No tracking cookies
We use essential cookies only. No advertising, no cross-site tracking.
EU data storage
Your data is stored on servers in the European Union. Documents are encrypted at rest.
We never sell your data
Your information is used to provide the service. It is never sold to or shared with third parties.
Who we are
ExpirVault is operated by CodeFirst Ltd, a company registered in England and Wales. Our registered address is available on request at hello@expirvault.com.
What we collect
We collect different data depending on how you interact with ExpirVault:
- Early access signup: your email address, and optionally your company size, industry, and role. We also capture the page you signed up from and any UTM parameters from the referring link.
- Product usage: employee names, certification details, expiry dates, and documents you upload. This data belongs to you and is stored solely to provide the service.
- Analytics: anonymous page view data collected via privacy-friendly analytics (no cookies, no cross-site tracking). We also use Microsoft Clarity to understand how visitors interact with the site through heatmaps and session recordings. Clarity does not use cookies for tracking.
- Technical data: IP address, browser type, and device type are collected automatically with each request. These are used for security and abuse prevention only.
How we use your data
- Email: to send you product updates, launch announcements, and account notifications. You can unsubscribe at any time.
- Signup form fields: to understand our audience and prioritise features for the industries and team sizes that need them most.
- Product data: solely to provide the certification tracking service to you and your team.
- Analytics: to improve the website and understand which pages are useful.
Cookies
ExpirVault uses essential cookies only:
- Session cookie: keeps you logged in while using the product. Expires when you close your browser or after 24 hours of inactivity.
- Authentication cookie: remembers your login between sessions if you choose "Remember me". Expires after 30 days.
We do not use advertising cookies, retargeting pixels, or any third-party tracking cookies.
Data storage and security
- All data is stored on servers located in the European Union.
- Documents you upload are encrypted at rest using AES-256 encryption.
- All connections to ExpirVault use TLS 1.2+ encryption in transit.
- Access to production systems is restricted to authorised personnel only, with multi-factor authentication required.
- We perform regular backups and maintain a disaster recovery plan.
Data sharing
We do not sell, rent, or trade your personal data. We share data only with:
- Infrastructure providers: cloud hosting, email delivery, and payment processing services that are necessary to operate ExpirVault. These providers are contractually bound to protect your data.
- Legal requirements: if required by law, regulation, or valid legal process.
Data retention
- Early access signups: retained until you unsubscribe or request deletion.
- Product data: retained while your account is active. After account deletion, all data is permanently removed within 30 days.
- Analytics: aggregated and anonymised. No personally identifiable information is retained in analytics.
Your rights
Under GDPR and applicable data protection laws, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data ("right to be forgotten").
- Export your data in a portable format.
- Object to processing of your data for marketing purposes.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email hello@expirvault.com. We will respond within 30 days.
Children's privacy
ExpirVault is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.
Changes to this policy
We may update this privacy policy from time to time. When we make significant changes, we will notify users by email. The "last updated" date at the top of this page will always reflect the most recent revision.
Contact
If you have questions about this privacy policy or how we handle your data, contact us at hello@expirvault.com.