1. About this Privacy Policy
This Privacy Policy explains how Rotaract South Asia MDIO (“RSAMDIO”, “we”, “us”, or “our”) handles personal information in Rotaract Certify, available at https://certify.rsamdio.org (the “Service”).
Rotaract Certify helps Rotaract organizers create activities, manage recipient records, and make digital certificates available for download. ZeoSpec develops and supports the platform for RSAMDIO.
This Policy applies to public visitors, certificate recipients, and invited organizers or managers who use the Service. It does not replace the privacy notice of an individual Rotaract club, event organizer, or other organization that collected your information for an activity.
2. Who is responsible for information
RSAMDIO operates the Service. For a particular activity, the organizer that decides which recipient information to collect, why to collect it, and how to use it will generally be responsible for that activity’s recipient information. RSAMDIO and ZeoSpec may process that information to operate, secure, support, and improve the Service.
Organizers must ensure they have the authority required to upload and use recipient information.
3. Information we process
3.1 Public visitors and certificate recipients
When you visit the public catalog or an activity page, we may process:
- activity information published by organizers, such as title, description, date, certificate design, and field labels
- technical and usage information such as browser type, approximate device details, IP address, pages or features used, and event timestamps
- the email address, redeem code, or other lookup value you submit to find a certificate
- certificate data returned for a successful lookup, including recipient name, lookup value, certificate status, download status, and activity-specific certificate fields
- information relating to download attempts and when a certificate is marked downloaded
The PDF is generated in your browser from the certificate design and data returned for your lookup. We do not need to store the generated PDF merely because you download it.
3.2 Organizers and managers
If you are invited to the organizer workspace, we may process:
- Google account information made available through Google sign-in (such as name, email, account identifier, and profile image where available)
- your role and access scope (platform administrator or activity manager)
- activity details, certificate designs, placement settings, field schemas, recipient records, imports, exports, and manager invitations
- support communications and operational records
- actions taken in the organizer workspace where needed for security or administration
3.3 Recipient information uploaded by organizers
Organizers may upload recipient information such as names, email addresses, redeem codes, selected certificate design, certificate status, and custom fields configured for an activity. Custom fields are chosen by organizers and may appear on a certificate or be retained only as an activity record.
Organizers must not use the Service for sensitive personal information unless RSAMDIO has expressly approved that use and the organizer has an appropriate legal basis and safeguards.
4. How we use information
We use information to:
- display the public catalog and activity pages
- authenticate invited organizers and enforce role-based access
- create, manage, issue, retrieve, and support certificates
- process certificate lookup requests and reduce unauthorized guessing or abuse
- enable browser-based certificate generation and record download status
- operate CSV, public Google Sheets imports, and automated API webhook integrations selected by organizers
- host and deliver certificate-design assets
- maintain records, resolve errors, provide support, and protect the Service
- understand aggregate product use and improve reliability
- comply with legal obligations and protect RSAMDIO, users, and the Service
5. Certificate lookup, security, and access limits
Public visitors can browse activity information, but recipient lists are not publicly browseable.
To retrieve a certificate, you submit an activity-specific lookup value (such as an email address or redeem code). The lookup is handled by a secure backend check (verifyCertificate) rather than by public access to recipient records. A successful match returns the minimum certificate data needed to display one certificate.
This is not the same as identity verification. Anyone who knows or can correctly guess a valid lookup value may be able to retrieve that certificate. Do not share redeem codes or other lookup values unnecessarily. Organizers should use sufficiently unpredictable codes where email lookup is unsuitable.
The lookup service uses Firebase App Check with Google reCAPTCHA v3 and durable rate limiting to reduce automated abuse. These controls reduce risk but cannot guarantee that unauthorized access, attacks, or errors will never occur.
6. Service providers and data locations
We use service providers to operate the Service, including:
- Firebase / Google Cloud: Authentication, Firestore, Realtime Database, Cloud Functions, App Check, and Analytics. Realtime Database and Cloud Functions are configured for the
asia-southeast1region. Other Google processing may occur in locations selected or operated by Google. - Google reCAPTCHA: reCAPTCHA v3 supports App Check for certificate lookup abuse prevention.
- Netlify: hosting and delivery of the website and related server routes.
- Cloudflare R2: storage and public delivery of organizer-uploaded certificate design images through
cert.rsamdio.org. - Google Sheets: when an organizer pastes a public Google Sheets URL, the Service may read that public sheet for import. Google’s own terms and privacy practices also apply.
- ZeoSpec: platform development, technical support, security, and operational assistance for RSAMDIO.
