn it on - Section 10 explains exactly what is stored, and how to change your choice at any time. We do not use web beacons, pixel tags, or advertising trackers of any kind.
Compliance Passport views are recorded. A Compliance Passport is a page a certificate holder reaches by scanning a QR code or following a link someone shared with them. When a passport is opened, we record that it was opened and when, against that passport's own record, and we count the view in our product analytics. The record identifies the passport, not the person who opened it - we do not set an identifier for the viewer, do not build a profile of them, and do not link the view to any other activity. This happens whether or not the viewer has accepted analytics, because recording access to a shared compliance document is part of providing it rather than measurement of the viewer.
We may receive information about you from:
When you upload insurance certificates or other documents, our AI technology automatically extracts and processes data from those documents, including policy numbers, coverage amounts, dates, and party names. This information is then stored and used to power the Platform's verification and tracking features.
We use the personal information we collect for the following purposes:
Under applicable U.S. laws, we process your personal information on the following legal bases:
Under PIPEDA and Quebec Law 25, we collect, use, and disclose personal information only:
In addition to using your data to provide the Certgio services, we may process, retain, and analyze information derived from the documents you submit (such as Certificates of Insurance) to create de-identified, anonymized, and aggregated datasets. We systematically strip this data of identifying details so that the resulting information cannot be reasonably linked back to you, your business, or your vendors. Because this de-identified data is no longer considered personal information under applicable privacy laws, we may use it for any lawful purpose, including to understand industry insurance habits, build benchmarking tools, and continuously improve the Certgio platform.
AI Transparency Notice: Certgio uses artificial intelligence and automated processing tools to provide key features of our Platform. This section explains how AI is used, what decisions it informs, and your rights related to automated processing.
Certgio uses AI and machine learning tools for the following purposes:
Our AI-powered document processing engine analyzes uploaded insurance certificates to extract structured data, recognize policy terms and coverage details, and populate fields within the Platform. This is an automated process that does not involve human review of every document.
The Platform uses automated logic to assess whether submitted COIs meet predefined compliance requirements set by certificate holders or administrators. Automated flags and alerts may be generated based on this analysis.
Certgio's AI tools assist in processing and verification but do not constitute professional insurance, legal, or underwriting advice. AI-generated analysis may contain errors. Critical decisions about insurance compliance should be reviewed by qualified personnel. Certgio is not responsible for decisions made solely in reliance on AI-generated output without human review.
Where a consequential decision may be made using AI (such as a flagging of a COI as non-compliant), you have the right to request human review of that decision. Please contact us at hello@certgio.com to exercise this right.
We do not use AI to make final adverse insurance coverage or underwriting decisions.
We do not sell your personal information for monetary compensation. We may share your information in the following circumstances:
The core function of our Platform involves sharing COIs between parties - for example, from an insured party to a certificate holder. When you share a COI or grant access to your information through the Platform, that information will be visible to the designated recipients. This sharing is at your direction and is necessary to provide the service.
We engage third-party service providers to assist us in operating our Platform. These providers are permitted to use your information only as directed by us and consistent with this Policy. Categories of service providers include:
We name every one of them. The current list, including what each receives and where it processes, is published at certgio.com/subprocessors and kept up to date there rather than in this document.
With your consent or as permitted by law, we may share information with authorized business partners, such as insurance brokers or agencies who manage COI compliance on behalf of their clients.
We may disclose your information when required to:
If Certgio undergoes a merger, acquisition, reorganization, sale of assets, or bankruptcy proceeding, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information in accordance with applicable law.
Gramm-Leach-Bliley Act (GLBA) Notice: We do not share your nonpublic personal information with nonaffiliated third parties for their own marketing purposes unless you have authorized us to do so. We share information with service providers as necessary to administer our services, consistent with GLBA requirements. You may have the right to opt out of certain sharing; please see Section 8 for details.
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with the following rights, effective January 1, 2026:
To submit a CCPA request, please contact us at hello@certgio.com. We will respond within 45 days (extendable by an additional 45 days with notice). You may designate an authorized agent to submit requests on your behalf.
Residents of the following states have privacy rights similar to those described above under their respective state laws. We honor these rights for residents of:
Rights available under most state laws include the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of the processing of personal data for targeted advertising. To exercise any of these rights, please contact us at hello@certgio.com.
Under the Gramm-Leach-Bliley Act (GLBA), you have the right to:
To exercise your GLBA opt-out rights, please contact us at hello@certgio.com.
