Last updated: 31 August 2026
SAP TLS (saptls.com) is operated by Paul, trading as SAP TLS, based in the United Kingdom. This policy explains what personal data we collect, why, and what rights you have over it. If you have questions, contact us via our contact page.
What we collect
We collect different data depending on how you use the site:
- Browsing the site. Standard technical data (IP address, browser type, pages visited) collected automatically by our hosting and security providers for performance and security purposes.
- Buying a certificate. Name, email address, billing address, and payment details (handled directly by our payment processor – we do not store card details ourselves) are needed to process an order.
- Certificate issuance. Issuing an SSL/TLS certificate requires domain and organisation details, and a Certificate Signing Request (CSR) that you generate and submit. This information is passed to the underlying certificate authority (via our reseller partner, TheSSLStore) to issue the certificate – see “Third parties” below.
- Getting in touch. Anything you send us via email or a contact form, so we can respond.
Why we collect it
We use this data to: fulfil and deliver your certificate order; communicate with you about your order or enquiry; keep the site secure and functioning; and meet our own legal and accounting obligations (e.g. invoicing, tax records).
Third parties
We share data with the following categories of third party, only as needed to run the site and fulfil orders:
- TheSSLStore (our certificate reseller partner) – receives the domain/organisation details and CSR needed to actually issue a certificate.
- Our payment processor – handles payment collection; we do not see or store full card details.
- Hosting and infrastructure providers (currently Hostinger for hosting, Cloudflare for DNS/CDN/security) – process data as part of running the site.
- PostHog (our analytics provider) – collects usage data (such as pages visited, browser/device type, and IP address) to help us understand how the site is used, and records screen sessions and on-page interactions to help us spot and fix usability issues. PostHog processes and stores this data in the EU. No personal data is sold to advertisers.
We don’t sell your personal data to third parties for marketing purposes.
Cookies
The site uses cookies required for core functionality – keeping your cart and login session working – and, via our analytics provider PostHog, cookies used for usage analytics and session recording (recording how visitors move through and interact with pages, to help us find and fix problems). You can control cookies through your browser settings; blocking essential cookies may affect checkout.
How long we keep data
Order and invoicing data is kept for as long as required by UK tax and accounting law (currently up to 6 years). Data related to a certificate order (domain/CSR details) is kept for as long as needed to support that certificate’s lifecycle, then deleted or anonymised.
Your rights
Under UK GDPR, you have the right to access, correct, or request deletion of your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us via our contact page. If you’re not satisfied with our response, you can complain to the UK Information Commissioner’s Office (ico.org.uk).
Changes to this policy
We may update this policy as the site’s functionality changes (for example, when a payment processor is finalised). The “Last updated” date at the top will reflect the most recent revision.