DRAFT, PENDING LEGAL REVIEW.This document accurately reflects Stamp's current technical reality but has not yet been reviewed by external counsel. Use it as a working draft; do not rely on it as final legal advice or a binding instrument until this banner is removed.
Home / Legal / Privacy Policy

Privacy Policy

How Stamp collects, uses, retains, and shares personal data. Written to match exactly what the platform does today; the engineering-honest companion to this document is our security page.

EFFECTIVE: 11 June 2026 (DRAFT) · CONTACT: VERIFY@STAMPCERTIFIED.COM

1Who we are

Stamp is operated by 3DGE, a sole proprietorship registered in the Netherlands. Our trading address is Amsterdam, Netherlands. References to "we," "us," and "Stamp" in this policy mean 3DGE acting in its capacity as the operator of the Stamp service.

A successor Dutch B.V. is planned. When that entity is incorporated, this policy will be amended to name it as the controller, and existing data subjects will be notified of the transfer via the email address on file.

For privacy questions, exercising your rights, or any contact under this policy, email verify@stampcertified.com. A dedicated privacy@ alias will be made available; until then, verify@ is routed and monitored.

2Scope of this policy

This policy covers personal data we collect through:

  • The public website at stampcertified.com (the directory, marketing pages, verify pages).
  • The Stamp dashboard used by vendor accounts.
  • The reference-customer flows at /approve/[token], /r/[token], and /retract/[token].
  • Transactional communications we send (verification invites, capture invites, certificate delivery emails).

It does not cover third-party websites we link to, even when those links carry a Stamp badge. Each third party operates its own privacy policy.

3Personal data we collect

We collect different categories of data depending on who you are. Each category is listed below with what we collect and why.

3.1. Visitors to the website

  • Server logs: IP address, user agent, referrer, path, timestamp. Retained for up to 30 days for security monitoring and debugging.
  • Essential session cookies: see Section 10.

3.2. Vendor accounts (the paying audience)

  • Account identifiers: email, full name, password hash, company name, role within the company.
  • Company information: trading name, country, KvK number, VAT number, logo, public profile fields (tagline, audience, founded year, bio).
  • Business-verification artefacts: KvK / VIES lookup results, reviewer notes, certificate metadata.
  • Operational data: assets you submit, captures you start, embed settings, retraction events, support correspondence.

3.3. Reference customers (the people who confirm verifications)

When a reference customer signs into the approval flow via LinkedIn OAuth, or starts a capture via /r/[token], we receive and store:

  • LinkedIn-verified identity: full name, job title, employer, LinkedIn profile identifier.
  • Email address used to receive the invite.
  • Consent records: timestamped confirmations of each individual claim (metric, quote, narrative), the consent level the customer chose (named or anonymised), and the IP address from which the confirmation was submitted.
  • Capture responses: the customer's free-text answers to the guided questions.

We act as the controllerfor this data. The reference customer interacts with Stamp directly through the consent flow; the vendor does not transmit this personal data to us on the customer's behalf.

3.4. What appears publicly

What publishes on a certificate depends on the consent level chosen by the reference customer:

NamedInitials only ("Jane D."), job title, employer, plus the confirmed metrics and quote. Full name and email are not public.
AnonymisedSeniority band, function, industry, and company size band. Initials, name, employer, and email are not public. The mapping back to the verified person exists only inside the identity vault and is readable to Stamp reviewers only.

4How we use it

  • Operate the verification service: process captures, run prescreening, issue certificates, generate embeds, and serve the public directory.
  • Identity verification: confirm a reference customer is who they say they are via LinkedIn OAuth, registry checks (KvK, VIES), and reviewer judgment.
  • Account administration and billing: manage vendor accounts and (once billing is wired) process payments.
  • Transactional communications: send confirmation, approval, reminder, retraction, and delivery emails.
  • Security and abuse prevention: monitor for fraud, misuse, and security incidents; respond to law- enforcement requests where legally required.
  • Service improvement: aggregate, de-identified usage statistics inform product decisions.

We do not use any personal data to train AI models, ours or anyone else's.

Under the GDPR, we rely on the following legal bases:

ContractOperating vendor accounts; processing reference- customer confirmations that the customer submitted through the consent flow; issuing and delivering certificates.
ConsentPublishing the reference customer's named or anonymised attribution; storing capture responses and confirmations. Consent is recorded with a timestamp and an audit trail and can be withdrawn at any time without affecting the lawfulness of prior processing.
Legitimate interestsSecurity monitoring, fraud prevention, integrity of the public certificate record, and operational improvement. We balance these against the rights of data subjects and apply minimisation throughout.
Legal obligationResponding to lawful requests from competent authorities, retaining records to the extent required by Dutch and EU law.