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), individuals in Canada have the following rights:
Quebec's Act Respecting the Protection of Personal Information in the Private Sector (commonly known as Law 25 or Loi 25) provides Quebec residents with additional rights:
Quebec Law 25 Penalties: Non-compliance with Quebec Law 25 can result in penalties of up to $25 million CAD or 4% of worldwide turnover.
Quebec Law 25 requires an assessment of privacy-related factors before certain processing, including the communication of personal information outside Quebec. Certgio is committed to assessing the privacy impact of new technologies and processes that involve personal information, and to completing formal Privacy Impact Assessments for the processing that requires them, including our use of AI to read uploaded documents and our use of service providers located outside Quebec. This programme is in progress and not yet complete. If you would like to know the current status for a specific processing activity, contact our Privacy Officer at hello@certgio.com.
To exercise any of your rights under PIPEDA or Quebec Law 25, please contact our Privacy Officer at:
We will respond to requests within 30 days. If we need additional time, we will notify you. Where we are unable to fulfill a request, we will explain why.
This section lists everything we store on your device and everything we ask your browser to store on our behalf. We use a small number of first-party cookies and browser-storage entries to operate the Platform, and two third-party analytics services that run only if you accept them. We do not use web beacons, pixel tags, advertising cookies, or cross-site tracking of any kind.
Most of what we store is not a cookie at all - our analytics provider is configured to use your browser's local storage instead, which means it is not transmitted with every request to our servers. We list it here regardless, because what matters is that something is stored on your device, not the technical form it takes.
Strictly necessary - always active. Without these the Platform cannot sign you in or defend itself.
| What | Where | Whose | Why | How long |
|---|---|---|---|---|
| certgio_token | Cookie | Certgio | Keeps you signed in; checked before protected pages load | 7 days |
| certgio_access_token, certgio_refresh_token | Local storage | Certgio | Your signed-in session | Until you sign out |
| certgio_2fa_temp_token, certgio_2fa_email | Local storage | Certgio | Completing two-factor sign-in | Deleted as soon as sign-in finishes |
| authjs.session-token, authjs.callback-url, authjs.csrf-token | Cookies | Certgio | Signing in with Google | Session token expires after 1 hour |
| Cloudflare Turnstile | Cookie | Cloudflare | Confirms a person, not a bot, is using the free COI checker | Duration set by Cloudflare - see their privacy policy at cloudflare.com/privacypolicy |
| certgio_consent_v1 | Local storage | Certgio | Remembers whether you accepted or declined analytics | Until you clear your browser data |
| certgio_pending_vendor | Session storage | Certgio | Carries what you typed across signing up, so you do not retype it | Deleted when you close the tab |
Functional - always active, signed-in users only. Small preferences that make the app less repetitive: which hints you have dismissed, an unfinished form draft, your onboarding checklist progress, recently used commands. All stored in your browser's local storage, all first-party, all kept until you clear your browser data. None of it is transmitted to us as analytics.
Analytics - only if you accept. None of the following is created, and neither service is loaded, unless you have accepted analytics. If you decline, or if your browser sends a Global Privacy Control signal, nothing in this group exists on your device.
| What | Where | Whose | Why | How long |
|---|---|---|---|---|
| ph_..._posthog | Local storage | PostHog | Product analytics: which pages are opened, which steps of a check are completed | Until you clear your browser data or withdraw consent |
| certgio_anon_id | Local storage | Certgio | A random identifier linking your steps through one instant check into a single journey | Until you clear your browser data or withdraw consent |
| certgio_first_credit_fired | Local storage | Certgio | Ensures your first completed check is counted once rather than every time | Until you clear your browser data or withdraw consent |
| sentryReplaySession | Session storage | Sentry | Ties together a masked recording of a session in which an error occurred | Deleted when you close the tab |
The three durations above are maximums, and your browser may enforce a shorter one. Safari, in particular, deletes first-party local storage after seven days without a visit, so these entries can disappear sooner than stated. Shorter is the safe direction: it means the data is gone, and you would simply be asked for your choice again.
We do not use marketing or targeting cookies. There are none to consent to. We run no advertising technology, no ad network, no conversion pixel, and no cross-site tracking, and we do not participate in cross-context behavioral advertising.
One thing runs without your consent and is worth naming. If the Platform hits an error, we send a crash report to Sentry so the fault can be fixed. Crash reporting stores nothing on your device - the entry above is created by session replay, which is part of the analytics group and off unless you accept it. We treat crash reporting as necessary to keep the service working and secure; we treat recording your session as analytics, which is why the two are separated here rather than described together as "monitoring".
