Privacy

Privacy Policy

VSI (VeriScope Identity) is built around data minimization: verification is treated as an event (purpose-limited and time-bound), not a permanent identity profile.

Last updated:

1. Overview

What this policy covers.

This Privacy Policy explains how VSI collects, uses, and protects information when you use our website, verification flows, and related services (the “Service”). It applies to: (a) Platforms/Customers using VSI to request verification events, and (b) Users/Subjects completing a verification flow for a specific event.

2. Our privacy posture

Data minimization is the product strategy.

Event, not profile

Verification is scoped to a purpose and expiry. We aim to avoid creating permanent identity profiles.

Evidence, not surveillance

We provide audit-ready event evidence (IDs, timestamps, scope, status). We do not sell identity data.

3. Information we may collect

Depends on your role and the workflow.

A) Platform / Customer info

  • Account/contact details (name, email, organization, billing contact)
  • Integration details (webhook endpoints, configuration settings, event templates)
  • Billing/payment metadata (transaction IDs, plan details; payment processing may be handled by third parties)

B) Verification event info (metadata)

  • Event ID, creation time, scope/purpose label, expiry/validity window
  • Status (e.g., submitted, pending review, verified, denied)
  • Operational audit fields (timestamps of key steps, method flags, internal notes where applicable)

C) Verification submission info (provided by the User/Subject)

Depending on the event scope, a User may be asked to submit information such as a selfie, an ID photo, or other verification inputs. If collected, these inputs are used to complete the verification event under the scope defined.

D) Technical data

  • Basic device and log data (IP address, user agent, timestamps) for security and abuse prevention
  • Cookies or similar technologies for site functionality (where applicable)

4. How we use information

Only for operating VSI and improving integrity.

  • To operate verification events and generate event evidence/receipts
  • To provide support, onboarding, and integration assistance
  • To prevent abuse, fraud, and security incidents
  • To comply with legal obligations and respond to lawful requests
  • To improve reliability and performance (aggregate analytics where possible)

5. What we share (and what we don’t)

Clear boundaries.

We may share

Event status/evidence with the Platform that requested the verification (e.g., verified/denied, timestamps, scope), and necessary operational details to support dispute posture or audit.

We do not sell

We do not sell personal data. We do not operate a data brokerage model.

Service providers

We may use service providers for hosting, email delivery, forms, analytics, and payments. These providers process data on our behalf for Service operation, subject to their terms and safeguards.

6. Retention

Keep the minimum needed for audit and integrity.

Retention depends on the verification event scope, legal requirements, and operational integrity needs. Generally:

  • Event metadata (event ID, timestamp, scope, status, expiry) may be retained to support auditability and dispute posture.
  • Verification submission artifacts (e.g., images) are intended to be used to complete the event and minimized thereafter, where feasible and consistent with configured workflows.
  • We may retain limited logs for security, abuse prevention, and incident investigation.

Platforms may have their own retention obligations. VSI is not responsible for retention decisions made by Platforms outside VSI.

7. Security

Reduce attack surface through minimization.

We use reasonable administrative, technical, and organizational safeguards designed to protect information. No system is perfectly secure, but VSI is designed to reduce risk by limiting long-term custody of sensitive artifacts and emphasizing event-scoped evidence.

8. Your choices & rights

How to request access or deletion.

Depending on your jurisdiction and role (Platform vs. User/Subject), you may have rights to access, correct, or delete personal information. To make a request, contact us at admin@veriscopeidentity.com.

  • We may need to verify your identity before responding.
  • Some data may be retained where required for legal compliance, security, or audit integrity.
  • If you are a User/Subject, your request may need to be coordinated with the Platform that initiated the event.

9. Children

Not intended for children.

VSI is not intended for use by children. Platforms are responsible for ensuring appropriate age gating and compliance with applicable laws in their own products.

10. International use

Cross-border processing may occur.

If you access the Service from outside our operating region, your information may be processed in jurisdictions with different data protection laws. We take reasonable steps to protect information consistent with this Policy.

11. Changes

We’ll update the date when it changes.

We may update this Policy from time to time to reflect product evolution and legal requirements. The “Last updated” date above indicates the latest revision.

12. Contact

Privacy questions & requests.

Privacy: admin@veriscopeidentity.com
Support: support@veriscopeidentity.com
Pilots/Integration: sales@veriscopeidentity.com