1. Who we are and our role
VerifyAI is operated by Switch Labs LC (“Switch Labs,” “we,” “us,” or “our”). Our role depends on whose information it is:
- We are the controller of information about website visitors, people who contact us or request a demo report, and account holders, including account, billing, analytics, and marketing information.
- We are a processor (a “service provider” under U.S. state privacy laws) for the photos, metadata, and results that our customers submit through the API, SDKs, or dashboard to verify their own operations, for example a fleet operator checking a rider’s end-of-trip parking photo. We process that data on the customer’s behalf and under its instructions, according to our agreement with the customer and, where one applies, our Data Processing Addendum. The customer’s own privacy notice governs that data.
If you took a photo in an app or service that uses VerifyAI, please contact that company about your information. We will help it respond. Our GDPR page describes the controller and processor split in more detail.
2. Information we collect
Information you give us
- Account information. When you create an account we collect your email address and password. Passwords are handled by our authentication provider and are not stored in plaintext. If you sign in with an emailed magic link, we collect your email address. We may also hold your name and company if you give them to us.
- Contact and sales inquiries. When you use a contact or enterprise inquiry form we collect your name, email address, company, message, and the page you submitted from. The enterprise form also asks about expected volume, integration platforms, use case, timeline, existing tooling, whether you operate in a regulated industry, and your role.
- Demo report requests. If you ask us to email you a demo report or request a migration review after using the demo, we collect your email address, the demo policy you ran, the verdict and confidence score you saw, whether you want a migration review, and, if you tell us, the product you use today.
- Billing information. When you subscribe to a paid plan, card details are collected directly by our payment processor, Stripe. We receive and store a Stripe customer identifier, your billing email, and your plan and subscription status. We do not store full card numbers.
- Photos and metadata submitted to the Service. Customers send photos, a verification policy, and any metadata their application chooses to include, such as a device identifier, GPS coordinates, or timestamps. Photos can incidentally show people, faces, vehicle license plates, or locations. The customer controls what is sent.
- Communications. When you email us or speak with us, we keep a record of the conversation.
The public demo
Photos you upload to the demo are sent to the image analysis service that produces the result. They are analyzed in memory and are not written to our storage or to verification history. For each demo attempt we record the policy, the verdict and confidence score, the response time, whether you used a sample photo or your own, and the page that sent you to the demo. That record contains no image, no email address, and no IP address. We use IP addresses temporarily, in memory, to rate-limit the demo.
Information collected automatically
- Device and usage data. Like most websites, we and our hosting and analytics providers receive your IP address, browser and operating system type, referring page, pages viewed, and the date and time of your visit.
- Campaign attribution. If you arrive through an ad or a link with campaign parameters, we store a first-party cookie named
va_attrfor up to 90 days. It holds UTM parameters, Google Ads click identifiers (gclid, gbraid, wbraid), campaign, ad group, keyword, device, and network details, your landing page, and your referrer. If you later submit a form or create an account, we save those details with your submission or account so we know which campaigns bring us customers. - Security and abuse prevention. Our contact form may use Cloudflare Turnstile, which evaluates browser and device signals to tell people from bots. We also use IP addresses to rate-limit some forms.
- Error monitoring. When the site hits an error, our error-monitoring provider receives technical details about the error, your browser, and the page.
- Service usage. For account holders we record API requests, request diagnostics, and service events, which we use to run, bill, secure, and troubleshoot the Service.
Cookies, pixels, and similar technologies are described in Section 9.
3. How we use information
- To provide the Service: create and secure accounts, sign you in, process verification requests, run the demo, and provide support.
- To respond to you: answer contact and sales inquiries, send the demo report you asked for, and manage our business relationship with you, including following up by email about your inquiry.
- To bill you: process payments, calculate usage-based fees, and keep financial records.
- To keep the Service secure: detect bots and abuse, enforce rate limits, protect API keys, and investigate incidents.
- To improve the Service: understand how the site and product are used, fix errors, and develop features. Production customer images are processed to provide, secure, support, and improve the ordered service. We do not use them to train shared or general-purpose models unless separately agreed in writing.
- To measure our marketing: learn which ads and campaigns lead to visits, inquiries, signups, and purchases.
- To communicate with you: send service, security, billing, and policy notices. You can opt out of non-essential emails at any time by replying to the email or writing to hello@switchlabs.dev.
- To meet legal obligations: comply with the law, enforce our Terms of Service, and protect our rights and the rights and safety of others.
4. Legal bases for processing
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases when we act as controller:
- Contract: to provide the Service, manage your account, and bill you.
- Legitimate interests: to respond to business inquiries, secure and improve the Service, understand site usage, and market VerifyAI to businesses. We balance these interests against your rights, and you can object at any time.
- Consent: where the law requires consent, for example for certain non-essential cookies and similar technologies or for some electronic marketing. You can withdraw consent at any time without affecting processing that already took place.
- Legal obligation: to keep tax and accounting records and respond to lawful requests.
When we process customer-submitted photos as a processor, the customer determines the legal basis. Our GDPR page sets out the data processing register for that data.
5. How we share information
We do not sell personal information for money. We share it only as follows:
- Service providers. Companies that help us run the Service: cloud hosting and delivery, database and file storage, image analysis, email delivery, payment processing (Stripe), bot protection (Cloudflare Turnstile), and error monitoring. They may use the information only to provide their services to us. The categories of sub-processor that handle customer verification data, and where they are located, are listed on our GDPR page. The named sub-processor list is provided with our Data Processing Addendum on request.
