Privacy Policy
How VerifyMe collects, uses, protects, and manages personal data.
1. About this policy
VerifyMe provides digital credential issuance, management, and verification services for institutions and their authorised users. This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected when a person uses the VerifyMe website, an institutional workspace, the public credential-verification service, or a support channel.
VerifyMe is operated by Faisal Ahmed Habib trading as VerifyMe, of Maitama, Abuja, FCT, Nigeria ("VerifyMe", "we", "us", or "our").
For account administration, platform security, service analytics, billing, support, and VerifyMe's own business operations, VerifyMe generally acts as a data controller. For credential and recipient data entered and managed by an issuing institution, the institution generally acts as the data controller and VerifyMe processes that information on its instructions as a data processor. The precise allocation of responsibilities may be further described in an institution's service agreement or data-processing agreement.
Each issuing institution is responsible for having a lawful basis and proper authority to collect recipient information and to issue, publish, correct, expire, or revoke a credential.
2. Scope
This policy applies to VerifyMe's public website and verification pages, account registration and authentication, institutional and platform-administration workspaces, credential records, uploaded documents, notifications, audit and verification activity, and communications with VerifyMe.
It does not replace an issuing institution's own privacy notice. An institution may have additional duties to credential recipients, students, employees, members, or other data subjects.
3. Personal data we collect
Account and identity data
We may process a user's name or display name, email address, user identifier, organisation membership, assigned role, account status, invitation information, and account creation or activity timestamps.
Authentication and security data
We process session and authentication information, security events, and whether multi-factor authentication is enrolled or satisfied. VerifyMe support will never ask a user to disclose a password, current one-time password, authenticator secret, recovery code, secret key, or session cookie.
Institution data
We may process an institution's name, slug, contact and location details, logo, verification status, membership records, verification application, accreditation or registration evidence, and other documents submitted for institution verification.
Credential and recipient data
Information supplied by an issuing institution may include:
- Recipient name and email address, where collected.
- Credential title, programme, qualification, certificate type, or description.
- Credential number, public identifier, or verification code.
- Issuing institution and relevant institution profile information.
- Issue date and expiry date, where applicable.
- Credential status, including active, revoked, or an expiry-derived status.
- Revocation date and reason, where recorded.
- Supporting credential documents or generated credential files.
VerifyMe should collect only the information reasonably needed to issue, manage, and verify the credential.
Public verification data
Subject to the institution's configuration and the current product implementation, a public credential result may display the recipient's name, credential title or type, issuing institution and logo, credential number or public identifier, issue date, expiry date where applicable, and current verification status. It may also state whether the credential was successfully verified.
Private email addresses, internal membership data, audit records, uploaded identity evidence, institution-verification documents, and revocation notes should not be displayed publicly unless a separate lawful and clearly disclosed feature expressly requires it.
Verification, notification, and audit data
We may process verification events, audit actions, notification records, action types, timestamps, and the associated credential, institution, or user identifiers. These records help preserve credential integrity, accountability, and service security.
Technical and security data
We may process browser and device information, request metadata, diagnostic logs, security events, and network information used for fraud prevention and rate limiting. Where implemented, network identifiers such as IP addresses may be transformed or cryptographically hashed before storage.
Cloudflare Turnstile processes technical signals and returns challenge results and related verification metadata. VerifyMe does not receive the confidential signals Cloudflare uses to perform its risk assessment.
Communications
We process the information a person includes in support requests, privacy requests, security reports, abuse reports, or other communications with us.
4. How we obtain personal data
We receive personal data directly from account holders, issuing institutions, institution administrators, credential recipients who contact us, public verifiers, automated security systems, and service providers used to operate VerifyMe.
5. Purposes and lawful bases
We process personal data only where a lawful basis applies. Depending on the circumstances, this may include:
- Contract: to create an account, provide the service, administer an institution's subscription, or take requested pre-contract steps.
