Legal
Privacy Policy
Last updated May 5, 2026. This policy is a polished implementation draft and should be reviewed by counsel for production use.
Information we collect
We collect account information, contact details, submission details, handbag photos, payment status metadata, certificate data, support inquiries, and operational logs required to provide authentication services.
How we use information
We use information to create accounts, process submissions, manage payments, conduct authentication review, issue certificates, provide public verification, prevent abuse, respond to inquiries, and improve the service.
Submission photos
Handbag images are used for authentication review and internal quality control. Production storage should use private buckets, signed URLs, access controls, file-name sanitization, and audit logging.
Public certificate verification
Public verification pages show certificate status, certificate ID, brand, model, result, date issued, and any COA photos or authentication notes deliberately selected by an administrator for public display. Private customer information and unselected submission images are not displayed by default.
Payments
Payments are processed by Stripe. Veritable stores payment status and identifiers needed for reconciliation, support, refunds, and audit records, but does not store full card numbers.
Service providers
We may use infrastructure, storage, email, analytics, fraud prevention, and payment providers to operate Veritable. These providers process information according to their contracts and security obligations.
Retention
We retain records for as long as needed to provide authentication services, maintain certificate verification, meet legal obligations, resolve disputes, prevent fraud, and support audit trails.
Your choices
You may update account details, request support, and inquire about data access or deletion where applicable. Certificate integrity and fraud-prevention obligations may limit deletion of certain records.
Security
Veritable is designed with role-based access, protected routes, signed file access, webhook verification, audit logs, and environment-based secret handling. No system can guarantee absolute security.