Legal

Privacy Policy

This policy explains what data VerifyDocs collects, why we collect it, how it is secured, and the rights you have over it — including data processed on behalf of our business customers during identity verification.

Effective date: July 8, 2026 Applies to: VerifyDocs website, API and dashboard

1Scope of this policy

This Privacy Policy applies to VerifyDocs ("we", "us", "our"), operated by SUPERMINT INFOTECH PRIVATE LIMITED, and covers our website, API, developer dashboard, and any verification services offered under the VerifyDocs brand.

We act in two capacities depending on the data involved:

  • As a data controller for account, billing and dashboard data belonging to our business customers ("Merchants").
  • As a data processor for end-customer identity data (such as Aadhaar, PAN or bank details) that a Merchant submits to us for the purpose of running a verification. In that case, the Merchant is the controller and instructs us on how that data may be used.
Not a substitute for your Merchant agreement

If you are a Merchant, your use of the API is also governed by our Terms of Service and any Data Processing Agreement signed with us, which take precedence for API-level data handling.

2Information we collect

We collect information in three broad categories:

CategoryExamplesCollected from
Account & billing dataName, business email, phone, company details, GSTIN, billing address, payment recordsYou, directly
Usage & technical dataAPI request logs, IP address, device/browser metadata, dashboard activity, error logsAutomatically, via our systems
End-customer verification dataAadhaar number, PAN, bank account/IFSC, name, DOB, photograph, OTP responsesSubmitted by Merchants via the API, on behalf of their end customers

3Identity & verification data

Where our API is used to verify a government identifier (such as Aadhaar or PAN), we process that data strictly to return a verification result to the Merchant. We do not use end-customer identity data for advertising, profiling, or any purpose unrelated to the verification request that generated it.

  • Full Aadhaar numbers are never returned in an API response; only masked or last-4 references are exposed where applicable.
  • OTP-based verification sessions are scoped to a single reference ID and expire on a short window.
  • Consent is a mandatory field on every identity verification request submitted through the API — Merchants are responsible for obtaining that consent from their end customer before calling us.

4How we use information

  • To provide, operate and maintain the verification API and dashboard.
  • To authenticate accounts and enforce API rate limits and wallet balances.
  • To detect fraud, abuse, or misuse of the platform.
  • To meet regulatory, audit and compliance obligations applicable to identity verification services in India.
  • To communicate service updates, invoices, and security notices.
  • To improve reliability of the API based on aggregated, de-identified usage patterns.

6Sharing & disclosure

We do not sell personal data. We share data only in the following circumstances:

  • With UIDAI or other official source systems, strictly as required to complete a verification request.
  • With infrastructure and hosting providers who process data on our behalf under confidentiality obligations.
  • With payment processors, to process wallet top-ups and billing.
  • With regulators, courts, or law enforcement, where legally compelled to do so.
  • With a successor entity in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.

7Data retention

Verification records, including request/response logs and supporting documents, are retained for the lifetime of the Merchant's account to preserve an audit trail for compliance and dispute-resolution purposes, unless a shorter period is required by applicable law or agreed in writing.

Why we retain verification records

Regulated onboarding (lending, broking, exchanges) commonly requires proof that a verification occurred. We retain the verification event and its outcome so Merchants can produce that proof on request from a regulator or auditor.

Account and billing data is retained for as long as the account is active, plus a period afterward as required for tax, accounting and legal record-keeping.

8Security measures

  • All data in transit is protected with TLS encryption.
  • Sensitive fields are encrypted at rest.
  • Access to production data is restricted to authorised personnel on a need-to-know basis.
  • API access requires authenticated, per-Merchant credentials.
  • All verification requests are logged with a timestamp and reference ID for audit purposes.

No system is completely secure. If we become aware of a data breach affecting your information, we will notify you and take reasonable steps to limit the impact, in line with applicable law.

9Your rights

Subject to applicable law, you may have the right to access, correct, or request deletion of your personal data, and to object to certain processing. Merchants can exercise these rights for their account data by contacting us directly. End customers should raise identity-data requests with the Merchant they interacted with, as the Merchant is the data controller for that relationship; we will support the Merchant in fulfilling verified requests.

10Cookies & tracking

Our website and dashboard use essential cookies required for login sessions and security, and limited analytics cookies to understand product usage. We do not use cookies for third-party advertising.

11Children's data

Our services are intended for business use and are not directed at children. We do not knowingly collect personal data from individuals under 18 except where an end customer's identity data is submitted by a Merchant as part of a lawful verification flow.

12International transfers

Our infrastructure is primarily hosted in India. Where any data is processed outside India — for example via a sub-processor — we take reasonable steps to ensure it receives an equivalent level of protection to that described in this policy.

13Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal requirements. Material changes will be notified to Merchants via email or dashboard notice. The "Effective date" at the top of this page reflects the latest revision.

14Contact & grievance officer

For privacy questions, data requests, or grievances, reach out using the details below.

Grievance officer

Priyanshu Singh

Email

support@verificationapis.com

Registered Address

Plot No 6, Khasara No 407 Mishrpur, Lucknow, Uttar Pradesh, 226026