1. Data controller
For account and billing data, the data controller is:
Oleksandr KryvtsunNIF: Z2015426X
C/ Uruguay 1, Bloque E, Escalera 2, Planta 01, Puerta 7A
Edificio Mirador (Camporrosso Village), 03509 Finestrat (Alicante), Spain
[email protected]
Privacy requests: [email protected]
2. Scope
This policy covers data processed when you use verid.io, create an account, connect Magento, connect ad platforms, install the Verid purchase pixel, or subscribe to a paid plan. You remain the controller for your Magento customers' personal data; Verid processes store commerce and advertising data as your processor for profit analytics (see Data & DPA).
3. Data we collect
Account & billing
- Name, email address, store / workspace name
- Role (owner / viewer) and team membership
- Subscription plan and billing history (card data is processed by Stripe — we do not store full card numbers)
- Notification preferences for margin alerts
Store commerce (from Magento sync)
- Store URL, timezone, base currency, payment fee settings
- Orders and credit memos: amounts, statuses, SKUs, product names, quantities, COGS, shipping, taxes, discounts — attributed to store calendar days
- Encrypted Magento API credentials you provide
Advertising
- OAuth tokens and ad account IDs when you connect Meta or Google Ads; daily campaign spend pulled via those APIs
- Manual spend rows you enter in the dashboard
Purchase pixel (optional)
- Purchase events: order identifier, campaign / click identifiers you configure, timestamps — used to attribute orders to campaigns for ROAS / profit views
- We do not use the pixel for cross-site advertising or sell event data
4. Purposes & legal bases
- Contract — provide the Verid service, sync, dashboards, exports
- Legitimate interests — security, abuse prevention, product improvement on aggregated/anonymous metrics
- Legal obligation — tax and accounting records where required
- Consent — optional marketing email (if offered); withdraw anytime
5. Processors
We use subprocessors such as hosting, Postgres, Redis, Stripe (payments), and Resend (email). A current list is available on request at [email protected].
6. Retention
Account and synced commerce data are retained while your workspace is active. After cancellation we may delete or anonymise store data within a reasonable period (typically up to 90 days), except records we must keep for legal or billing purposes. Encrypted credentials are removed when you disconnect an integration.
7. Your rights (EEA / UK)
You may request access, rectification, erasure, restriction, portability, or object to certain processing. Contact [email protected]. You may lodge a complaint with the AEPD (Spain) or your local supervisory authority.
8. International transfers
If data is processed outside the EEA, we use appropriate safeguards (e.g. SCCs) with providers.
9. Security
Credentials are encrypted at rest; access is limited to your workspace members; transport uses TLS. No method is 100% secure — report issues to [email protected].
10. Changes
We may update this policy; the "Last updated" date will change. Material changes may be notified by email or in-app.