Legal

Privacy Policy

Last updated: June 18, 2026

1. Who we are

Berlvis Credentials ("we", "us") operates the credential issuance platform at credentials.berlvis.com. We are the data controller for personal data processed through the service.

2. What we collect

  • Account data: email address, password hash, authentication metadata.
  • Project data: template designs, project names, plan/subscription status.
  • Credential data: names, photos, and other fields you upload to issue ID cards or certificates. Bulk data files and uploaded images remain on your device until you explicitly connect a cloud connector.
  • Payment metadata: plan, currency, transaction reference. Card details are processed by Paystack or Stripe; we never store full card numbers.
  • Usage data: standard server logs (IP, user agent, timestamps) for security and debugging.

3. How we use Google user data

When you connect your Google account, we request only the scopes needed for the feature you use:

  • openid, userinfo.email — to identify your Google account.
  • drive.file — to read and write only the Drive files this app creates or that you explicitly open with it. We do not access any other files in your Drive.
  • spreadsheets — to read and write spreadsheets the app creates for your projects.
  • forms.body, forms.responses.readonly — to create intake Forms and read responses into your project.

Google user data is used solely to provide the features you requested. We do not use Google user data for advertising, do not sell it, do not transfer it to third parties except as needed to provide the service (e.g. our hosting provider), and do not use it to train machine learning models.

Berlvis Credentials' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Storage and security

Account, project, and subscription data are stored in Supabase (managed Postgres) with row-level security. Google OAuth refresh tokens are stored encrypted server-side and never sent to the browser. All traffic is served over HTTPS.

5. Data sharing

We share data only with the sub-processors required to run the service: Supabase (database, auth), Cloudflare (hosting, CDN), Paystack and Stripe (payments), and Google (only when you connect your Google account, and only the scopes listed above).

6. Your rights

You may export, correct, or delete your data at any time from your account settings, or by emailing privacy@berlvis.com. You may disconnect your Google account from the dashboard, which immediately revokes our access and deletes stored tokens. You may also revoke access directly at myaccount.google.com/permissions.

7. Retention

Account and project data are retained until you delete them or close your account. Google OAuth tokens are deleted immediately on disconnect. Server logs are retained for up to 30 days.

8. Contact

Questions about this policy: privacy@berlvis.com.

See also our Terms of Service.