Legal
Privacy Policy
Last updated: 2026-06-21
1. Overview
Veramask ("we", "us", or "our") operates this website to provide information about our API platform, manage user accounts, process subscriptions, and respond to support inquiries. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, who we share it with, and what rights you have over it.
This policy applies to your use of the Veramask website (https://veramask.com). The Veramask API itself is a separate service that processes data you submit to it; please refer to the API documentation and your customer agreement for how the API handles your data.
2. Data We Collect
2.1 Account data
If you create an account, we collect your email address, full name, the version of our Terms of Service and Privacy Policy you accepted, the timestamp of your acceptance, and your marketing opt-in preference. We also store the Firebase Authentication user ID (UID) as the primary key.
When you verify your email address, we store your email and name in MailerLite (our email service provider) so we can send you important account-related communications, such as subscription confirmations and security alerts. This is separate from marketing communications, which we send only if you explicitly opt in (see Section 2.4).
2.2 Subscription and payment data
If you subscribe to a paid plan, our payment processor (Paddle) collects payment information directly. We receive subscription state (plan name, status, billing interval, renewal date) but we do not receive or store your payment card details. We also generate an API key associated with your subscription.
2.3 Support form
When you submit a support request, we collect your name, email address, subject, and message. Please do not submit Protected Health Information (PHI) or other sensitive personal data through this form. Submissions are transmitted by email to our support team and used solely to respond to your inquiry. We do not write form submissions to our database.
2.4 Newsletter
If you subscribe to our newsletter, we collect your name and email address and add you to our email service provider (MailerLite). You may unsubscribe at any time using the link in any newsletter email, or by contacting us.
2.5 Server logs and IP addresses
Your IP address is processed transiently in memory to enforce abuse rate limits. It is not written to persistent storage and is discarded when the server process restarts or when the rate-limit window expires. Our hosting infrastructure may produce standard access logs (request path, HTTP status, timestamp) used for operational monitoring.
2.6 Cookies and similar technologies
We use a small number of strictly necessary cookies for session management and CSRF protection. We do not use advertising cookies. We may, in the future, use additional analytics or marketing cookies only with your prior consent. See the Cookies section below.
3. How We Use Your Data (Lawful Basis)
We process your personal data only when we have a valid legal basis to do so. Under the EU/UK General Data Protection Regulation (GDPR), the lawful bases we rely on are:
- Performance of a contract (GDPR Art. 6(1)(b)) — to provide the service you signed up for, to manage your account, to process payments, and to deliver the API keys and features you have subscribed to.
- Legitimate interests (GDPR Art. 6(1)(f)) — to respond to support requests, to prevent abuse and fraud, to monitor service availability and performance, and to maintain the security of our systems. We balance these interests against your rights and freedoms.
- Consent (GDPR Art. 6(1)(a)) — to send you marketing communications (newsletter, product updates) only if you have explicitly opted in. You may withdraw your consent at any time without affecting prior processing.
- Legal obligation (GDPR Art. 6(1)(c)) — to comply with tax, accounting, and other legal record-keeping requirements.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
4. Sub-Processors and Third-Party Services
We use the following sub-processors to operate the Service. Each is engaged under a written agreement that includes data-protection obligations:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud (Firebase Auth, Firestore, Cloud Run) | Authentication, database, hosting | United States |
| Google reCAPTCHA Enterprise | Support-form abuse protection | United States |
| counter.dev | Privacy-friendly visitor counting | United States |
| MailerLite | Newsletter and account-related email delivery | United States (EU servers available) |
| Paddle | Payment processing | United States |
| Purelymail | Transactional email relay | United States |
| Veramask API (separate service) | PII detection and anonymization for account-bound features | United States |
For the data-protection terms of each sub-processor, please refer to their respective privacy policies. We will update this list as our sub-processors change.
5. Data Retention
We retain personal data only for as long as necessary to provide the Service and to comply with our legal obligations (GDPR Art. 5(1)(e) — storage limitation):
- Support emails (SMTP inbox): 24 months after last contact.
- Account data: until you request deletion, then a 30-day grace period during which the record can be restored, after which it is permanently deleted.
- Rate-limit IP records: up to 10 minutes (held in memory only, never persisted).
- Server access logs: 30 days.
- Subscription history: 7 years after the subscription ends (for tax, accounting, and audit purposes).
- MailerLite subscriber data: until you unsubscribe or delete your account.
- API key records: for the life of the active subscription, plus 30 days after cancellation.
6. Your Rights
Depending on where you live, you may have some or all of the following rights with respect to your personal data:
- Access — request a copy of the personal data we hold about you (GDPR Art. 15; CCPA right to know).
- Rectification — request that we correct inaccurate or incomplete data (GDPR Art. 16; CCPA right to correct).
