Privacy Policy

Last updated: May 2026

1. Who we are

Omnitech HQ (“Omnitech HQ”, “we”, “us”) operates the certification platform at certifyai.omnitechhq.com. This policy explains what personal information we collect, why we collect it, and the choices you have.

2. Information we collect

  • Account information: your name (optional), email address, and a hashed copy of your password. We never store your password in clear text.
  • Order information: the certification(s) you purchase or unlock with a key, the amount paid, and the Stripe session identifier. We do not store full card numbers — Stripe handles payment data directly.
  • Learning activity: lessons completed, exam attempts, scores, prompt-lab submissions, and the certificate IDs issued to you.
  • Operational data: sign-in sessions, IP address of password-reset requests, and basic server logs used to keep the service running securely.

3. How we use your information

  • To create and operate your account and deliver the certifications you purchase.
  • To send transactional emails (welcome, password reset, order receipts, certificate issuance).
  • To support the public certificate verification page, which displays the holder's name, the certification title, the issue date, and the certificate ID to anyone with the certificate ID.
  • To prevent fraud, abuse, and unauthorized access.
  • To meet legal and tax obligations.

We do not sell your personal information. We do not use your data to train AI models.

4. Service providers we use

  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Managed PostgreSQL hosting — primary data store.

Each of these providers processes data on our behalf under their own security and privacy commitments.

5. Cookies

We use a single strictly necessary cookie — a signed session cookie that keeps you logged in. Your acknowledgement of our cookie notice is stored in your browser's local storage rather than in a cookie. We do not use third-party advertising or cross-site tracking cookies.

6. Public certificate verification

Certificates issued through Omnitech HQ are designed to be verifiable by employers. When you earn a certificate, the verification page at /verify/<your-cert-id> displays your name, the certification title, and the issue date. If you do not want this information to be public, do not share the certificate ID.

7. Data retention

We keep account, order, and certificate records for as long as the account exists, and for a reasonable period after closure to satisfy tax and legal obligations. Password reset tokens expire within 60 minutes of being issued.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, write to privacy@omnitechhq.com. We'll respond within a reasonable time.

9. Security

We hash passwords with bcrypt, transmit data over HTTPS, store password-reset tokens only as SHA-256 hashes, and follow the principle of least privilege for production access. No system is perfectly secure, but we take reasonable steps to protect your data.

10. Children

Omnitech HQ is intended for working professionals and is not directed at children under 16. We do not knowingly collect personal information from children.

11. Changes to this policy

If we make material changes we'll update the “Last updated” date above and, where appropriate, notify you by email or in-app notice.

12. Contact

Questions? Reach us at privacy@omnitechhq.com.