Who is responsible
ShareCert is owned and operated by Fat Dog Labs Pty Ltd, a company registered in Australia and based in Victoria (we, us or our). This policy explains our information-handling practices for this website and enquiries. It does not waive rights you have under applicable privacy law or give us permission for unrelated uses of your information.
Certificate fields and generated PDFs
Company, holder, address, share, payment, signer-name and notice fields are processed in your browser to create the preview and PDF. The generator does not send these fields to our server, an AI service or an analytics service. We do not receive or retain a server copy of certificates generated this way.
There is no saved-project or cloud-backup feature. Leaving or refreshing the page can clear your entries. Downloaded files are controlled by you and your device or backup providers; we cannot retrieve, edit or delete them remotely. Browser history, extensions, device syncing and anything you choose to upload or share are separate from the generator.
Only enter information you are authorised to use, especially when acting for clients or other people. This policy does not replace your own confidentiality obligations, privacy notices or required permissions.
Website access and technical information
Our hosting and access providers may process IP addresses, browser and device details, requested pages, timestamps, error records and security logs to deliver the site, manage access, diagnose faults and prevent misuse. Providers may make relevant access or diagnostic information available to us. When sign-in is required, the access provider manages authentication and may make account identity and access-status information available to the site owner.
These technical records are distinct from certificate fields. Do not put personal or certificate information into a website URL, as URLs can appear in browsing history and technical logs.
ShareCert does not use advertising trackers, product analytics, session-replay tools or marketing cookies. Hosting and access providers may use cookies or similar technologies for sign-in, security and service delivery. Disabling those technologies may affect access.
Messages you choose to send us
If you contact us, we may receive your name, contact details, message and anything you attach or provide through that channel. We use this information to respond, provide requested assistance, investigate problems or complaints, protect legal rights and meet legal obligations.
A certificate or screenshot you send in an enquiry is no longer held only in your browser. Please use a redacted or fictional example where possible, and do not send passwords, identity documents or unnecessary client information. We may ask you to remove information that is not needed.
Providing enquiry information is voluntary, but we may be unable to respond or verify a request without sufficient details. We do not add enquiry contacts to a marketing list without an appropriate separate basis.
Service providers and disclosure
We use service providers for hosting, access control, security and, when you contact us, communications. The site currently uses OpenAI’s Sites service and Cloudflare infrastructure. Their notices describe their own processing: OpenAI privacy policy and Cloudflare privacy policy.
We may share relevant technical or enquiry information with providers or professional advisers where reasonably necessary to operate the service, respond to you, resolve a dispute or meet legal obligations. We may also disclose information where required or authorised by law, or where reasonably necessary and lawful to address fraud, a security incident or a threat to safety. We do not sell personal information or disclose it for targeted advertising.
If ownership of the business changes, information we actually hold may be transferred where lawful and necessary for that change, with appropriate confidentiality protections. This does not include browser-only certificate fields that we never received, or authorise an unrelated use contrary to applicable law.
Processing outside Australia
Hosting, access, security and communications providers may process technical or enquiry information outside Australia, including in the United States and other countries where they operate. The locations depend on the provider and service configuration; we cannot specify every processing country. Provider privacy notices give further information. This does not change the generator’s browser-only treatment of certificate fields.
We remain responsible for obligations that apply to us. This policy is not a request for you to waive protections for cross-border disclosures.
Retention and security
We keep enquiry and related business records only as long as reasonably needed for the enquiry, security, a dispute or legal obligations, then take reasonable steps to delete or de-identify information no longer needed where required by law. Provider logs, backups and legal-retention requirements may have different retention periods; we do not promise immediate deletion from every backup or provider system.
We take reasonable steps appropriate to the information we hold to protect it from misuse, loss and unauthorised access or disclosure. No internet service or device can guarantee absolute security. Keep your device secure and protect downloaded certificates and any copies you share. We will address security incidents and make notifications where required by applicable law.
Access, correction and complaints
To ask about information we hold, request access or correction, or make a privacy complaint, contact us using:
Email: [Email address to be added]. A dedicated email address is not yet available. In the meantime, use the contact channel through which you received access to ShareCert.
Explain your concern and provide enough information for us to identify the relevant record and verify your identity or authority. We may seek proportionate verification before disclosing information. We aim to acknowledge requests promptly and respond within 30 days, or explain any delay, subject to any shorter legal deadline.
Access, correction or deletion requests are subject to applicable law, including lawful exceptions and retention requirements. If we refuse a request, we will explain the reason and available complaint options where required. We cannot act on a certificate held only on your device.
If a concern remains unresolved, you may be able to complain to the Office of the Australian Information Commissioner or your local regulator, depending on the law and jurisdiction that apply. This policy does not limit that right.
Changes to this policy
We will update this policy when our practices change and revise the date above. Material changes will be brought to your attention where reasonably practicable, and we will provide additional notice or obtain consent when required by law. Updating this policy does not itself authorise a new use of previously collected information that would otherwise be unlawful.