We do not sell personal information or use it for third-party advertising. We may disclose information to these providers, to authorized organizers for their activities, where required by law, or where reasonably necessary to prevent fraud, abuse, or harm.
7. Analytics, cookies, and similar technologies
If Firebase Analytics is configured for the Service, it may collect information about use of the public catalog and activity pages, including events such as catalog views, activity opens, certificate lookup outcomes, and download outcomes. These events are intended to measure Service use and reliability. Organizers should not place recipient names, email addresses, redeem codes, or other personal information into analytics fields.
Google and Firebase may use cookies, local storage, device identifiers, or similar technologies to provide analytics, authentication, App Check, security, and service functionality.
You can control cookies through browser settings. Blocking necessary technologies may limit sign-in, security checks, or other features. Where applicable law requires consent before non-essential technologies are used, RSAMDIO will provide an appropriate notice or consent mechanism.
8. Google Sheets and uploaded designs
A Google Sheet import works only for a sheet shared as “Anyone with the link.” That sharing choice can make the sheet accessible to people who receive the link, outside Rotaract Certify. Before using this import option, organizers must confirm that public-link sharing is appropriate. Organizers may instead export a CSV and upload it locally.
Certificate designs are uploaded to Cloudflare R2 and delivered from cert.rsamdio.org so certificates can be rendered in browsers. Organizers must not embed personal information, confidential material, or content they lack rights to use in a design image.
9. Retention
We retain information for as long as reasonably necessary to operate the Service, support certificate issuance and verification, meet legal or organizational recordkeeping needs, resolve disputes, and protect the Service.
- Activity and recipient records may be retained while an activity remains available and afterward where historical certificate records are needed. Inactive activities and their associated recipient data may be purged after an extended period of inactivity to minimize data retention.
- Organizer accounts and access records may be retained until access is removed and for an appropriate security or audit period
- Security and rate-limit records are retained for the period needed to prevent abuse and maintain system integrity
Retention periods may vary by activity and applicable law. RSAMDIO or the relevant organizer may delete or correct records where appropriate, subject to legitimate recordkeeping, legal, security, and fraud-prevention needs.
10. Your choices and rights
Depending on where you live and applicable law, you may have rights to request access to, correction of, deletion of, restriction of, objection to, or a copy of personal information. You may also have rights to withdraw consent where processing is based on consent.
For information in a specific activity, contact that activity’s organizer first. They are best placed to correct recipient details or update a certificate record. You may also contact RSAMDIO or ZeoSpec using the details below.
We may need to verify your identity and authority before responding. Rights are not absolute and may be limited by applicable law, security needs, the rights of others, or legitimate recordkeeping requirements.
11. International processing
Rotaract Certify serves a South Asian Rotaract community and uses providers that may process information in India, Singapore, the United States, and other countries where they or their subprocessors operate. Data-protection laws in those countries may differ from the laws where you live.
12. Children and young people
The Service is not designed for children to use independently. Activities may involve young people, and organizers are responsible for ensuring that collection and use of recipient information complies with applicable age, consent, safeguarding, and parental-authority requirements.
If you believe information about a child or young person was uploaded or used improperly, contact the relevant organizer and RSAMDIO promptly.
13. Changes to this Policy
We may update this Policy to reflect changes to the Service, law, or our data practices. We will post the revised Policy on this page and update the “Last updated” date. Where required by law, we will provide additional notice or obtain consent.
14. Contact us
Rotaract South Asia MDIO
Email: rsamdio@gmail.com
Privacy and product support (ZeoSpec)
Email: rsamdio@gmail.com
15. Additional notices for certain regions
15.1 European Economic Area / United Kingdom
If you are in the EEA or UK, you may have rights under applicable data-protection law, including rights to access, update, delete, rectify, object, restrict processing, receive portable data, and withdraw consent where processing is based on consent. Contact us using the details above to exercise these rights.
15.2 California
If you are a California resident, you may have the right to:
- know what personal information is collected, used, or shared
- request deletion of personal information
- opt out of the sale of personal information (we do not sell personal information)
- not be discriminated against for exercising privacy rights
16. Certificate-specific privacy notes
- Sharing certificates: people may share downloaded certificates; share carefully
- Organizer responsibility: organizers should have a lawful basis before uploading recipient details
- Data minimization: only include details needed for the certificate or activity record
- Lookups: email and redeem codes are used to find the right certificate and are not a public directory
- Download status: may be recorded to understand issuance and support
- Organizer access: only authorized organizers manage recipient lists
- Data breaches: if an organizer's webhook credentials or external data sources are compromised, the organizer is responsible for notifying affected recipients
By using Rotaract Certify, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of information as described here.
