Legal
Privacy Policy
Verified Everywhere is a trading name of JWC Apps, based in San Diego, California. We set up official verification programs for small businesses. To do that we collect your contact details, information about your business, business documents you upload at intake, delegated access roles on your platform accounts, DMARC report data if you are on monitoring, and basic website analytics. We never collect your passwords, your government-issued ID documents, or your payment card numbers. That is a deliberate design choice, not an oversight, and the rest of this policy explains how it works. We do not sell or share your personal information. You can ask us to delete your uploaded documents once your engagement closes, and we relinquish all access within 7 business days of termination.
Who we are and what this policy covers
Verified Everywhere is a trading name of JWC Apps, a company based in San Diego, California, USA. This policy explains what we do with information on verifiedeverywhere.com and in the work we do for clients.
Our clients are businesses. Most of what we handle is business information. Some of it still identifies a person: an owner's name, a work email address, a home address printed on a utility bill, an officer's name on a registration document. We treat all of it as confidential, and where it identifies a person we treat it as personal information under this policy.
If you are just visiting the website and have not hired us, only the sections on cookies, analytics, and your rights apply to you.
We are not affiliated with, endorsed by, or sponsored by any platform or certificate authority we work with.
What we collect
We collect the following, and only for the reasons given.
We ask for the least we can get away with. If we ask for something and you cannot see why we need it, ask us. If we cannot give you a straight answer, we should not be asking.
- Contact and account details. Your name, work email, phone number, company name, role, and mailing address. We need a real human contact because most verification steps require one.
- Business information. Legal entity name, trading names, EIN, your domains, your registrar, your DNS provider, your email provider, which platform accounts already exist, and the history of what has been tried before. This is the diagnostic layer. It is most of what makes a rescue engagement work.
- Business documents you upload at intake. Business registration, licenses, a utility bill, a bank statement, EIN letter, trademark certificate, logo artwork, and storefront photos. Platforms and certificate authorities decide what proof they want. We collect what the specific application in front of us requires.
- Delegated access. Roles, permissions, and access tokens granted to us through each platform's official flow. This is an access grant, not a credential. See the section on delegated access below.
- DMARC aggregate report data, if you are on a Trust Monitoring retainer. This is machine-generated reporting about email authentication on your domain.
- Website analytics. Pages viewed, referring source, approximate location derived from IP address, and device and browser type.
- Payment records. Stripe processes payments. We see a receipt record, the amount, the billing name and email, and the last four digits of the card. We never see or store the full card number.
- Support correspondence. Emails, call notes, and shared documents relating to your engagement.
A note on bank statements
Some certificate authorities and some platform appeals accept a bank statement as proof of business name and address. That is the only thing we need from it.
Redact your account number and your transaction lines before you send it. We will ask you to do this at intake, and if you send an unredacted statement we will ask you to send a redacted one instead. The name and the address at the top are the parts that do the work.
What we never collect, and why that matters
We do not accept or store any of the following, ever:
This is not caution for its own sake. Those three items are exactly what a scammer needs from you. If we never hold them, a breach of our systems cannot expose them, and no one can convincingly impersonate us to ask you for them.
So here is a rule you can use. If anyone contacts you claiming to be Verified Everywhere and asks for a password, an ID document, or a card number, it is not us. Stop, and email us at the address at the bottom of this page.
Some steps genuinely require your identity documents. The certificate authority identity check involves an officer of your company on a live video call with their ID, or a notary appointment. The Google Business Profile video verification is you, on site, live in your own app. Those are done by you, directly with the platform or the certificate authority. Your ID goes to them and never passes through us. Your own two-factor prompts stay on your own device, and platform subscriptions are paid by you on your own account.
- Passwords or login credentials to any of your accounts.
- Government-issued ID documents. No passport scans, no driver's licenses, no ID selfies.
- Payment card numbers.
How we use your information
We use what we collect to do the work you hired us for and to run the business behind it. Specifically:
We do not use your documents, your DMARC data, or your engagement records to train machine learning models, to build a marketing list, or to enrich any data product. We do not sell them. We do not rent them.
