Privacy Policy
Last updated: September 3, 2026
This policy explains what personal data FullyVerify (“we”, “us”) collects, why we collect it, who we share it with, and how long we keep it. It covers both data about you as an account holder and the email addresses you upload for verification.
1. Who we are
FullyVerify is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], Canada. We are subject to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and to the GDPR and UK GDPR in respect of customers and data subjects in the EEA and UK.
Our designated privacy officer, as PIPEDA and Quebec’s Law 25 require, can be reached at privacy@fullyverify.com. That is also the address for any access, correction or deletion request.
2. Data we collect about you
- Account data — your name and email address, provided when you sign up. Authentication is handled by Clerk; we never see or store your password.
- Billing data — purchase amounts, credit quantities and timestamps. Card details are entered directly with Stripe and never reach our servers.
- Usage data — verification jobs you run, their settings, results and the time you were last active.
- Support data — anything you send us through the feedback or contact forms.
3. Email addresses you upload
The core of the service is checking email addresses you supply. Those addresses usually belong to other people, which makes this the most important section of this policy.
- You are the controller; we are a processor. You decide which addresses to submit and why. We process them only to perform the verification you asked for, on your instructions.
- Your responsibility. You must have a lawful basis to submit each address to us and to have it verified. Do not upload data you are not entitled to process.
- What we do with them. Each address is sent to every verification provider in the bundle you selected, and the returned verdicts are stored against your job so you can view and export them.
- What we never do. We do not sell uploaded addresses, do not market to them, do not add them to any shared or cross-customer database, and do not use them to train models.
4. Sub-processors
Running a verification necessarily discloses the address to the providers you selected. We use the following sub-processors:
- Verification providers — ZeroBounce, MillionVerifier, NeverBounce, Hunter, Emailable, Bouncer, Clearout, EmailListVerify and IcyPeas. An address is only sent to the providers included in the bundle you chose for that job.
- Clerk — authentication and user management.
- Convex — application database and backend hosting.
- Vercel — web application hosting.
- Stripe — payment processing.
- Resend — transactional email delivery.
Each sub-processor handles data under its own privacy policy and terms. A current list of every sub-processor, including the country each one processes data in, is kept in our Data Processing Agreement, along with how we notify you before adding a new one.
4a. International transfers
We are based in Canada and our sub-processors operate in Canada, the United States and the European Union. Submitting a list therefore involves transferring personal data outside your country, and outside Canada.
- From the EEA and UK. The European Commission has recognised Canada as providing an adequate level of protection for personal data handled by organisations subject to PIPEDA, so transfers to us do not require separate safeguards. Onward transfers to sub-processors outside Canada are made under standard contractual clauses or an equivalent mechanism.
- From Quebec. Where Law 25 applies, we assess a transfer outside Quebec before making it, taking account of the sensitivity of the data, the purpose, the protections the recipient gives it, and the legal framework where the recipient operates.
- Into the United States. Data held by US sub-processors may be accessible to US authorities under their law. If that matters for your use case, choose a bundle whose providers are located where you need them to be, and ask us before you upload.
5. Legal bases
Where the GDPR applies, we rely on: performance of a contract for account, billing and verification data; legitimate interests for security, abuse prevention and product improvement; and legal obligation for tax and accounting records.
Under PIPEDA we rely on your consent, given when you create an account and upload a list, for the purposes described in this policy. We identify those purposes before collecting, collect only what the service needs, and do not use the data for a new purpose without asking you first. You may withdraw consent at any time by deleting your account, subject to the records we must keep by law.
6. Retention
- Uploaded addresses — the raw list you upload is held only for as long as the job needs it, and is deleted automatically once the job finishes or fails.
- Verification results — kept while your account is open so you can revisit and export past jobs. To have the results of a specific job erased before then, email us and we will delete them.
- Account data — kept until your account is deleted.
- On account deletion — deleting your account removes your jobs, verification results, bundles, orders and feedback, including every uploaded address held in them. Deletion is automatic and cascades through our database; it is not a flag on your record.
- Billing records — retained as long as tax and accounting law requires, typically seven years, even after account closure. These records cover amounts and dates, not uploaded addresses.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to it. California residents have the right to know what is collected and to opt out of “sale” or “sharing” — we do neither. Email privacy@fullyverify.com and we will respond within the period the applicable law requires.
Under PIPEDA you may ask what personal information we hold about you, why we collected it, and who we have disclosed it to, and you may ask us to correct it. If you are not satisfied with how we handle your request, you can complain to the Office of the Privacy Commissioner of Canada. If you are in Quebec, Law 25 also gives you the right to receive the data you provided in a structured, commonly used technical format, and to be told before a decision about you is made solely by automated processing — we make no such decisions.
If your address was uploaded to us by one of our customers and you want it removed, contact us and we will help, though the customer who uploaded it is the controller of that data.
8. Security
Data is encrypted in transit. Provider API credentials are held only in server-side environment variables and are never exposed to the browser. Access to production data is limited to the people who need it. No system is perfectly secure, and we cannot guarantee absolute security.
If a breach happens. Where a breach of security safeguards creates a real risk of significant harm, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to notify the affected individuals as soon as feasible, and to keep a record of every breach. Where the GDPR applies we will notify the relevant supervisory authority within 72 hours. If the breach involves a list you uploaded, we will tell you without undue delay so you can meet your own notification duties as the controller.
9. Cookies
We use cookies that are strictly necessary to keep you signed in and to keep the service secure. We do not use advertising cookies.
10. Children
The service is not directed at anyone under 16, and we do not knowingly collect their data.
11. Changes
We may update this policy. Material changes will be announced in the app or by email, and the date at the top will change.
12. Contact
Questions or requests: privacy@fullyverify.com.