Terms of Service
The rules for using SSLCloak to order TLS certificates. Please read before you sign up — creating an account means you agree to these terms.
Last updated August 10, 2026.
The short version
- ✓ We're a reseller/facilitator — Let's Encrypt or ZeroSSL actually issue your certificate, not us.
- ✓ You must own or control every domain you request a certificate for.
- ✓ Card payments go through Stripe; we never see or store your card number. Crypto payments, where offered, are final.
- ✓ We can suspend or terminate accounts for abuse, unlawful domain requests, or a reversed/disputed payment — see Report abuse.
- ✓ You can delete your own order or account data at any time — see Privacy.
- ✓ This is a stopgap version of these terms — see the notice near the bottom.
1. Who we are
SSLCloak (“SSLCloak,” “we,” “us”) is operated by SSLCloak LLC, an Ohio limited liability company. These terms govern your access to and use of the SSLCloak website and certificate-ordering service (the “Service”). By creating an account or placing an order, you're agreeing to them.
2. Your account
You need to be at least 18 (or the age of majority where you live) and able to form a binding contract to use the Service. You're responsible for keeping your login credentials confidential and for all activity under your account — enable two-factor authentication (TOTP or a passkey/security key, both available from Account settings) if you want an extra layer of protection. We don't offer SMS-based two-factor authentication, by design — see Privacy. If you believe your account has been compromised, contact us immediately at support@sslcloak.com.
3. How certificate ordering & issuance works
We are not a Certificate Authority. SSLCloak is a facilitator that places your order with Let's Encrypt or ZeroSSL — whichever you choose at checkout — using the real ACME protocol. They are the entities that actually validate your domain and issue the certificate; we relay the request, handle payment, and give you a simpler ordering experience on top. When you place an order, you're also agreeing to the issuing CA's own Subscriber Agreement, as published in their certificate policy repositories (currently linked from letsencrypt.org and zerossl.com) — those terms apply to the certificate itself, alongside ours.
Issuance isn't guaranteed. It depends on domain validation succeeding (proving you control the domain(s) requested) and on the issuing CA's own systems being available — both are outside our control. If validation fails or a CA is unavailable, we'll tell you what we can see on our end, but we can't compel either outcome.
4. Your responsibilities
You represent and agree that:
- •You own or are otherwise authorized to request a certificate for every domain you submit — domain-control validation happens at the CA level, but the underlying authorization is your representation to us.
- •You won't use the Service to request certificates for domains used for phishing, malware distribution, impersonation of a person or organization you're not authorized to represent, or any other unlawful purpose.
- •The billing and account information you provide is accurate, and you'll keep it up to date.
- •You won't attempt to circumvent rate limits, probe for vulnerabilities, or otherwise interfere with the Service outside of good-faith security research — if that's what you're doing, tell us first at abuse@sslcloak.com.
If you breach any of these, or a claim is made against us arising from a domain you weren't actually authorized to request a certificate for, you agree to indemnify and hold us harmless from the resulting losses, costs, and reasonable legal fees.
5. Fees, billing & refunds
Card payments are processed by Stripe — we never see or store your full card number; Stripe collects it directly. Where crypto payment is offered, it's handled by our payment processor and, like most crypto transactions, is final once confirmed on-chain — we can't reverse it on our end.
Subscription orders renew automatically until cancelled; you can turn off renewal reminders or cancel from Account settings or Order status. If an order hasn't been issued yet, contact support@sslcloak.com for a refund. Once a certificate has been issued, we're generally not able to refund it, since the underlying validation work and any CA-side costs have already been incurred — we'll still look at unusual cases individually if you reach out.
6. No warranty
The Service is provided “as is,” without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We don't currently commit to an uptime service-level agreement. We're not responsible for outages, delays, or issuance failures caused by Let's Encrypt, ZeroSSL, DNS providers, or other systems outside our infrastructure — including a CA being removed from a browser's trusted root store, which is a decision made by browser vendors, not us.
7. Limitation of liability
To the extent permitted by law, SSLCloak's total liability to you for any claim arising from the Service is limited to the greater of $100 or the fees you paid us in the 12 months before the claim arose. We're not liable for indirect, incidental, consequential, or lost-profit damages. Nothing here limits liability for gross negligence, willful misconduct, or anything else the law doesn't allow us to limit.
8. Suspension & termination
We may suspend or terminate your account for abuse, unlawful domain requests, breach of these terms, or a reversed or disputed payment. You can close your own account and permanently delete your data at any time — see Privacy. Ending your account doesn't automatically revoke certificates already issued to you; if you need a certificate revoked (for example, because a private key was compromised), contact abuse@sslcloak.com.
9. Privacy
How we handle your data is covered separately on the Privacy page, which is part of this agreement by reference.
10. Changes to these terms
We may update these terms as the Service changes. We'll update the date at the top of this page, and for material changes, email the address on your account before they take effect.
11. Governing law
These terms are governed by the laws of the State of Ohio, without regard to conflict-of- law principles. If a dispute comes up, please contact support@sslcloak.com first — most things are resolvable without involving a court.
This is a stopgap version of these terms, written to reflect how SSLCloak actually operates today, not a final document. It hasn't been through formal legal review, and some clauses that a fully-drafted agreement would normally include — for example, dispute-resolution mechanics like arbitration — have been deliberately left out rather than guessed at. Before real-world launch, this should be reviewed by qualified legal counsel.
Questions about these terms? Reach us at support@sslcloak.com.