We may describe our work in anonymous, aggregate terms, for example how long a certain kind of reinstatement typically takes. We will not name you as a client in marketing without your written permission.
- To prepare and submit your applications to platforms and certificate authorities.
- To configure DNS records, email authentication, and profile data within the scope you authorized in writing.
- To communicate with you about your engagement, including the parts that need you personally.
- To monitor authentication and profile status if you are on a retainer, and to tell you when something breaks.
- To bill you and keep the accounting records the law requires.
- To improve how we run engagements, using our own operational records.
- To meet legal obligations and to defend or establish legal claims if that ever becomes necessary.
How your documents are stored
Documents you upload go into private storage. They are encrypted at rest and in transit. There are no public links and no shareable URLs.
Access is limited to the people actually working your engagement. Every person has a named account with two-factor authentication. We do not use shared logins. Access is logged.
We avoid moving your documents around as email attachments. When a platform or certificate authority requires an upload, we upload directly into their portal rather than emailing files onward.
When a person leaves the engagement or the company, their access is removed as part of offboarding, not later.
Delegated access, and exactly what it does and does not let us do
We work through each platform's official delegated-access flow. In practice that means one of these:
Two things follow from that. First, you can see us in the access list, and you can remove us yourself at any time, without our help and without changing your own password. Second, our access is separately auditable from yours, so nothing we do is ever mixed in with your own activity.
We ask for the least-privileged role that can actually do the job. Some platforms do not offer a narrow role. A Google Workspace or Microsoft 365 admin account, for example, is broader than what DNS and authentication work requires, because that is how those products are built. Where that happens we will tell you at the time rather than let you assume the role is narrower than it is. We use it only within the scope written into your Letter of Authorization, and every grant is recorded in your access register.
We require a scope-limited Letter of Authorization before we touch anything. It names the specific domains and the specific record types we may change. If work needs to go beyond that, we come back to you and ask for a revised authorization first.
At handoff we give you an access register listing every access we hold and how to remove each one. We relinquish all access within 7 business days of termination.
- A Manager role on your Google Business Profile.
- Partner access on your Meta assets.
- DNS delegation at your registrar, scoped to the records named in your authorization.
- A dedicated admin user in your Google Workspace or Microsoft 365 tenant, created for us and separate from your own account.
DMARC report data
If you are on a Trust Monitoring retainer, mailbox providers send aggregate DMARC reports to a monitoring endpoint we configure for your domain.
An aggregate report is a machine-generated XML summary. It contains sending IP addresses, message counts, the domains involved, and pass or fail results for SPF, DKIM, and DMARC alignment. It does not contain the content of your emails, subject lines, or the addresses of the people you email.
Failure reports, sometimes called forensic or ruf reports, are a different thing. They can include fragments of message headers, which can include individual email addresses. We do not enable failure reporting by default. If you ask us to enable it, we will explain the tradeoff in writing first.
We use this data to tell you what is authenticating, what is failing, and what changed. Nothing else.
How long we keep things, and how to get documents deleted
Retention works like this:
You can ask us to delete your uploaded business documents once your engagement closes. Email us and we will delete them and confirm in writing. This is a standing right, not a favor, and you do not need to give a reason.
Two honest limits. We keep billing and accounting records for the period tax and financial recordkeeping rules require, even after you ask us to delete documents. And if a certificate or a platform profile is still live, we will tell you which records you may want to keep on your own side before we destroy our copy, because renewal and reissue are much harder without them.
- Business documents you uploaded: deleted on request after your engagement closes, and otherwise deleted 12 months after close.
- Delegated access: relinquished within 7 business days of termination, with an access register provided at handoff.
- DMARC report data: retained for 13 months while a monitoring retainer is active, so year-over-year comparison works, and deleted 30 days after the retainer ends.
- Engagement and correspondence records: retained for the period we need to support renewals, reissues, and disputes.
- Billing records: retained for the period required by tax and accounting rules.
- Website analytics: retained on a rolling basis as set by our analytics provider.
Who else touches your data
We use a small number of service providers to run the business. They are bound to use your information only to provide their service to us.