6Who we share it with

We share data with the subprocessors listed below. Each sees only the minimum required for its role. The full technical description, what each receives and what it does not, lives on our security page.

SubprocessorPurposeLocation
SupabaseDatabase, authentication, storageEU (Frankfurt)
VercelHosting and deliveryEU edge + US (DPA in place)
AnthropicAI drafting and prescreeningUS (SCC-covered)
DigiCertRFC 3161 timestampingUS
ResendTransactional emailEU + US (DPA in place)
KvKNL business registry lookupNL
VIESEU VAT registry lookupEU
LinkedInOAuth identity sign-inEU + US

We do not sell, rent, or trade personal data. We do not share data with advertising networks or data brokers.

We may share data with competent authorities if compelled by valid legal process. Where the law allows, we will notify the affected data subject.

7International transfers

Our primary data store sits in the EU (Supabase, Frankfurt). Some subprocessors operate from the US (Anthropic, DigiCert, Vercel edge). For those, we rely on the European Commission's Standard Contractual Clauses (SCCs) where adequacy decisions are unavailable, plus supplementary technical measures (encryption in transit, redaction where applicable, and minimisation of what is transferred).

8Retention

We retain personal data only for as long as we need it for the purposes set out in this policy:

Active certificatesIdentity records linked to an active certificate are retained while the certificate is live, by default up to three years from creation (the data_retention_until column on the identity mapping). The verifiability of an active certificate requires the underlying identity record to remain available.
Withdrawn / expired certificatesOnce a certificate is withdrawn or expires, we retain only what the audit trail requires (the fact of the certificate, its status, its issuance timestamp). The identity record is purged on the schedule above.
Server logsUp to 30 days for security purposes.
Email logsRetained as long as the recipient relationship is active, plus a reasonable post-relationship period for audit (one year).

A current limitation, stated plainly. The retention timestamps above are populated correctly at insert time, but no automated purge cron runs against them yet. Deletion happens by hand today, by a named operator, within the statutory window of any request. Automating the purge is on the engineering roadmap. We document this on the security page as well; we would rather tell you here than have you discover it through a request.

9Your rights under the GDPR

As a data subject, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Rectification of inaccurate or incomplete data.
  • Erasure("the right to be forgotten") where the conditions of Article 17 GDPR are met. Note that the integrity of an active public certificate depends on the underlying identity record; in some cases we will instead withdraw the certificate (which makes the identity record unnecessary for verification) and then purge.
  • Restriction of processing.
  • Data portability for data you provided to us.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing. For reference customers, withdrawing consent is also the retraction mechanism for the certificate; one click from any past Stamp email triggers it.
  • Lodge a complaint with the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or another supervisory authority in your EU member state.

To exercise any of these rights, email verify@stampcertified.com. We will respond within one month, with the option of a two-month extension where the request is complex.

10Cookies

Stamp uses only the cookies strictly necessary to operate the service:

  • Session cookies set by Supabase to keep you signed in.
  • CSRF tokens on forms that mutate state.

We do not use analytics cookies, marketing cookies, advertising cookies, or third-party tracking. We do not load Google Analytics, Meta pixel, or comparable trackers. Because we use only strictly-necessary cookies, no consent banner is required under Dutch implementation of the ePrivacy Directive.

11Security

The technical and organisational measures protecting personal data are documented in detail on our security page. That page is updated when the underlying controls change, and we suggest reading it as a companion to this policy. Key points:

  • Identity records live in a separated table with row-level security; only the Stamp reviewer role can read them.
  • Encryption in transit (TLS) and at rest (AES-256) is inherited from our database provider.
  • Vendor-uploaded asset text is redacted locally on our infrastructure before any AI call.
  • Anonymous certificates scrub name / role / company at the data layer, not just hide them in the UI.

12Changes to this policy

We update this policy when our practices or applicable law require it. Material changes (anything affecting your rights, the legal bases we rely on, or the categories of subprocessors) are notified to affected data subjects via email and surfaced as a banner on this page for at least 30 days. Editorial corrections are noted in the version history at the bottom of this document.

13Contact

Privacy enquiries, rights requests, and complaints: verify@stampcertified.com. A dedicated privacy@stampcertified.com alias is planned; until it is in place, verify@ is the canonical address and is read by a named operator.