CERTRAV LLC / CertRez
Data Deletion & Privacy Rights
Individuals may request deletion or exercise other privacy rights relating to personal information processed by CERTRAV LLC and CertRez. CERTRAV LLC processes privacy requests in accordance with applicable privacy and data-protection laws. Rights and legal requirements may vary by jurisdiction.
Your Privacy Rights
Depending on your location and relationship to CertRez, you may be able to make one or more of these requests:
- Request deletion
- Request access
- Request correction
- Request data export or portability
- Request restriction of processing
- Object to certain processing
- Withdraw consent where processing relies on consent
- Request information about data sharing
- Close a CertRez account
Availability of each right depends on applicable law, identity verification, and whether the data belongs to you, a business tenant, a customer, staff member, or another person.
What Deletion Normally Covers
A valid deletion request may include personal information associated with:
- CertRez user profile and account information
- Authentication/account information controlled by CERTRAV
- Business profile information attributable to the requester
- Booking-related personal information
- Customer/contact information where legally appropriate
- Communications and CertAI conversation records associated with the requester
- Social-channel connection metadata controlled by CertRez
- Marketing preferences, usage information, stored identifiers, and other associated personal information
CERTRAV preserves multi-tenant boundaries. One business user cannot use a privacy request to delete another person's data or destroy business records without proper verification and business-data handling.
What We May Need To Retain
Deletion rights are not always absolute. CERTRAV may retain limited information where required or permitted for:
- tax and accounting obligations
- payment or transaction records
- fraud prevention and security investigations
- dispute resolution, legal claims, and regulatory compliance
- enforcement of contractual rights and required audit trails
- other applicable legal obligations
Retained personal information is minimized, restricted from ordinary product use where appropriate, securely protected, and deleted or anonymized when the retention requirement ends. Stripe financial transaction records are handled conservatively where tax, accounting, payout, chargeback, or fraud-prevention obligations may require retention.
Backups
Deleted information may remain temporarily in encrypted backups until ordinary backup rotation expires. Deleted information in backups is not restored to active production use except where technically necessary for disaster recovery and remains subject to deletion controls after restoration.
Third-Party Service Providers
CertRez relies on service providers actually used by this project. Deletion requests may require corresponding action concerning data maintained by processors, subject to their role, legal obligations, and retention requirements.
- Supabase for database and authentication
- Stripe for subscriptions, customer payments, and payout-related records
- Meta for WhatsApp, Instagram, Facebook, and Messenger messaging integrations
- OpenAI for CertAI-assisted responses when enabled
- Resend for transactional email
- Vercel for application hosting
How Long Requests Take
We acknowledge privacy requests promptly and aim to complete verified requests within 30 days where practicable, while honoring any shorter or different deadline required by applicable law. The internal request system can support different review targets by jurisdiction after legal review.
Contact CERTRAV LLC
For privacy questions or help with a request, contact certravllc@certrav.com.
You can also review the Privacy Policy and Terms of Service.