How Stamp collects, uses, retains, and shares personal data. Written to match exactly what the platform does today; the engineering-honest companion to this document is our security page.
EFFECTIVE: 11 June 2026 (DRAFT) · CONTACT: VERIFY@STAMPCERTIFIED.COM
Stamp is operated by 3DGE, a sole proprietorship registered in the Netherlands. Our trading address is Amsterdam, Netherlands. References to "we," "us," and "Stamp" in this policy mean 3DGE acting in its capacity as the operator of the Stamp service.
A successor Dutch B.V. is planned. When that entity is incorporated, this policy will be amended to name it as the controller, and existing data subjects will be notified of the transfer via the email address on file.
For privacy questions, exercising your rights, or any contact under this policy, email verify@stampcertified.com. A dedicated privacy@ alias will be made available; until then, verify@ is routed and monitored.
This policy covers personal data we collect through:
/approve/[token], /r/[token], and /retract/[token].It does not cover third-party websites we link to, even when those links carry a Stamp badge. Each third party operates its own privacy policy.
We collect different categories of data depending on who you are. Each category is listed below with what we collect and why.
When a reference customer signs into the approval flow via LinkedIn OAuth, or starts a capture via /r/[token], we receive and store:
We act as the controllerfor this data. The reference customer interacts with Stamp directly through the consent flow; the vendor does not transmit this personal data to us on the customer's behalf.
What publishes on a certificate depends on the consent level chosen by the reference customer:
We do not use any personal data to train AI models, ours or anyone else's.
Under the GDPR, we rely on the following legal bases:
We share data with the subprocessors listed below. Each sees only the minimum required for its role. The full technical description, what each receives and what it does not, lives on our security page.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU (Frankfurt) |
| Vercel | Hosting and delivery | EU edge + US (DPA in place) |
| Anthropic | AI drafting and prescreening | US (SCC-covered) |
| DigiCert | RFC 3161 timestamping | US |
| Resend | Transactional email | EU + US (DPA in place) |
| KvK | NL business registry lookup | NL |
| VIES | EU VAT registry lookup | EU |
| OAuth identity sign-in | EU + US |
We do not sell, rent, or trade personal data. We do not share data with advertising networks or data brokers.
We may share data with competent authorities if compelled by valid legal process. Where the law allows, we will notify the affected data subject.
Our primary data store sits in the EU (Supabase, Frankfurt). Some subprocessors operate from the US (Anthropic, DigiCert, Vercel edge). For those, we rely on the European Commission's Standard Contractual Clauses (SCCs) where adequacy decisions are unavailable, plus supplementary technical measures (encryption in transit, redaction where applicable, and minimisation of what is transferred).
We retain personal data only for as long as we need it for the purposes set out in this policy:
data_retention_until column on the identity mapping). The verifiability of an active certificate requires the underlying identity record to remain available.A current limitation, stated plainly. The retention timestamps above are populated correctly at insert time, but no automated purge cron runs against them yet. Deletion happens by hand today, by a named operator, within the statutory window of any request. Automating the purge is on the engineering roadmap. We document this on the security page as well; we would rather tell you here than have you discover it through a request.
As a data subject, you have the right to:
To exercise any of these rights, email verify@stampcertified.com. We will respond within one month, with the option of a two-month extension where the request is complex.
Stamp uses only the cookies strictly necessary to operate the service:
We do not use analytics cookies, marketing cookies, advertising cookies, or third-party tracking. We do not load Google Analytics, Meta pixel, or comparable trackers. Because we use only strictly-necessary cookies, no consent banner is required under Dutch implementation of the ePrivacy Directive.
The technical and organisational measures protecting personal data are documented in detail on our security page. That page is updated when the underlying controls change, and we suggest reading it as a companion to this policy. Key points:
We update this policy when our practices or applicable law require it. Material changes (anything affecting your rights, the legal bases we rely on, or the categories of subprocessors) are notified to affected data subjects via email and surfaced as a banner on this page for at least 30 days. Editorial corrections are noted in the version history at the bottom of this document.
Privacy enquiries, rights requests, and complaints: verify@stampcertified.com. A dedicated privacy@stampcertified.com alias is planned; until it is in place, verify@ is the canonical address and is read by a named operator.