- Erasure ("right to be forgotten") — request that we delete your personal data (GDPR Art. 17; CCPA right to delete).
- Restriction — request that we limit the processing of your data in certain circumstances (GDPR Art. 18).
- Portability — receive your data in a structured, commonly used, machine-readable format (GDPR Art. 20).
- Objection — object to processing based on our legitimate interests (GDPR Art. 21).
- Withdraw consent — withdraw any consent you have given, at any time, without affecting prior lawful processing (GDPR Art. 7(3)).
- Lodge a complaint with your local data-protection authority (GDPR Art. 77).
- Limit Use of My Sensitive Personal Information (California residents).
To exercise your right of access or portability, log in and visit your account page and click Download my data under Data & Privacy. You will receive a JSON file containing your account record, subscriptions, usage, and consent log.
To exercise your right of erasure (account deletion), log in and visit your account page and click Delete account. Your account is scheduled for permanent deletion in 30 days; you can cancel the deletion any time within the grace period by signing back in and clicking Restore account.
For all other rights (rectification, restriction, objection, withdrawal of consent), please contact us via the support page or by email at team@veramask.com. We will respond within 30 days; for complex requests we may extend by up to 60 additional days as permitted by applicable law.
7. Children's Data
The Service is not intended for children under 16 years of age (the GDPR default minimum) or under 13 years of age (the COPPA minimum in the United States). We do not knowingly collect personal data from children. If you believe we have collected data from a child in either age group, please contact us and we will delete it promptly.
8. HIPAA and Health Information
The Service (this website, including the support form, account system, and billing) is not a HIPAA-compliant service and is not intended to receive, store, or process Protected Health Information (PHI) as defined by the U.S. Health Insurance Portability and Accountability Act (HIPAA) or analogous health-privacy laws. You agree not to submit PHI through the website.
If you require HIPAA-compliant processing of health data, please contact us to discuss a separate business-associate agreement.
9. Our Position on Selling Personal Information
We will never sell, rent, or trade your personal information to third parties for their own marketing purposes. This is a foundational commitment, not a policy we may revisit. It applies to every data category we collect, every region we operate in, and every future sub-processor we may engage.
We also do not engage in "cross-context behavioural advertising" as defined by the CPRA. We do not share your information with ad networks, data brokers, or analytics providers that build advertising profiles. The analytics tools we use (counter.dev) are privacy-friendly, do not set cookies, and do not collect personal information.
If you are a California resident, you also have the right to know what personal information we collect and share, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right to non-discrimination for exercising your rights. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Iowa, Tennessee, Delaware, Oregon, Montana, and other US states with comprehensive privacy laws have similar rights. You may exercise these rights via the support page.
10. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you (GDPR Art. 22). The Veramask API is a tool that returns transformed data; you remain the decision-maker for any downstream use of that data.
11. Cookies and Similar Technologies
The website uses a small number of cookies and similar technologies, organised into categories you can opt in or out of at any time:
- Strictly necessary: an HTTP session cookie used for authentication and CSRF protection. This cookie is essential for the website to function and does not require consent under EU/UK ePrivacy rules.
- Analytics: counter.dev, a privacy-friendly visitor counter that uses a hashed IP and does not set cookies. Loaded only after you opt in to the "Analytics" category in the cookie banner.
- Marketing: the MailerLite Universal script, which enables newsletter subscription and assigns an anonymous account identifier. Loaded only after you opt in to the "Marketing" category.
On your first visit, a small banner appears at the bottom of the page asking for your choice. You can change your preferences at any time using the Cookie settings link in the website footer.
We honour the Global Privacy Control (GPC) signal. If your
browser sends Sec-GPC: 1 (or the equivalent JavaScript API is
enabled), non-essential categories default to off and the banner shows a
notice. You may still opt in manually.
Your consent choices are stored in your browser's local storage and recorded server-side in our audit log. You can clear cookies and site data at any time using your browser settings; doing so will reset your preferences and the banner will reappear on your next visit. Blocking strictly-necessary cookies will prevent login and account functionality from working.
12. Personal Data Breaches
We take the security of your personal data seriously. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33).
- Notify affected data subjects without undue delay (GDPR Art. 34), with a description of the breach, likely consequences, and the steps you can take to protect yourself.
- Document the incident internally, including root cause and remediation, in line with our Incident Response Plan.
Our full incident response process — including severity classification, decision trees, and notification templates — is documented in our Incident Response Plan. We conduct tabletop exercises twice per year to keep the plan current.
13. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision. For material changes, we will notify you by email (if you have an account) or by a prominent notice on the website. Continued use of the website after changes are posted constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related questions, requests, or complaints, please contact us through our support page or by email at team@veramask.com.
