Privacy
We don't want your data. We take only what's needed to process your order, and you can permanently delete it yourself, at any time.
The data controller for the processing described on this page is SSLCloak LLC, an Ohio limited liability company (“SSLCloak,” “we,” “us”). Contact us about anything on this page at privacy@sslcloak.com.
The short version
- ✓ We collect the minimum needed to issue, bill, and support your certificate order — nothing more.
- ✓ No tracking, no analytics trackers, no ad pixels, no data resale.
- ✓ You can permanently delete an order's data yourself, any time, with no request or waiting period.
- ✓ GDPR rights (access, erasure, rectification, portability, objection, restriction) are honored — several are already self-serve.
What we collect, and why
- Domain names & CSR
- The primary domain, any additional hostnames, and the public-key data inside your CSR — required to issue a certificate that actually covers your domains. Your private key is never sent to us or seen by us.
- Billing details
- Name, email, and billing address — required to charge for the order and issue a receipt. Card payments are processed by Stripe; we never see or store your full card number. Crypto payments, where offered, are handled by our payment processor the same way.
- Order & account email
- Used to identify your order and send status updates (e.g. validation failures, certificate ready). Nothing else is sent to this address.
What we don't do
- ✕No analytics or advertising trackers on this site.
- ✕No cross-site tracking, fingerprinting, or ad pixels.
- ✕No selling or renting your data to anyone, ever.
- ✕No marketing emails unless you explicitly ask for them.
- ✕No keeping data "just in case" after you've deleted it.
About domain names being public
One thing we can't change: Certificate Transparency logs make the domain names in any publicly trusted TLS certificate public, regardless of issuer — that's a Web PKI requirement, not a SSLCloak choice. Our privacy commitment is about data minimization and control over everything else: no tracking, no unnecessary retention, and self-serve deletion of everything we do hold.
How long we keep data, and deleting it
We keep order data only as long as needed to fulfill and support your order. You don't have to wait for us: on the Order status page, any order has a “Delete this order's data” action that immediately and permanently removes its domains, CSR, billing details, and certificate from our systems — a real, working deletion, not a request queue. Want everything gone, not just one order? “Delete my account” on Account settings does the same thing for your whole account at once.
Your rights under GDPR
Whether or not GDPR applies to you specifically, we apply these rights to everyone:
Access
Ask what data we hold about your orders. Since you place orders directly and can view them any time on Order Status, this is already self-serve.
Erasure ("right to be forgotten")
Permanently delete a single order's domains, CSR, billing details, and certificate from the Order Status page, or your entire account and everything tied to it from Account settings - either way, immediately and yourself, no request or waiting required.
Rectification
Fix incorrect details before an order is placed by editing any step; for a placed order, delete it and reorder with correct information.
Restriction & objection
Ask us to pause processing of specific data, or object to a particular use, by contacting us below.
Portability
Request your order data in a portable format by contacting us below.
Lodge a complaint
If you're in the EU/EEA/UK, you can complain to your local data protection supervisory authority at any time.
Legal basis for processing
We process order and billing data on the basis of contract performance (fulfilling the certificate order you place) and, for billing records, legal obligations around financial record-keeping.
Who we share data with
- The issuing certificate authority
- Domain and CSR data is shared with whichever CA issues your certificate (Let's Encrypt or ZeroSSL, via the ACME protocol) — required to issue any publicly trusted certificate. The CA is an independent entity, not a subprocessor acting on our instructions — see Terms for how their own Subscriber Agreement applies alongside ours.
- Stripe (payment processing)
- Billing details and payment amounts, to process your charge. Stripe collects your card number directly — it never reaches our servers. Bound by Stripe's own standard data processing terms, incorporated into the agreement every Stripe customer accepts by using their service.
- Resend (transactional email)
- Your email address and the content of order-status notifications, to deliver them. Not used for anything beyond sending the emails we trigger. Same as Stripe, bound by Resend's own standard data processing terms.
We don't share your data with anyone else for marketing or resale purposes. If a business customer needs a signed Data Processing Agreement with us specifically beyond what's described here, contact privacy@sslcloak.com.
This is a working prototype. The commitments above reflect how the product actually behaves today, but this page hasn't been through formal legal review — before a real-world launch, it should be reviewed by qualified legal counsel to confirm full regulatory compliance for your jurisdictions.
Questions or requests not covered above? Reach us at privacy@sslcloak.com.