1. Data controller
For account and billing data, the data controller is:
Oleksandr KryvtsunNIF: Z2015426X
C/ Uruguay 1, Bloque E, Escalera 2, Planta 01, Puerta 7A
Edificio Mirador (Camporrosso Village), 03509 Finestrat (Alicante), Spain
[email protected]
Privacy requests: [email protected]
2. Scope
This policy covers data processed when you use verid.io, create an account, connect Magento, connect ad platforms, install the Verid purchase pixel, enable profit conversion uploads to Google Ads or Meta, use product label feeds, or subscribe to a paid plan. You remain the controller for your Magento customers' personal data; Verid processes store commerce and advertising data as your processor for profit analytics (see Data & DPA).
3. Data we collect
Account & billing
- Name, email address, store / workspace name
- Role (owner / viewer) and team membership
- Subscription plan and billing history (card data is processed by Stripe — we do not store full card numbers)
- Email address for transactional mail (trial, billing, optional digest)
Store commerce (from Magento sync)
- Store URL, timezone, base currency, payment fee settings, and merchant shipping-cost rules you configure (method matchers, fallback € / % of revenue)
- Orders and credit memos: amounts, statuses, SKUs, product names, quantities, COGS, shipping charged, taxes, discounts, payment / shipping method codes — attributed to store calendar days
- Customer identifiers needed for new vs returning and LTV analytics: Magento customer id and customer email (when present on the order). We do not sync full billing/shipping addresses for core P&L
- Encrypted Magento API credentials you provide
Advertising
- OAuth tokens and ad account IDs when you connect Meta or Google Ads; daily campaign spend pulled via those APIs
- Manual spend rows you enter in the dashboard
- When you enable profit conversion uploads: Google Ads click conversions and/or Meta Conversions API Purchase events with conversion value set to calculated gross profit (not necessarily the order grand total). Meta events may include hashed email (SHA-256) and click cookies (fbc / fbp) when available from the pixel
Purchase pixel (optional)
- Installed as a local Magento bootstrap that does not contact Verid until marketing consent is granted; then PageView / Purchase may include order identifier and campaign / click identifiers (e.g. gclid, gbraid, wbraid, fbclid, fbc, fbp) for attribution and optional upload to ad platforms. Client-supplied consent fields are attribution metadata only — legal consent records stay in your CMP.
- We do not use the pixel for cross-site advertising brokerage or sell event data
Contact form & aggregate lead measurement
- When you contact us, we use the name, email address, store URL, subject, and message you provide to respond to the request and maintain the related correspondence.
- After a contact form submission succeeds, we record a PII-free internal aggregate using only a fixed page-source label and a fixed request category. It does not contain your name, email, store URL, message, referrer, UTM values, or browser identifiers, and it does not create analytics cookies or local storage.
Pricing & checkout attribution
- When you start checkout from a Verid landing page, we may attach a fixed internal source label (for example, profit calculator) to the checkout acceptance record so we can measure aggregate funnel performance.
- This label is selected from a small allowlist. We do not store a raw referrer, UTM value, URL, or browser identifier for this purpose.
Product label feed (optional)
- Public feed URL (tokenised) that exposes SKU identifiers and profit-based custom labels for Merchant Center / Shopping — no customer personal data
4. Google user data (Google API Services)
This section discloses how Verid accesses, uses, stores, and shares Google user data obtained through Google OAuth / the Google Ads API, in line with the Google API Services User Data Policy, including Limited Use requirements.
What we access
When you choose Connect Google in Verid, you authorize Verid to access your Google Ads account. Depending on the features you enable, that may include: OAuth tokens, Google Ads customer / account identifiers, campaign and spend metrics, and (only if you enable profit conversion uploads) the ability to upload click conversion values derived from Magento order gross profit.
How we use and store it
- Use: only to provide Verid's user-facing Magento profit analytics (show ad spend next to Magento contribution / net profit) and, if you enable it, to upload profit-valued conversions back to the same Google Ads account you connected.