- Analytics and advertising partners. Google (Google Analytics, Google Ads, and Google Tag Manager) and Meta (the Meta Pixel) receive information about your browser and your activity on our site, such as pages viewed and events like submitting an inquiry, starting a signup or checkout, or completing a purchase. When you submit a form or sign up, a one-way hashed (SHA-256) form of your email address may be passed to Google’s tags to help measure conversions. These partners use the information under their own privacy policies.
- Our customers. If you are an end user of one of our customers, we return verification results for your photos to that customer.
- Business transfers. In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to this policy.
- Legal and safety reasons. To comply with law or legal process, to enforce our terms, or to protect the rights, property, or safety of Switch Labs, our customers, or others.
- With your direction or consent. For example, when you ask us to share information with an integration partner.
We may also share aggregated or de-identified information that cannot reasonably be used to identify you.
6. International transfers
Switch Labs is based in the United States, and our service providers may process information in the United States and other countries. Customers can choose EU-region storage for verification data. When personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country that does not have an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses. See the international transfers section of our GDPR page.
7. How long we keep information
- Customer verification images: 90 days by default, then deleted from active systems, unless the customer configures a different retention period.
- Verification results: for the duration of the customer’s service agreement.
- Account data: for as long as your account is open, plus any period the law requires us to keep records, such as for tax and accounting.
- Inquiries and demo report requests: for as long as we need them to respond and manage our relationship with you. After that we delete or de-identify them.
- Public demo photos: not stored. Demo run records contain no image, email address, or IP address.
- The
va_attrcookie: up to 90 days in your browser. - Logs: according to our operational log retention policy.
Deleted information may remain in backups for a limited period until those backups are overwritten.
8. Security
We protect information with encryption in transit and at rest, hashed API keys, least-privilege access controls, and audit logging. Our SOC 2 audit is in progress. No system is perfectly secure, so we cannot guarantee absolute security. Our Security page describes our controls. Please report suspected vulnerabilities to hello@switchlabs.dev.
9. Cookies and similar technologies
We and our partners use cookies, pixels, browser storage, and similar technologies. They fall into these groups:
Strictly necessary
Examples: Sign-in session cookies set by our authentication provider when you use the dashboard; cookies set by our payment processor, Stripe, on checkout pages for fraud prevention.
Purpose: Keep you signed in, secure the Service, and process payments. The Service does not work properly without them.
Marketing attribution (first party)
Examples: va_attr, kept for up to 90 days.
Purpose: Remembers the campaign that brought you to the site (UTM parameters, Google Ads click identifiers, landing page, and referrer) so we can attribute an inquiry or signup to it.
Analytics
Examples: Google Analytics cookies such as _ga, loaded through Google Tag Manager.
Purpose: Understand how visitors find and use the site, such as pages viewed and steps completed in the demo or signup.
Advertising measurement
Examples: Google Ads conversion tracking and conversion linker cookies (such as _gcl_au) and the Meta Pixel (such as _fbp).
Purpose: Measure whether our ads lead to visits, inquiries, signups, checkouts, and purchases. Google and Meta may also use this information under their own policies, including to personalize ads.
We also keep a small flag in your browser’s session storage so the same visit is not counted as engaged more than once.
Your cookie choices
- Use your browser settings to block or delete cookies. Blocking strictly necessary cookies will stop sign-in and checkout from working.
- Opt out of Google Analytics with the Google Analytics opt-out browser add-on.
- Manage Google ad personalization in My Ad Center, and read how Google uses information from sites that use its services.
- Manage Meta ad preferences in your Meta ad settings.
- Use industry opt-out tools such as the DAA opt-out page or, in Europe, Your Online Choices.
Our site does not currently change its behavior in response to browser “Do Not Track” signals.
10. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate information;
- delete your information;
- receive your information in a portable format;
- restrict or object to our processing, including objecting to direct marketing at any time;
- withdraw consent where we rely on it;
- opt out of the “sale” or “sharing” of personal information or its use for targeted advertising;
- appeal our decision on your request; and
- not be treated differently for exercising these rights.
To make a request, email hello@switchlabs.dev. We will verify your identity, for example by confirming the request from the email address on your account, and respond within the time the law requires. Where the law allows, you can use an authorized agent, and we may ask for proof of their authority.
Advertising cookies and U.S. state laws. We do not sell personal information for money. Our use of Google and Meta advertising cookies and pixels may count as “selling” or “sharing” personal information, or as targeted advertising, under some U.S. state laws. To opt out, use the choices in Section 9 or email hello@switchlabs.dev with the subject “Do Not Sell or Share.”
End users of our customers. If your photo was submitted by one of our customers, please send your request to that customer. We act on its instructions and will help it respond.
If you are in the EEA, the United Kingdom, or Switzerland, you can also complain to your local data protection authority. We would appreciate the chance to address your concern first.
11. Children
VerifyAI is a business service. It is not directed to children under 16, and we do not knowingly collect their personal information through the website. If you believe a child has given us personal information, contact hello@switchlabs.dev and we will delete it.
12. Third-party sites and services
The Service links to and integrates with third-party sites and services, such as Stripe for payments and workflow platforms you connect. Their own privacy policies govern their handling of your information. We are not responsible for their practices.
13. Changes to this policy
We may update this policy as the Service changes. When we do, we will update the effective date at the top of this page. If a change is material, we will give notice on this site or by email to account holders before it takes effect.
14. Contact us
Questions about this policy or your information:
- Privacy requests, security reports, and general questions: hello@switchlabs.dev
Switch Labs LC
434 Pine Street
San Francisco, CA 94158
United States