- Legal obligation: to comply with applicable law, lawful regulatory requirements, court orders, accounting duties, or valid authority requests.
- Legitimate interests: to secure and improve VerifyMe, prevent fraud, preserve credential integrity, maintain audit trails, support users, enforce contractual terms, and protect legal rights, where those interests are not overridden by the data subject's rights and interests.
- Consent: where consent is the appropriate basis, including for optional processing or processing involving a child where legally required. Consent may be withdrawn without affecting processing already lawfully performed.
- Vital interests: in exceptional situations where processing is necessary to protect a person's life or physical safety.
- Public interest or official authority: where an eligible institution lawfully relies on such a basis and instructs VerifyMe accordingly.
These bases reflect the framework of the Nigeria Data Protection Act 2023. The issuing institution remains responsible for selecting and documenting the lawful basis for recipient and credential data it supplies.
We use personal data to:
- Create, authenticate, and secure accounts and organisation workspaces.
- Permit authorised users to issue, manage, expire, verify, or revoke credentials.
- Display limited approved information through public credential verification.
- Review institution-verification applications.
- Deliver service emails and in-product notifications.
- Provide customer support and respond to rights requests.
- Keep audit trails, enforce rate limits, prevent fraud, and investigate misuse.
- Diagnose faults and improve service reliability, usability, accessibility, and performance.
- Administer subscriptions, invoices, and commercial relationships when paid plans are introduced.
- Comply with legal obligations and establish, exercise, or defend legal claims.
6. Public credential verification
A person who possesses a credential's verification link, code, or public identifier may be able to view the limited public result described above. Public verification is intended to confirm authenticity and current status, not to expose unnecessary personal information.
A verifier must use the result only for a lawful verification purpose. Automated scraping, bulk collection, profiling, sale, republication, harassment, or other misuse of credential or recipient information is prohibited.
7. Sharing and service providers
We may disclose personal data:
- To the institution responsible for the relevant account or credential.
- To a person using the public verification service, limited to the approved public result.
- To vetted service providers that process data to operate, secure, communicate, and support VerifyMe.
- Where required by applicable law, a court order, or a lawful request from a competent authority.
- Where reasonably necessary to investigate fraud, abuse, security threats, unlawful conduct, or threats to the rights or safety of a person.
- In a legitimate financing, merger, acquisition, reorganisation, or sale of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.
Key providers currently or prospectively used include:
- Supabase for database, authentication, and storage services.
- Vercel for application hosting and delivery.
- Cloudflare Turnstile for bot and abuse protection.
- Upstash for rate-limiting infrastructure.
- Resend for transactional email delivery when domain email is configured.
VerifyMe does not sell personal data and does not use personal data for third-party behavioural advertising. If advertising or non-essential analytics are introduced later, this policy and any required consent controls must be updated before they are activated.
8. International transfers
Some service providers may store or process personal data outside Nigeria. Before making a restricted transfer, VerifyMe will take reasonable steps to identify the destination and use a lawful transfer basis recognised by the Nigeria Data Protection Act 2023, such as an adequacy basis or appropriate contractual, organisational, and technical safeguards. Transfer assessments and provider agreements will be reviewed as the service and hosting arrangements develop.
