Skip to content

Legal

Privacy Policy

Effective 1 March 2026Last updated March 2026

InfraVerifier runs the InfraVerifier email verification platform. This policy sets out what we hold about you, why we hold it, and when it is deleted. It applies to infraverifier.com and to the application that sits alongside it. For everything described below we act as the data controller, and privacy@infraverifier.com reaches the people responsible for it.

1. Data we hold

  • Account information. A name, an email address, and a password kept only as a hash. Nobody here can read it back.
  • Usage data. A running count of the verifications your account performs. That count is what enforces plan limits and flags abuse. Nothing about the content of your results reaches our logs beyond what your dashboard already shows you.
  • Addresses you submit for verification. They sit in your scan history, ready to export whenever you want them, and they are put to no other use.
  • Billing information. Our payment processor handles it. Card numbers never reach us. What comes back is confirmation that a payment succeeded and the email address attached to it.
  • Technical data. Session identifiers and IP addresses, held for security and abuse prevention.

2. Why we hold it

  • Running the verifications you ask for
  • Signing you in and holding your account to its plan limits
  • Sending sign-in codes, password resets and other transactional mail
  • Spotting fraudulent or abusive use and stopping it
  • Replying when you contact support

We do not sell personal information. The lists you upload are never used for advertising, for marketing, or to build any kind of contact database.

3. Providers with access

Information reaches an outside provider only where the platform cannot run without one: payment processing, DDoS protection and bot detection, optional single sign-on, transactional email delivery, and privacy-preserving analytics. No advertiser and no data broker appears on that list.

To be completed before launch: list each subprocessor by name, the category of data it receives, and the country it processes in.

4. How long it stays

Account data lasts as long as the account does. Scan results and uploaded files are deleted permanently 30 days after they are created, which limits how much of your data exists to be exposed in the first place. You can delete any scan yourself before then. Close the account and the remainder goes within 30 days of the request.

5. Your rights

Which rights you hold depends on local law. The common four are access, correction, export and deletion. Send a request to privacy@infraverifier.com and a reply follows inside 30 days.

In the European Economic Area and the United Kingdom, two further rights apply. One is data portability. The other is complaining to your local supervisory authority.

6. Security

Connections are encrypted with TLS, passwords are hashed, and sessions are managed server-side. No system is perfectly secure and we will not claim otherwise, but we keep the amount of data we hold deliberately small, which is the most effective control available to us.

7. Cookies and analytics

The marketing site uses privacy-preserving analytics that set no cookies, store no identifiers, and do not track you between sites. The application uses a single session cookie to keep you signed in. No cookie here serves advertising or cross-site tracking. The DDoS provider may set a cookie of its own, strictly for security.

8. Age limit

Anyone under 16 is outside the intended audience for the service, and we do not knowingly collect their information.

9. Changes

We may update this policy. If a change is material, registered users are notified by email before it takes effect.

10. Contact

For anything covered by this policy: privacy@infraverifier.com