Privacy Policy

Effective date: August 4, 2026

1. Who we are

verifications.email ("EVA", "we", "us") provides an email verification API and related services at https://verifications.email. Questions about this policy or your data: [email protected].

2. The two roles we play

We handle personal data in two distinct roles:

  • As a controller for the data of our own customers: your account details, usage records, and billing information, as described in section 3.
  • As a processor for the email addresses you submit for verification. For that data, you (our customer) are the controller. We process it only to deliver the verification service you requested, under our Data Processing Addendum.

3. Data we collect about you (as controller)

  • Account data: your email address, a bcrypt-hashed password (or your Google account identifier if you sign in with Google), and your API keys, which are stored only in hashed form.
  • Usage data: verification counts, quota usage, request timestamps, and IP addresses used for rate limiting, abuse prevention, and security logs.
  • Billing data: your plan, invoices, and cryptocurrency payment identifiers (invoice IDs, payment status, transaction references). Payments are processed on our own self-hosted checkout. We do not receive or store card numbers and no third-party payment processor is involved.
  • Support correspondence: emails you send us.

4. Data you submit for verification (as processor)

When you submit email addresses (individually, via the API, or in bulk uploads), we process those addresses and the resulting verification data (validity verdicts, scores, and related technical metadata) solely to provide the service to you. Specifically:

  • We check addresses using DNS lookups and SMTP-level conversations with the responsible mail servers. We never send an email message to the addresses you check.
  • We never sell, rent, share, or disclose your lists or results to anyone.
  • We never use your lists for marketing, list building, or any purpose of our own.
  • Results are stored in your account history so you can review and export them.

5. Legal bases

Where GDPR applies, we rely on: performance of a contract (providing the service you signed up for), legitimate interests (securing the service, preventing fraud and abuse, improving accuracy), and compliance with legal obligations. For data you submit for verification, the legal basis is established by you as the controller; you warrant in our Terms of Service that you have a lawful basis for every address you submit.

6. Retention and deletion

  • Account and billing data is kept while your account is active and as required for tax and accounting records.
  • Submitted email addresses and verification results are kept in your account history while your account is active, so you can review and re-download them.
  • You can request deletion of specific verification history, bulk job data, or your entire account at any time by emailing [email protected]. We complete deletion within 30 days.
  • Server logs and backups rotate on a fixed schedule and are not retained indefinitely.

7. Sharing and subprocessors

We do not sell personal information, and we do not share it with third parties except: the infrastructure providers that host and support the service (a current subprocessor list is available on request at [email protected]), and disclosures required by law. Our payment checkout is self-hosted, so no payment processor receives your data.

8. International transfers

Our servers are located in the United States and the European Union. Where personal data protected by GDPR is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses, incorporated through our Data Processing Addendum.

9. Security

All traffic is encrypted in transit with TLS. Passwords and API keys are stored bcrypt-hashed. Session authentication uses HttpOnly cookies. Access to production systems is restricted and monitored, and we operate continuous error and security monitoring.

10. Cookies

We use essential cookies only: two HttpOnly authentication cookies (access and refresh tokens) that keep you logged in to the dashboard. We use no advertising cookies and no third-party analytics cookies. Because we set only strictly necessary cookies, no cookie consent banner is required.

11. Your rights

Depending on where you live (including under GDPR and the CCPA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. To exercise any right, email [email protected]. We respond within 30 days.

If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. If you are a California resident: we do not sell or share personal information as defined by the CCPA/CPRA.

If your email address was submitted to us by one of our customers for verification, the customer is the controller of that processing and rights requests are best directed to them. You can also contact us and we will assist, including deleting the data from our systems where the law requires.

12. Children

The service is intended for business use and not directed at children under 16. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced by email or a dashboard notice before they take effect. The effective date at the top always reflects the current version.

14. Contact

verifications.email · [email protected]