1. Who we are
Nyvarra (“we”, “us”) runs nyvarra.app, a service for issuing, keeping and checking digital certificates. Nyvarra is operated from Pakistan by its founder, Fateh Alam.
For anything in this policy, write to info@nyvarra.app. We answer privacy requests within 30 days.
2. Whose information this is
Nyvarra holds two kinds of information, and who is responsible for it differs.
Information about you as a user
Your account, your Passport, your payments and how you use the site. We decide how this is used, and this policy describes it.
Certificates an organization issues
When an organization issues certificates on Nyvarra, it decides who receives them and what they say. It gives us recipients' names, email addresses and certificate details so we can sign, send and verify them on its behalf. The issuing organization is responsible for having the right to share that information. If you received a certificate and want something about it changed, the issuer is usually the right place to start; we'll help if you write to us.
3. What we collect
- Account details: your name, email address, password (stored only as a secure hash by our sign-in provider), and the date and version of the Terms and this policy you accepted.
- Organization details: for issuers, the organization's name, website, contact person, logo, and what it submits for review, such as proof that it controls its web domain.
- Certificates: recipients' names and email addresses, what each certificate is for, dates, results the issuer chooses to include, serial numbers, and the digital signature that fixes the contents.
- Passport: certificates you keep, badges you import from other platforms, your profile details, and which of them you make public.
- Payments: your plan, invoices, and any receipt you upload for a bank transfer. We don't receive or store card numbers.
- Checks: when anyone checks a certificate, we record when, the result, the checker's IP address and browser type. Issuers see how many times a certificate was checked, not who checked it.
- Emails we send: the address, what was sent and whether it was delivered, opened or bounced, as reported by our email provider.
- Security records: sign-ins, important account changes, IP addresses and browser type, kept to protect accounts and investigate misuse.
- Messages: anything you send us by email or through the site.
We don't use advertising or analytics trackers, and we don't sell or rent anyone's information.
4. How we use it
- To run the service: create accounts, sign and send certificates, keep Passports, and answer checks.
- To show the result of a check to whoever checks a certificate. That is the point of the service, so the details on a certificate are visible to anyone who has its QR code or serial.
- To review organizations before they can issue, so a certificate's issuer is who it says it is.
- To keep Nyvarra secure: detect fraud, forged certificates, abuse and attacks, including checking whether a connection comes from an anonymizing network when someone signs up, issues or pays.
- To bill organizations and keep financial records the law requires.
- To send emails the service needs, such as certificates, sign-in and account notices, and receipts. We don't send marketing email unless you ask for it.
- To answer your messages and improve the service.
5. What is public
A certificate's verification page shows the recipient's name, the issuer, what it was awarded for, the date, and its current status (current, corrected or withdrawn). Anyone with the QR code, link or serial can see it.
A withdrawn or corrected certificate stays on record as withdrawn or corrected, so an old copy can't be passed off as current.
On your Passport, you choose what is public. You can hide a certificate from your Passport at any time; that doesn't change the issuer's record.
Approved issuers appear in the public issuer directory with their name, website and verification level.
6. Who processes it for us
We use a small number of providers to run Nyvarra. Each handles information only to provide its service to us.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage | Asia-Pacific (Sydney, Australia) |
| Cloudflare | Hosting, delivery and protection of the website | Global network |
| Resend and Mailtrap | Sending email | Their own infrastructure |
| IPinfo | Telling whether a connection comes from a VPN or proxy | Their own infrastructure |
Because these providers operate outside Pakistan, your information may be stored and processed in other countries. We only use providers that protect it with encryption and access controls.
We may also share information when the law requires it, to protect people from fraud or harm, or with a buyer if Nyvarra is ever sold, in which case this policy continues to apply.
7. How long we keep it
- Accounts and Passports: until you delete your account.
- Certificates: for as long as the issuing organization keeps them, so they can still be checked. If an issuer leaves Nyvarra, we keep its certificates checkable unless it asks us to withdraw them.
- Payment records: as long as tax and accounting law requires.
- Check, email and security logs: only as long as they are useful for security and support.
8. Your choices and rights
Wherever you live, you can ask us to:
- show you the information we hold about you, and give you a copy;
- correct anything that's wrong;
- delete your account and the information that belongs to it;
- stop using your information for something you object to.
Write to info@nyvarra.app. We may need to confirm it's you first. Some things we can't delete, such as records the law requires us to keep, or a certificate an organization issued to you, which belongs to the issuer's records; we'll pass your request to the issuer and tell you what we did.
If you're not satisfied with our answer, you may also complain to the data protection authority where you live.
9. Security
Every certificate is signed with an Ed25519 key, all traffic is encrypted, database access is restricted row by row, and administrator accounts require two-factor authentication. No system is perfectly secure; if a breach affects your information, we'll tell you and the relevant authorities as the law requires. Read more on our security page.
11. Children
Schools and other organizations may issue certificates to people under 18. They are responsible for having permission to do so. Someone under 18 should only create their own account with a parent's or guardian's permission.
12. Changes to this policy
When we change this policy, we'll update the version and date at the top. If a change matters, we'll tell account holders by email or on the site before it takes effect, and ask you to accept the new version when you next sign in.