9. Retention
VerifyMe will retain personal data only for as long as reasonably necessary for the stated purpose and will periodically review retained data. The following is the adopted target schedule, subject to longer retention required by law, a legal claim, fraud prevention, an institution's lawful instruction, or a signed service agreement:
| Record | Target retention period |
|---|---|
| Account and organisation-membership records | While the account or institutional relationship is active, then up to 24 months after closure, except essential audit records |
| Credential core record and status history | While the credential remains relevant and for 7 years after expiry, revocation, or termination of the issuing institution's service, whichever occurs later |
| Credential and institution-verification documents | While needed for the applicable credential or verification process, then deleted or de-identified within 12 months after the related retention need ends |
| Verification events | Up to 24 months from the event |
| Security-sensitive and administrative audit logs | Up to 7 years from the event |
| In-product notifications | Up to 12 months from creation |
| Invitations | Up to 90 days after expiry, cancellation, or acceptance, with essential audit evidence retained where necessary |
| Rate-limit and routine security records | Ordinarily no more than 12 months; short-lived rate-limit keys may expire much sooner |
| Support, privacy, abuse, and security correspondence | Up to 3 years after the matter closes, or longer where a legal claim or investigation requires it |
| Billing, tax, and transaction records | For the period required by applicable tax, accounting, and commercial law |
These periods must be implemented operationally before they are represented as firm automated deletion deadlines. Backup copies may persist for a limited disaster-recovery cycle and remain protected from ordinary use until overwritten.
A deletion request does not require deletion of a record that must lawfully be retained to protect credential integrity, preserve a security or audit trail, comply with law, resolve a dispute, or prevent fraud. Where an institution controls the relevant data, VerifyMe may refer the request to that institution and assist it as appropriate.
10. Security
VerifyMe uses technical and organisational safeguards intended to protect personal data, including role-based permissions, encrypted connections, multi-factor authentication for sensitive platform administration, row-level database controls, rate limiting, audit logging, and restricted file handling. No service or transmission method is completely secure; therefore, absolute security cannot be guaranteed.
11. Data-subject rights
Subject to applicable law and valid exemptions, a data subject may request information and access, correction, deletion, restriction, objection, portability, or withdrawal of consent. A person may also object to certain automated decision-making and lodge a complaint with the Nigeria Data Protection Commission.
Requests should be sent to Email address coming soon. VerifyMe may verify the requester's identity and authority before acting. If an institution supplied or controls the relevant information, VerifyMe may refer the request to that institution while supporting an appropriate response.
VerifyMe's internal target is to acknowledge a privacy request within two business days and provide a substantive response within 30 days, unless applicable law permits or requires a different period. A complex request may take longer where lawful, in which case the requester will be informed.
12. Children and credentials concerning minors
VerifyMe accounts are intended only for persons aged 18 or older who are authorised to act for an institution or otherwise use an authenticated feature. Children must not independently create or administer VerifyMe accounts.
An institution may issue a credential concerning a person under 18 only where the institution has proper authority and has satisfied applicable notice, lawful-basis, safeguarding, and data-minimisation requirements. Where consent is required for a child who lacks legal capacity to consent—including the statutory requirements applicable to a child under 13—the institution must obtain and verify consent from a parent or other appropriate legal guardian before submitting the child's data.
VerifyMe will not knowingly use a child's credential data for advertising or unrelated profiling. A parent, guardian, or eligible young person may contact the issuing institution or Email address coming soon about an applicable privacy right.
13. Cookies and similar technologies
VerifyMe currently uses only technologies reasonably necessary for authentication, session security, user preferences, bot protection, and operation of the service. Cloudflare Turnstile and other security providers may process technical signals to detect automated or abusive traffic.
VerifyMe does not currently use behavioural advertising cookies. Before non-essential analytics or advertising technologies are introduced, VerifyMe will update this policy and implement any notice or consent mechanism required by law.
14. Third-party links
The service may link to third-party websites or services. Their privacy practices are governed by their own notices, and VerifyMe is not responsible for those independent practices.
15. Changes to this policy
We may update this policy to reflect changes in the service, law, providers, or processing practices. The revised version will show an updated date. Additional notice will be provided where required by law or where a change materially affects users.
16. Contact and complaints
Privacy enquiries: Email address coming soon
General support: Email address coming soon
Telephone: Business support number coming soon
Postal address: Faisal Ahmed Habib trading as VerifyMe, Maitama, Abuja, FCT, Nigeria
A person who is dissatisfied with our response may lodge a complaint with the Nigeria Data Protection Commission or seek another remedy available under applicable law.