1Scope of this policy
This Privacy Policy applies to VerifyDocs ("we", "us", "our"), operated by SUPERMINT INFOTECH PRIVATE LIMITED, and covers our website, API, developer dashboard, and any verification services offered under the VerifyDocs brand.
We act in two capacities depending on the data involved:
- As a data controller for account, billing and dashboard data belonging to our business customers ("Merchants").
- As a data processor for end-customer identity data (such as Aadhaar, PAN or bank details) that a Merchant submits to us for the purpose of running a verification. In that case, the Merchant is the controller and instructs us on how that data may be used.
If you are a Merchant, your use of the API is also governed by our Terms of Service and any Data Processing Agreement signed with us, which take precedence for API-level data handling.
2Information we collect
We collect information in three broad categories:
| Category | Examples | Collected from |
|---|---|---|
| Account & billing data | Name, business email, phone, company details, GSTIN, billing address, payment records | You, directly |
| Usage & technical data | API request logs, IP address, device/browser metadata, dashboard activity, error logs | Automatically, via our systems |
| End-customer verification data | Aadhaar number, PAN, bank account/IFSC, name, DOB, photograph, OTP responses | Submitted by Merchants via the API, on behalf of their end customers |
3Identity & verification data
Where our API is used to verify a government identifier (such as Aadhaar or PAN), we process that data strictly to return a verification result to the Merchant. We do not use end-customer identity data for advertising, profiling, or any purpose unrelated to the verification request that generated it.
- Full Aadhaar numbers are never returned in an API response; only masked or last-4 references are exposed where applicable.
- OTP-based verification sessions are scoped to a single reference ID and expire on a short window.
- Consent is a mandatory field on every identity verification request submitted through the API — Merchants are responsible for obtaining that consent from their end customer before calling us.
4How we use information
- To provide, operate and maintain the verification API and dashboard.
- To authenticate accounts and enforce API rate limits and wallet balances.
- To detect fraud, abuse, or misuse of the platform.
- To meet regulatory, audit and compliance obligations applicable to identity verification services in India.
- To communicate service updates, invoices, and security notices.
- To improve reliability of the API based on aggregated, de-identified usage patterns.
5Legal basis for processing
We process personal data on the basis of: performance of a contract with our Merchants; consent captured at the point of verification for end-customer identity data; compliance with applicable legal and regulatory obligations; and our legitimate interest in securing the platform against fraud and misuse.
7Data retention
Verification records, including request/response logs and supporting documents, are retained for the lifetime of the Merchant's account to preserve an audit trail for compliance and dispute-resolution purposes, unless a shorter period is required by applicable law or agreed in writing.
Regulated onboarding (lending, broking, exchanges) commonly requires proof that a verification occurred. We retain the verification event and its outcome so Merchants can produce that proof on request from a regulator or auditor.
Account and billing data is retained for as long as the account is active, plus a period afterward as required for tax, accounting and legal record-keeping.
8Security measures
- All data in transit is protected with TLS encryption.
- Sensitive fields are encrypted at rest.
- Access to production data is restricted to authorised personnel on a need-to-know basis.
- API access requires authenticated, per-Merchant credentials.
- All verification requests are logged with a timestamp and reference ID for audit purposes.
No system is completely secure. If we become aware of a data breach affecting your information, we will notify you and take reasonable steps to limit the impact, in line with applicable law.
9Your rights
Subject to applicable law, you may have the right to access, correct, or request deletion of your personal data, and to object to certain processing. Merchants can exercise these rights for their account data by contacting us directly. End customers should raise identity-data requests with the Merchant they interacted with, as the Merchant is the data controller for that relationship; we will support the Merchant in fulfilling verified requests.
11Children's data
Our services are intended for business use and are not directed at children. We do not knowingly collect personal data from individuals under 18 except where an end customer's identity data is submitted by a Merchant as part of a lawful verification flow.
12International transfers
Our infrastructure is primarily hosted in India. Where any data is processed outside India — for example via a sub-processor — we take reasonable steps to ensure it receives an equivalent level of protection to that described in this policy.
13Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. Material changes will be notified to Merchants via email or dashboard notice. The "Effective date" at the top of this page reflects the latest revision.
14Contact & grievance officer
For privacy questions, data requests, or grievances, reach out using the details below.
Grievance officer
Priyanshu Singh
support@verificationapis.com
Registered Address
Plot No 6, Khasara No 407 Mishrpur, Lucknow, Uttar Pradesh, 226026