VeriBag

v0.1 draft, pending legal review. For accurate terms, contact press@veribag.io.

Privacy Policy

This policy covers the public VeriBag marketing site and VeriBag mobile app. It is written for launch review and remains subject to final legal review.

1. What VeriBag Collects

We collect email addresses submitted to the early access list.

When you submit a waitlist or account request, we collect basic delivery and attribution metadata, including user agent, referrer, country header, campaign parameters, selected airport, travel timing, and priority-traveler status when you provide it.

When you use the VeriBag mobile app, we collect account profile data, bag library records, trip data, protection record metadata, seal-time location provenance when permission is granted, and photos or files you choose to capture for a protection record.

2A. Account Deletion and Data Removal

You can delete your account from within the VeriBag app by going to Settings -> Account -> Delete Account.

You can also request account deletion by emailing support@veribag.io or visiting https://veribag.io/delete-account.

Upon deletion, account profile data, bag library data, trip data, and active session credentials are removed within 30 days.

Cryptographic evidence records, including Merkle roots, Bitcoin anchors, and signed receipts, may be retained in aggregated, non-identifiable form indefinitely because public blockchain anchors cannot be altered after publication.

You may download your evidence bundles before deletion by using Settings -> Export My Data.

2. How We Use It

Marketing signup data is used for launch notices, press follow-up, and product updates requested by the subscriber.

VeriBag does not sell marketing-list data, share it with advertisers, or use it for behavioral advertising.

Protection record data is used to create tamper-evident receipts, verify bag status, support export requests, and provide shareable proof when you choose to share a record.

Seal-time location provenance is used only to strengthen the protection record by documenting where the record was created. VeriBag does not collect background location, continuous location, or location for advertising.

3. Analytics and Cookies

The site uses privacy-respecting analytics when analytics scripts are enabled to understand aggregate page performance and signup conversion. Analytics are limited to the public marketing site.

Cookies, if present, are used for analytics and site operation only. You can disable cookies in your browser settings.

3A. Biometric Data

VeriBag uses biometric authentication, such as Face ID, Touch ID, or fingerprint, when you enable secure signing through your device operating system.

VeriBag does not collect, store, transmit, or process biometric data.

All biometric verification occurs entirely on your device through Apple's Secure Enclave or Android secure hardware.

VeriBag receives only a yes/no signal from the device indicating successful biometric authentication.

7. Your Rights

Canadian visitors may request access, correction, or deletion under PIPEDA. EU and UK visitors may request access, deletion, portability, or objection under GDPR-style rights.

To make a request, email privacy@veribag.io from the address you used to sign up.

We respond to verified requests within 30 days.

We may require identity verification before processing requests to protect against unauthorized access.

If you disagree with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada or your applicable regulatory authority.

8. Data Retention

Evidence bundles: Accessible while your account is active. We recommend exporting evidence you wish to retain before deleting your account via Settings → Export My Data.

9. Children's Privacy

VeriBag is not intended for children under 16 in the EU, UK, or Quebec, or under 13 elsewhere.

We do not knowingly collect personal information from anyone under these ages. If we learn we have collected information from a minor, we will delete it promptly.

Travelers under 18 should use the product only with parental or guardian consent.

10. Third-Party Services

Supabase Inc. (United States) provides cloud database, authentication, and file storage. Supabase receives account data, bag metadata, and photo storage data. Privacy policy: https://supabase.com/privacy

RevenueCat Inc. (United States) processes subscription management. RevenueCat receives a user identifier and subscription status. Privacy policy: https://www.revenuecat.com/privacy

OpenTimestamps is decentralized and receives cryptographic hash values for blockchain anchoring. VeriBag does not transmit personal data to OpenTimestamps.

Apple Inc. and Google LLC receive payment processing data for subscriptions under their platform terms. Device operating systems may also provide location and reverse-geocoding services when you allow seal-time location capture.

13. Data Breach Notification

If a data breach affects personal information, VeriBag will notify affected users without undue delay.

Notifications will comply with PIPEDA, Quebec's Law 25, GDPR where applicable, and other applicable laws.

VeriBag will also notify the Office of the Privacy Commissioner of Canada and applicable regulatory authorities where required.

14. Canadian Privacy Compliance

VeriBag complies with the Personal Information Protection and Electronic Documents Act (PIPEDA).

Quebec residents have additional rights under An Act Respecting the Protection of Personal Information in the Private Sector (Law 25), including the right to be informed of automated decision-making and the right to data portability.

VeriBag's designated Privacy Officer can be contacted at privacy@veribag.io.