1. Who we are
Certo Partners LLC ("Certo Partners", "we", "us") is a bespoke application studio. We design, build and operate custom mobile, web and backend systems for small and mid-size businesses.
For questions about this policy or about data we hold, contact [email protected].
2. What this policy covers
This policy covers three distinct things, which are worth separating because they involve very different data:
- This website — certopartners.com, which is a static marketing site.
- Google user data — information our applications access through Google APIs when you authorize them.
- Applications we build and operate — software we run on behalf of a client, where the client is the data controller and we act as a processor.
3. Information collected through this website
Essentially none. This site is static. It has no analytics, no tracking pixels, no advertising scripts, no cookies set by us, and no forms.
Our hosting provider, Cloudflare, processes standard request data — IP address, user agent, requested URL, timestamp — to serve the site and protect it from abuse. We do not use that data to build profiles and we do not combine it with any other source.
If you email us at the address above, we receive whatever you choose to put in that email and keep it as business correspondence.
4. Google user data
Some applications we build connect to Google APIs on your behalf. When you authorize one, you are asked to consent to specific scopes, and we access only what those scopes cover.
What we access
- Google Ads data (scope
https://www.googleapis.com/auth/adwords) — read-only keyword planning metrics: average monthly search volume, competition level, and top-of-page bid ranges for keywords our software supplies. We do not read, create or modify campaigns, ads, budgets, billing details, conversion data or customer lists. - Google Business Profile and Places data — publicly listed business information such as name, address, rating, review count, website and opening hours. This is public listing data, not personal data about you.
How we use it
Solely to produce the analysis the application exists to produce — for example, scoring how competitive a local service market is. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalized machine learning or AI models.
How we store and share it
Derived metrics are stored in our application databases as described in section 6. We do not transfer Google user data to third parties except as needed to provide the application to you, to comply with law, or as part of a merger or acquisition in which you would be notified in advance.
Limited Use. Certo Partners' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Revoking access
You can withdraw our access at any time at myaccount.google.com/permissions. Revoking stops all future access immediately. To also have data already derived from your Google account deleted, email us and we will remove it within 30 days.
5. Data in applications we build and operate
When we run an application for a client, the client decides what personal data is collected and why. They are the data controller; we are a processor acting on their documented instructions, and our handling is governed by our agreement with them.
Depending on the application, that can include contact details, addresses, service history, and — where a product includes call handling — call recordings and transcripts. Where a voice application records or transcribes a call, callers are informed at the start of the call.
If you are an end user of a product we operate for a client and want your data accessed, corrected or deleted, contact that business directly. If you contact us instead, we will forward your request to them and support them in fulfilling it.
6. Storage, security and location
Data is stored on infrastructure operated by Google Cloud Platform, Microsoft Azure and Cloudflare, in data centers located in the United States.
- Traffic is encrypted in transit with TLS.
- Data at rest is encrypted using the storage encryption provided by those platforms.
- Credentials and API keys are held in access-controlled secret storage, never in source code.
- Access is limited to the people who need it to build or operate the system.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your data, we will notify you and the relevant client without undue delay.
8. Retention and deletion
Business correspondence is kept as long as it is commercially useful. Data processed for a client is retained per our agreement with that client and deleted or returned at the end of the engagement. Data derived from Google APIs is deleted within 30 days of a deletion request or of access being revoked, whichever comes first.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. Residents of California, Colorado and Nevada, and individuals in the EEA and UK, have specific statutory rights along these lines.
Email [email protected] to exercise any of them. We respond within 30 days and do not charge a fee or discriminate against you for asking.
10. Children
Our website and services are not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us data, email us and we will delete it.
11. Changes to this policy
We update this policy when our practices change. The effective date at the top always reflects the current version. Material changes affecting how we handle data you have already given us will be communicated directly where we have a way to reach you.
12. Contact
Certo Partners LLC
[email protected]