Legal
Privacy Policy
Last updated July 21, 2026
In plain terms: we collect the account, domain and contact data needed to run the Service, store it securely with tenant isolation, share it only with the processors that make the product work (Cloudflare, Auth0, Stripe, Resend), and never sell it. Certificate private keys are never in our custody.
1. Who this covers
This Privacy Policy explains how Pcnaid Inc. ("we", "us") handles personal data in connection with DelegatedSSL (the "Service"). It applies to visitors of delegatedssl.com and to customers using the authenticated application and API.
2. What we collect
- Account data — your name, email and organization details, provided directly or via Auth0 at sign-in.
- Operational data — the domains, clients, tags and notes you add; validation and certificate status; audit-log entries for privileged actions.
- Contact data — information you submit through our contact form (name, email, company, message).
- Technical data — request metadata such as IP address, user agent and a request ID, used for security, rate limiting and troubleshooting.
We do not collect or store certificate private keys; that material is managed by Cloudflare for SaaS at the edge.
3. How we use it
- To provide the Service — creating custom hostnames, delegating validation, issuing and renewing certificates.
- To secure the platform — authentication, tenant isolation, rate limiting and abuse prevention.
- To communicate with you — service notices, responses to enquiries and, where applicable, billing.
- To improve reliability and diagnose issues.
4. Sub-processors we rely on
We share data only with the providers needed to operate the Service:
- Cloudflare — hosting, Custom Hostnames, certificate issuance and edge delivery.
- Auth0 — authentication and identity.
- Stripe — billing and payment processing (where applicable).
- Resend — transactional and contact email.
We do not sell your personal data.
5. Data retention
We retain account and operational data for as long as your organization uses the Service, and for a reasonable period afterward to meet legal, security and accounting obligations. Contact submissions are retained to handle and follow up on your enquiry. You can request deletion as described below.
6. Security
Every record is scoped to your organization by database row-level security. API keys and webhook secrets are stored only as hashes, transport is encrypted with HSTS and modern TLS, and access is authenticated on every request. See our security page for details.
7. Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email [email protected] and we'll respond within a reasonable timeframe.
8. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected in the "last updated" date above, and we'll take reasonable steps to notify you where appropriate.
9. Contact
Privacy questions or requests? Email [email protected].