Legal

Privacy Policy

How Veriwins collects, protects, and uses your data — with a specific focus on the sensitive evidence you upload. Your safety and the integrity of the audit process come first.

1. Who We Are (Data Controller)

Veriwins ("we", "us", "our") operates the VeriWin$ platform and is the data controller responsible for personal data processed through the Service. For privacy questions, contact privacy@veriwins.com.

2. Data We Collect

  • Account data. Name, email, password hash, and authentication identifiers used to create and secure your account.
  • Profile & usage data. Settings, audit submissions, reports, in-app activity, device identifiers and IP address.
  • Giveaway data. Publicly available information from social media links you submit for auditing.
  • Sensitive evidence. Screenshots, direct messages and receipts you upload to prove fraud or prize fulfilment.
  • Support communications. Messages you send us and metadata about those messages.
  • Payment-related data. Billing email and subscription status. Card details and full billing addresses are collected directly by Paddle (see §5).

3. Purposes & Legal Bases

PurposeLegal basis
Create and manage your account; provide the ServicePerformance of a contract
Process payments and subscriptions via PaddlePerformance of a contract; legal obligation (tax/accounting)
Security, fraud prevention, abuse detectionLegitimate interests
Audit logic, trust scoring, product improvementLegitimate interests
Customer support communicationsPerformance of a contract
Marketing emailsConsent (you can withdraw at any time)
Responding to lawful requests from authoritiesLegal obligation

4. How We Handle Sensitive Evidence

  • Automated masking. AI detects and blurs PII (addresses, phone numbers) in uploaded images before permanent storage.
  • Encrypted storage. Evidence is stored using AES-256 encryption at rest, with TLS in transit.
  • Restricted access. Evidence is accessible only to you and, if you formally report a scam, to official state consumer protection offices.

5. Sharing & Disclosure

  • Payments — Paddle (Merchant of Record). We use Paddle.com as our payment processor and Merchant of Record. Paddle independently collects and processes your payment details (card data, billing address, tax identifiers) to fulfil your order, manage subscriptions, handle refunds, and meet tax and invoicing obligations.
  • Service providers. Cloud hosting, database, storage, analytics and email infrastructure providers that process data on our behalf under written agreements.
  • Government agencies. Packaged evidence is shared with consumer protection offices or the FTC only when you explicitly file a formal complaint, or where required by law.
  • Professional advisers. Legal, accounting and audit advisers, under confidentiality.
  • No data sales. Veriwins never sells your personal data or evidence to advertisers or data brokers.

6. Data Retention

  • Account data. Retained for the lifetime of your account and deleted within 30 days of account closure, except where longer retention is required by law.
  • Evidence uploads. Retained while the related audit or report is active, and for up to 24 months after closure to support investigations, then deleted or anonymised.
  • Billing & tax records. Retained by Veriwins and Paddle for up to 7 years to meet legal, tax and accounting obligations.
  • Support communications. Retained for up to 24 months after the conversation closes.
  • Security logs. Retained for up to 12 months for fraud prevention and incident response.

7. Your Rights & Control

  • Access & portability. Request a copy of the data we hold about you.
  • Correction. Update inaccurate or incomplete data from your account settings or by contacting us.
  • Deletion. Request permanent deletion of your account and associated evidence from settings.
  • Restriction & objection. Ask us to restrict or object to certain processing based on legitimate interests.
  • Withdraw consent. Withdraw consent for marketing at any time using the unsubscribe link in any email.
  • Complaints. If you are in the UK/EEA you may complain to your local data protection authority.

8. Security

We apply appropriate technical and organisational measures including AES-256 encryption at rest, TLS in transit, role-based access controls, audit logging, and background checks for staff with access to sensitive data. No system is perfectly secure; we will notify affected users without undue delay in the event of a qualifying breach.

9. International Transfers & Cookies

Personal data may be processed in countries outside your own, including the United States. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards. We use strictly necessary cookies to keep you signed in and optional analytics cookies to improve the Service; you can manage preferences in your browser.

This Privacy Policy is effective as of the date last updated and governs your use of Veriwins.