- Store: OAuth tokens are encrypted at rest; spend and conversion-related records are kept in your Verid workspace database for dashboards, sync, deduplication, and support while the workspace is active (see Retention).
- Verid does not create, edit, pause, or manage Google Ads campaigns, budgets, or creatives on your behalf.
With whom we share, transfer, or disclose Google user data
We share, transfer, or disclose Google user data only as follows — and we do not sell Google user data, and we do not transfer or disclose it to third parties for purposes unrelated to providing or improving Verid's features you use:
- You / your workspace members — owners and invited team members with access to your Verid workspace can see spend and related analytics derived from the connected Google Ads account.
- Google — we send API requests (and optional conversion uploads you enable) to Google's Google Ads API so the feature can work. Google processes that data under Google's terms as an independent platform.
- Infrastructure subprocessors necessary to operate Verid (currently: hosting / VPS infrastructure for verid.io, managed Postgres database storage, Redis for job queues, and Resend for transactional email such as alerts). These providers process data only to host or operate the service under our instructions; they are not advertising partners and do not receive Google user data for their own marketing.
- Legal / safety — if required by law, regulation, legal process, or to protect the rights, safety, or security of Verid, our users, or the public.
- Business transfer — in a merger, acquisition, or asset sale, Google user data may transfer to a successor only with notice and continued commitment to this policy (or equivalent protections) and applicable Limited Use rules.
We do not transfer or disclose Google user data to data brokers, information resellers, or unrelated advertising platforms. We do not use Google user data to serve ads, for retargeting or interest-based advertising outside the Verid features you enable, or to determine credit-worthiness or lending.
Human review of Google user data is limited to cases needed to operate, secure, or support the service (e.g. debugging a sync you reported), and is not used to build unrelated profiles or advertising products.
5. Purposes & legal bases
- Contract — provide the Verid service, sync, dashboards, exports, and optional profit signals to platforms you connect
- Legitimate interests — security, abuse prevention, product improvement on aggregated/anonymous metrics
- Legal obligation — tax and accounting records where required
- Consent — optional marketing email (if offered); withdraw anytime
6. Processors & subprocessors
We use subprocessors such as hosting, Postgres, Redis, Stripe (payments — account/billing only), and Resend (email). When you enable conversion uploads, Google and/or Meta act as independent controllers for the data you instruct us to send under their platform terms. A current subprocessor list is available on request at [email protected]. See also Data & DPA.
7. Retention
Account and synced commerce data are retained while your workspace is active. After cancellation we may delete or anonymise store data within a reasonable period (typically up to 90 days), except records we must keep for legal or billing purposes. Encrypted credentials and OAuth tokens are removed when you disconnect an integration. Synced Meta / Google Ads spend rows imported via that connection are also deleted on disconnect (manual spend entries without a matching sync record are kept). Conversion upload logs are retained for deduplication and support.
Contact-form correspondence is retained only as long as reasonably necessary to respond and maintain the correspondence, or to meet a legal obligation. The separate aggregate contact-event record contains no direct identifiers and is used only for internal conversion reporting and product improvement.
8. Your rights (EEA / UK)
You may request access, rectification, erasure, restriction, portability, or object to certain processing. Contact [email protected]. You may lodge a complaint with the AEPD (Spain) or your local supervisory authority. Disconnecting Google in Verid revokes our API access; you can also revoke access in your Google Account permissions.
9. International transfers
If data is processed outside the EEA, we use appropriate safeguards (e.g. SCCs) with providers. Ad platforms you connect (including Google) may process data in the US or other regions under their terms.
10. Security
Credentials and OAuth tokens are encrypted at rest; access is limited to your workspace members; transport uses TLS. No method is 100% secure — report issues to [email protected].
11. Changes
We may update this policy; the "Last updated" date will change. Material changes to how we use Google user data will be disclosed here before we use that data in a new way; where required we will seek renewed consent.