The short version
We hold the account details you give us and the lists you upload. Lists are used only to produce your results, are deleted when you download them, and are removed automatically after 14 days. We never sell your data and we never add your contacts to a list of our own.
What we collect
Account information — your name, email address and password (stored only as a bcrypt hash, never in readable form).
Lists you upload — the email addresses you ask us to verify, and the verdicts we produce for them.
Usage records — credits spent, jobs run, API calls, and the IP address and browser used to sign in. We keep these to bill correctly and to spot abuse.
Payment records — the amount, date and plan. Card details go directly to our payment processor and never reach our servers.
How long we keep it
| Uploaded lists | Deleted when you download your results, and in every case after 14 days |
|---|---|
| Verification results | 14 days, then permanently deleted |
| Account details | Until you close your account, then 30 days |
| Billing records | As long as tax law requires, typically 6–7 years |
| Sign-in records | 12 months |
Why we are allowed to hold it
For account and billing data, because we need it to provide the service you asked for (contract). For security and abuse records, because we have a legitimate interest in keeping the service safe. For the lists you upload, we act as a processor on your instructions — you remain the controller. See the DPA.
Who else sees it
We use a small number of providers to run the service:
- a hosting provider, which stores the application and database
- a payment processor, which handles checkout and invoices
- an email provider, for receipts and job notifications
Each is bound by contract to process data only on our instructions. We do not sell personal data, and we do not share your lists with anyone else.
Where it is processed
Processing takes place on servers in the European Union. Where a provider processes data outside it, we rely on Standard Contractual Clauses.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you
- correct anything inaccurate
- delete your data
- restrict or object to processing
- export your data in a portable format
Write to privacy@verifyprollc.com and we will respond within 30 days. You may also complain to your local data protection authority.
Security
Passwords are hashed with bcrypt. Session tokens are stored only as SHA-256 hashes, so a copy of our database cannot be replayed as a login. All traffic is encrypted with TLS, and credentials sit outside the web root where they cannot be requested over HTTP.
If a breach affects your data we will tell you and the relevant authority within 72 hours of becoming aware of it.
Contact
| Privacy | privacy@verifyprollc.com |
|---|---|
| Controller | VerifyingPro LLC |