Privacy Policy
Last updated: September 2026
Verdix AI ("Verdix", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our AI-powered visual audit services. This policy is designed to comply with applicable data protection regulations worldwide, including the EU General Data Protection Regulation (GDPR), UK GDPR, and United States federal and state privacy laws (including California CCPA/CPRA).
1. Information We Collect
We collect only the information necessary to provide, secure, and improve our services:
- Account Information: When you sign in (e.g., via Google OAuth), we receive your authenticated email address, unique user ID, and basic profile name.
- Audit Request Data: Public social media handles and publicly available profile metadata you submit for analysis.
- Transaction & Billing Data: Purchases and subscriptions are handled by our Merchant of Record, Paddle.com. We do not store or process your full payment card numbers on our servers. We only receive high-level transaction identifiers, subscription status, and billing renewal dates.
- Technical & Log Data: IP addresses, browser types, and timestamp data collected automatically for security, abuse prevention, rate-limiting, and error logging.
2. Cookies & Local Storage
We respect your digital privacy and minimize tracking:
- Strictly Necessary Cookies & Tokens: We use essential session cookies and local storage solely to maintain your authenticated login session (via Supabase Auth) and ensure CSRF security.
- No Third-Party Advertising Trackers: We do not deploy cross-site behavioral tracking pixels or third-party marketing cookies. Under GDPR and ePrivacy regulations, strictly necessary technical cookies do not require prior opt-in consent as they are essential to deliver the requested service.
3. How We Use Your Information
We process your data for legitimate business and contractual purposes:
- To generate AI visual audits, aesthetic analyses, and profile insights.
- To manage user accounts, authenticate access, and track credit/subscription balances.
- To process transactions, prevent fraudulent payments, and issue subscription lifecycle updates.
- To maintain platform stability, monitor performance, and diagnose technical issues.
4. Third-Party Service Providers
We do not sell, rent, or trade your personal data. We share necessary data only with trusted infrastructure and service partners bound by strict data protection terms:
- Merchant of Record & Billing: Paddle.com acts as our Merchant of Record for payment processing, tax calculation, and order fulfillment.
- Database & Authentication: Supabase for secure encrypted cloud database hosting and identity management.
- Artificial Intelligence Partners: Secure AI model APIs to analyze public content and generate structured audit recommendations.
- Data Aggregation APIs: To fetch publicly accessible profile information as requested by the user.
5. Rights for European & UK Users (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR:
- Right of access to the personal data we hold about you.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") of your personal account data.
- Right to restriction or objection to certain processing activities.
- Right to data portability.
6. Rights for US & California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- No Sale or Sharing of Personal Information: We do not sell your personal information or share it for cross-context behavioral advertising.
- Right to Know & Delete: You have the right to request disclosure of the categories of personal data collected and request deletion of your personal data without discrimination.
7. Data Security & Retention
We implement rigorous technical and organizational security measures, including TLS/HTTPS encryption in transit, encrypted storage at rest, and strict access controls. We retain personal data only as long as necessary to provide services and comply with legal obligations.
8. Contact Us
If you have any questions or wish to exercise your privacy rights, contact our Data Protection team at: support@verdix.ink