We will name the current provider in each category on request, and we keep an up-to-date list at verifiedeverywhere.com/subprocessors. If we change a provider in a way that affects where your documents sit, we will update that page.
We do not sell your data, and we do not share it for advertising.
- Stripe, for payment processing.
- Hosting and cloud infrastructure, where the website and your documents live.
- Email delivery, for the messages we send you.
- A DMARC monitoring platform, for clients on a Trust Monitoring retainer.
- Standard business tools for email, calendars, documents, and accounting.
Your California privacy rights
California residents have privacy rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. These rights cover business contacts as well as ordinary consumers. The old carve-out for business-to-business contact information expired on January 1, 2023.
Your rights are:
Two of those rights do not really arise with us. We do not sell or share personal information, so there is nothing to opt out of. And we deliberately do not collect the categories that would count as sensitive personal information, such as government ID documents and account credentials, so there is very little to limit.
Whether we meet the statutory thresholds that make a company a covered business under this law depends on our size in a given year. Rather than make you work that out, we will honor requests to know, delete, and correct from any client or website visitor who asks, regardless of where you live and regardless of whether we are technically covered.
To make a request, email us at the address below from the email address we have on file for you, or tell us enough that we can match you to our records. We do not require you to create an account. We will acknowledge your request promptly and respond within 45 days. If we need more time we will tell you why before that window closes. You may use an authorized agent, in which case we will ask for proof that you authorized them.
We will not retaliate against you for exercising any of these rights. We will not deny you service, change your price, or degrade your engagement because you asked.
- The right to know what personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to.
- The right to delete personal information we hold about you.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information.
- The right to limit the use of sensitive personal information.
- The right not to be discriminated against for exercising any of these rights.
If you are outside California
Several other US states now give residents similar rights, and the details vary between them. Rather than run a different process for each state, we apply the same process to everyone: tell us what you want and we will do it if we can lawfully do it.
If you are outside the US, see the section on where your information is processed.
Children
This service is sold to businesses. The website is not directed to children, and we do not knowingly collect personal information from anyone under 16.
If you believe a child has given us personal information, email us and we will delete it.
Security, and what happens if we get breached
What we actually do:
No system is perfectly secure, and we would rather say that plainly than promise you something no one can deliver. What we can tell you is that the highest-value items a thief would want from a company like ours, your passwords, your IDs, and your card numbers, are not in our systems to steal.
If we confirm a security incident that affects your information, we will tell you in writing within 72 hours of confirming it. We will tell you what we know, what we have done, which of your assets were touched, and what we recommend you do. If the picture is still incomplete at 72 hours, we will send you what we have and keep updating you rather than wait for a tidy account. We will also notify regulators and affected individuals where the law requires it.
- We hold no passwords, no ID documents, and no card numbers, which removes the most damaging categories of breach outright.
- Documents are encrypted at rest and in transit, in private storage with no public links.
- Every team member has a named account with two-factor authentication. No shared logins.
- Access is limited to the people working your engagement, and is removed at offboarding.
- Access to your platforms is delegated, logged, recorded in an access register, and relinquished within 7 business days of termination.
Where your information is processed
We are based in San Diego, California, and your information is stored and processed in the United States.
If you are outside the United States and hire us, your information will be transferred to and processed in the United States, where privacy law differs from the law where you live.
Verification work can also involve organizations that operate outside the United States. Certificate authorities and global platforms run international operations, and a submitted application may be reviewed outside the country you are in. We cannot control where a platform or certificate authority processes what you submit to them.
Changes to this policy
If we change this policy we will update the date at the top of the page.
If a change materially affects how we handle client information, we will email active clients before it takes effect rather than rely on you noticing.
How to contact us about privacy
Email privacy@verifiedeverywhere.com for any privacy request, including access, deletion, and correction, or for any question about this policy.
Postal mail reaches us at JWC Apps, [mailing address], San Diego, California, USA.
We aim to acknowledge privacy requests within a few business days and to complete them within 45 days.
If you want to know exactly what access we currently hold on your accounts, ask for your access register. We will send it, and you do not need a reason.
Questions about this document