Analytics is off until you turn it on. The first time you visit, a notice offers two choices - Accept analytics or Decline - presented equally, with no pre-selected option and no way to dismiss it without choosing. Until you choose, nothing in the analytics group above runs. Declining is not a degraded experience: every feature, including the free COI checker, works identically either way.
Changing your mind. The Cookie Settings link in our website footer opens a page showing your current setting and letting you change it. It works whether or not you are signed in, and no account is needed. When you turn analytics off we delete what was stored for it and reload the page, because that is the only way we can reliably stop code that has already started.
Global Privacy Control. If your browser sends a GPC signal, we treat it as a refusal automatically: analytics does not run, and you are not shown the notice at all, because asking again after you have already signalled a preference would not be a genuine choice. The signal overrides anything stored on this site, including an earlier acceptance. We also honour the older Do Not Track signal the same way.
For California residents. GPC is the opt-out mechanism described in Section 8.1, and it is honoured automatically. The "Do Not Sell or Share My Personal Information" link in our footer leads to the same Cookie Settings page.
For Quebec residents. In accordance with Quebec Law 25, we obtain your explicit opt-in consent before storing anything non-essential on your device, and you may withdraw that consent at any time using Cookie Settings. The consent notice does not treat silence, a page dismissal, or continued browsing as agreement.
Compliance Passport views are recorded separately and are not covered by this choice; see Section 4.2 for what is recorded and why.
We retain account data only for as long as necessary to fulfill the purposes for which it was collected. Ephemeral data, including uploaded source contracts, review copies, and anonymous checks, are not stored long-term and are automatically deleted within 7 days. Upon account closure, account identity fields (including name, email, phone, company, and password) are anonymised immediately. All other associated account data, including submission records, IP addresses, browser details, and audit snapshots, are permanently deleted or fully anonymised in our live systems within 30 days of closure. Copies made before closure remain in our backups until those backups expire: up to 6 days for daily backups, 27 days for weekly backups, and 89 days for monthly backups, and up to four weeks in our point-in-time recovery archive. Exception for Compliance Passports: Compliance passports issued to third parties are retained indefinitely to ensure their continued validity for the certificate holders who rely upon them; however, all digital links connecting these passports to your closed account are permanently severed within the 30-day closure period.
Certgio is committed to protecting the security of your personal information. Our measures include:
Security Incident Notice: In the event of a security breach that compromises your personal information, we will notify you as required by applicable law, including applicable U.S. state data breach notification laws and, in Quebec, the Commission d'accès à l'information (CAI) and affected individuals as required by Law 25.
Certgio is a Quebec enterprise. Personal information may be processed by service providers located in the United States or other countries; our Subprocessors page lists each of them, what it receives, and where it processes. Applicable protections govern these transfers:
Certgio's services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are under 18, please do not use our services or submit any personal information to us.
In the United States, the Children's Online Privacy Protection Act (COPPA) prohibits the collection of personal information from children under 13 without verifiable parental consent. If we become aware that we have collected personal information from a child under 13, we will promptly delete it. To report a concern, please contact hello@certgio.com.
We will send you transactional and service-related communications (such as account confirmations, COI alerts, expiration notices, and security notifications) as necessary to provide our services. These communications are not optional if you use the Platform.
We may send you marketing emails about our products, services, and promotions. In the United States, our marketing emails comply with the CAN-SPAM Act, which requires us to identify our messages as advertisements (where applicable), include our physical postal address, and provide a clear mechanism to opt out of future emails. We honor opt-out requests within 10 business days.
For Canadian recipients, we comply with Canada's Anti-Spam Legislation (CASL). We will only send commercial electronic messages (CEMs) to Canadian recipients with express or implied consent as defined under CASL, and every CEM will include our identification information and an unsubscribe mechanism that we will honor promptly.
Our Platform may integrate with or link to third-party services, including insurance management systems, broker portals, payment processors, and e-signature providers. These third parties have their own privacy policies, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you use in connection with our Platform.
Where we share your information with third-party service providers, we do so under each provider's data processing terms.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or applicable law. When we make material changes, we will notify you by:
Your continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of the changes (for non-material changes). For material changes, we will obtain your consent where required by applicable law.
Laws and regulations that may apply to the processing described in this Policy include:
United States
Canada
If you have questions, concerns, or complaints about this Privacy Policy or our privacy practices, or if you wish to exercise any of your rights described in this Policy, please contact us:
Email: hello@certgio.com
Mail: Privacy Officer, Technologies Certgio Inc., 12252 rue Filion, Montréal, Quebec H4J 1T8
Regulatory Authorities