Privacy Policy
Last updated: July 22, 2026
Verinest ("we", "us", "our") operates Vouch, a fraud-risk scoring and identity verification service (the "Service"). This policy explains what personal data we process, why, and what rights you have.
1. Who this applies to
- Sellers: businesses that create a Verinest account to use Vouch (e.g. hosting providers using our WHMCS plugin).
- End customers: the people placing orders on a seller's site, whose order/signup events are submitted to our API for a risk decision.
2. What we collect
From sellers (account data): name, email, company/domain, billing details (handled by Paddle, our payment provider — see below).
From end customers (via the seller's plugin, per order event): email, phone, IP address, billing address, device fingerprint, order/payment metadata (amount, card BIN, gateway, AVS/CVV/3-D Secure results). We never receive full card numbers.
Identity verification data: if an order is flagged as high-risk, the end customer may be invited to complete identity verification. Document capture and verification happen directly with our verification partner, Didit — we do not collect, transmit, or store raw identity documents on our own servers. We receive only the verification result (verified/declined) and a verification expiry.
3. Why we process this data
- To compute a real-time fraud/risk decision for an order (legitimate interest of the seller and their platform).
- To maintain an identity ledger so a previously verified customer is not asked to re-verify unnecessarily.
- To operate seller accounts, billing, and support.
- To improve our rules/scoring over time using aggregated, non-identifying statistics.
4. Sub-processors
We share limited data with:
- Didit — identity verification (KYC).
- Paddle — payment processing, invoicing, tax compliance (acts as Merchant of Record for subscription payments).
- Fraud data enrichment providers (e.g. IP/device reputation, BIN lookup) — queried asynchronously to enrich a risk decision.
We do not sell personal data.
5. Data location and retention
Our primary database is hosted in the EU. Order-event data used for risk scoring is cached short-term; identity ledger records (known/verified status) are retained only as long as needed to avoid duplicate verification, and verification validity has a defined expiry (document expiry, or 24 months by default). We do not log personal data such as email, phone, name, IP address, or card BIN in our operational logs.
6. Your rights
Depending on your jurisdiction (including EU/UK GDPR), you may have the right to access, correct, delete, or export your personal data, or object to its processing. End customers should contact the seller whose site they ordered from in the first instance, since the seller is typically the data controller for that relationship; sellers and Verinest account holders can contact us directly.
7. Cookies
Our website and dashboard use only essential cookies required for authentication and session management. We do not use third-party advertising cookies.
8. Changes to this policy
We may update this policy as the Service evolves. Material changes will be posted here with an updated date.
9. Contact
Privacy questions or requests: privacy@verinest.app