StepCert is built so that we never see what you record. This policy explains the little personal information we do handle: what you give us to buy and use a licence, and what this website needs to run.
Who we are
StepCert is run by Keith Taynton, a sole trader based in the UK. In this policy, “StepCert”, “we” and “us” mean the business that sells StepCert and runs stepcert.com. We are the controller of the personal information described here. For anything about this policy or your information, email sales@stepcert.com.
In short
Your recordings, screenshots, step text, notes, branding and settings stay in your browser on your computer. The extension never sends them to us or to anyone else.
The extension contacts only stepcert.com, and only to check your licence.
We keep your email address and licence details so you can buy, use and manage StepCert. Stripe handles payment; we never see your card details.
No analytics, advertising or tracking, in the extension or on this website. We don't sell personal information.
The StepCert extension
What stays on your computer
Everything you record or make with StepCert is kept in your browser's own storage, in the browser profile you use StepCert in: screenshots, step text (including values typed while recording, except password, card-number and similar fields, which are recorded as dots), page titles and addresses, notes, branding and settings. None of it is sent to us or to anyone else. StepCert writes the step wording and looks for personal details to suggest hiding on your computer, without any AI or other online service.
StepCert's recorder is loaded into the web pages you open so it's ready when you press Start recording, but it ignores everything on a page until a recording is running.
Files leave your computer only when you export or save them (a document, a course package, a .walk file or a settings template) and put them somewhere yourself. What happens to them then is up to you and wherever you send them.
What the extension sends to us
Only what we need to check your licence, and only to stepcert.com:
When you sign in: your email address, your licence key, a random ID the extension creates for that browser, and a short description such as “Chrome on Windows”. The extension doesn't keep your licence key; it keeps the sign-in tokens we send back.
About once a day while you use it: a sign-in token and that browser's random ID, to confirm the licence is still active.
When you sign out: the sign-in token, so we can remove that browser.
When you choose Manage subscription: a sign-in token, so we can open your Stripe billing page.
We use this only to confirm your licence, limit it to 3 browsers at a time, sign out a browser whose sign-in has been copied elsewhere, and open your billing page. The extension has no analytics, crash reporting or tracking.
Your recordings, documents and courses
We have no access to your recordings, the files you export or the courses you build, so we don't process any personal information in them, either for ourselves or on your behalf. You, or the organisation you work for, are responsible for them: for being allowed to record the systems and information you capture, for hiding anything that shouldn't be shared, and for how the files are stored, shared and kept.
StepCert's tools help, but check every picture and every step's text before you share anything. Suggest hiding doesn't find every kind of personal detail, Hide boxes cover pictures rather than text, and values typed while recording appear in the step text and in courses.
Courses you build run in your learning management system (LMS) and send learners' results only to it, or to the learning record store it tells the course to use. How those results are used and kept is up to your organisation and its LMS provider. Played outside an LMS, a course keeps the learner's progress in their own browser.
Buying and managing a licence
Payments are handled by Stripe. For purchases on stepcert.com, Stripe acts as merchant of record: it takes the payment, works out and collects any sales tax or VAT, and processes your card and billing details under its own privacy policy. We never see or store your card details.
From Stripe we receive and keep your email address, your Stripe customer and subscription IDs, and your subscription's status and dates. We create your licence key and store it with them. We use these to deliver your licence key, let you sign in, open your billing page, answer your questions and keep the records the law requires.
For each browser signed in to your licence we keep its random ID, its description (such as “Chrome on Windows”), when it signed in and last checked in, and a scrambled (hashed) copy of its current sign-in token, never the token itself. To spot a sign-in copied to another browser, we also keep scrambled copies of sign-in tokens that have already been used.
Emails
We email your licence key when you buy and whenever you ask for it on Manage your licence. These emails are sent through Cloudflare's email service and are about your licence only. So that the Manage page can't be used to flood someone's inbox, we send at most one email per address every 10 minutes, and keep a scrambled (hashed) copy of the address and the time to do that. If you email us, we keep the conversation so we can help you.
This website
stepcert.com is hosted by Cloudflare. Like any web host, Cloudflare processes technical information such as your IP address and browser details to deliver the site and protect it from abuse. We use:
your approximate country, as Cloudflare works it out from your IP address, to show prices in your currency (we don't store it);
your IP address, briefly, to limit how often sign-in, checkout and licence-email requests can be made;
short-lived technical logs of requests and errors, to find and fix problems and to look into abuse.
The website has no analytics, advertising or tracking scripts and loads no fonts or scripts from other companies. It sets no cookies of its own. Cloudflare may set a cookie that's strictly necessary to protect the site, and Stripe's checkout and billing pages, which are on Stripe's own website, use cookies under Stripe's policy. The demo course on this site keeps your progress in your browser's own storage, on your device only.
Why we're allowed to use it
Under UK and EU data protection law, we rely on:
our contract with you, to issue your licence key, let you sign in, keep to the 3-browser limit, open your billing page and help you;
our legitimate interests in running a secure, working service: rate limits, technical logs, spotting copied sign-ins and showing prices in your currency;
legal obligations, to keep purchase and tax records.
Who we share it with
We don't sell or rent personal information, and we don't share it for advertising. We share it only with the companies that run parts of the service, Stripe (payments, billing and tax) and Cloudflare (hosting, the licence database and sending email), and our email provider for messages you send us; with others when the law requires it or to protect our rights; and with a buyer or successor if the business is sold or reorganised, who must keep to this policy.
Where it's processed
Stripe and Cloudflare operate around the world, including in the United States, so information we hold may be processed outside the UK and the European Economic Area. Where it is, it's protected by the safeguards data protection law requires, such as standard contractual clauses or an adequacy decision.
How long we keep it
Licence and purchase records: while your licence is active, and afterwards for as long as we need them for tax, accounting and legal reasons.
Signed-in browsers: until you sign out, a newer sign-in replaces them, or they go 60 days without use. A browser unused for 60 days is signed out, and its record is deleted when that browser or your licence is next used to sign in, or sooner if you ask.
Scrambled copies of used sign-in tokens: cleared out regularly once they're more than 60 days old.
The licence-email limit: the scrambled address and time stop being used after 10 minutes and are cleared as later requests come in.
Technical logs: a few days.
Emails with us: as long as we need them to help you and to keep our business records.
How we protect it
Sign-in tokens are signed so they can't be forged, change every time they're used, and are stored on our side only in scrambled form. The extension doesn't keep your licence key. Your billing page opens only for the address the licence was bought with: from the extension, from a time-limited link we email to that address, or through Stripe's own sign-in with a one-time code sent to it. Sign-in and licence-email requests are rate-limited.
Your rights
Depending on where you live, you can ask for a copy of the personal information we hold about you, ask us to correct or delete it, object to or restrict how we use it, or ask for it in a form you can take elsewhere. Email sales@stepcert.com and we'll reply within a month. We may need to keep records the law requires, and if we delete your licence details, your licence stops working.
In the UK you can complain to the Information Commissioner's Office (ico.org.uk), and in the EU to your local data protection authority. We'd be grateful for the chance to put things right first.
In US states with privacy laws, such as California: we don't sell personal information or share it for targeted advertising, and we won't treat you differently for using your rights.
Children
StepCert is for people at work and isn't aimed at children. We don't knowingly collect children's personal information.
Changes to this policy
If we change this policy we'll publish the new version here and update the date at the top. If a change affects how we use information we already hold, we'll also email licence holders.