VerityOps Privacy Policy

Effective date: 2026-07-09

This Privacy Policy describes how VerityOps ("Company," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with:

  • our marketing website at verityops.ai (the "Website");
  • our software-as-a-service application at app.verityops.ai (the "Service"), including the Questionnaires, Library, Portal, Deal Room, and (when available) Inbox capabilities;
  • customer-branded trust portals served by the Service at /trust/[slug] (each, a "Portal"); and
  • email correspondence with us.

Two roles we play. For personal information we collect for our own purposes (Website analytics, account and billing records, our own marketing and correspondence), we act as the data controller / "business." For personal information contained in Customer Content, and for Portal Visitor information we process in operating a Customer's Portal, we act as a processor / "service provider" on behalf of the Customer — that processing is governed by our Data Processing Addendum, available at verityops.ai/dpa, and by the Customer's own privacy notices. Separately, we process limited technical data (for example, IP addresses, email-domain signals, and rate-limit counters) across the Service — including across Portals — for our own security, anti-abuse, and fraud-prevention purposes. For that processing we act as a controller / "business."


Definitions

  • "Company" (also "VerityOps," "we," "us," or "our") refers to Singleton Ventures LLC, a Utah limited liability company doing business as VerityOps.
  • "Website" — our marketing website at verityops.ai.
  • "Service" — our software-as-a-service application at app.verityops.ai, including the Questionnaires, Library, Portal, Deal Room, and (when available) Inbox capabilities.
  • "Customer" — the business that holds a VerityOps account and operates one or more workspaces in the Service.
  • "Authorized User" — an individual authorized by a Customer to use its workspace.
  • "Portal" — a Customer-branded trust portal served by the Service at /trust/[slug]; a "Portal Visitor" is an individual who visits one.
  • "Customer Content" — the documents, answers, and other materials a Customer or its Authorized Users upload to or generate within the Service.
  • "Usage Data" — aggregate or de-identified data about use of the Service that does not identify any individual, Customer, or Customer Content.

These summaries correspond to the fuller definitions in the VerityOps Terms of Service; for customers bound by the Terms of Service, the definitions there control for contractual purposes.


1. Who This Policy Covers

This Policy addresses four populations:

  1. Website visitors — anyone browsing verityops.ai or public pages of the Service.
  2. App users — Authorized Users and other individuals who create or use accounts on the Service.
  3. Portal Visitors — individuals who visit a Customer's Portal, verify their email, sign NDAs or clickwrap terms, or view gated documents.
  4. Email correspondents — anyone who emails us (support, sales, legal, privacy, or other addresses).

Each population is covered in Sections 2–5 below; Sections 6 onward apply to everyone.


2. Website Visitors

2.1 What we collect. When you visit the Website or public Service pages, we collect limited, privacy-conscious analytics:

  • Funnel and event analytics — page views, referrers, and product-relevant events (for example, pricing-page visits, trial signups), used to understand how the Website performs.
  • Core Web Vitals and performance telemetry — load-time and rendering metrics used to keep the site fast.
  • Standard server logs — IP address, user-agent, timestamps, and requested URLs, retained for security and troubleshooting.

2.2 What we do not do. We do not use advertising trackers, third-party ad pixels, or cross-site behavioral advertising cookies, and we do not sell or share personal information for advertising purposes (see Section 8.3).

2.3 Cookies. We use a small set of cookies and similar technologies:

Cookie categoryPurposeExamples
AuthenticationKeep app users signed in to the ServiceFirst-party authentication session cookies
Portal sessionsMaintain a verified Portal Visitor session after magic-link verificationA first-party Portal session cookie
Preferences / securityCSRF protection, load balancing, remembering non-tracking preferencesFirst-party functional cookies
AnalyticsThe minimal funnel/performance analytics described in Section 2.1First-party or privacy-focused analytics identifiers

We do not use cookies for advertising. The Website uses only strictly necessary cookies and first-party analytics without cross-site tracking, so no cookie-consent banner is presented.

We do not track users over time and across third-party websites, and therefore do not respond to browser Do Not Track signals; because we do not sell or share personal information, opt-out preference signals such as Global Privacy Control impose no additional obligations on us, though our processing already conforms to their intent.


3. App Users

3.1 What we collect.

  • Account data — your name and email address, collected and managed through our authentication provider (see the Subprocessor List, Section 7), along with workspace membership and role information. If your organization enables single sign-on, we receive identity attributes from your identity provider.
  • Billing data — subscription plan, billing history, and payment status. Payments are processed by Stripe; we never receive or store full payment card numbers. Stripe collects card details directly under its own privacy policy.
  • Content you upload — Customer Content, including evidence documents, canonical answers, questionnaire files, and portal content. We process this on behalf of your organization (the Customer) as a service provider; it is governed by the Terms of Service, the Data Processing Addendum, and your organization's own policies. Your organization's workspace admins control this content.
  • Service activity — audit and activity logs of actions taken in a Workspace (for example, uploads, approvals, exports, portal configuration changes), which are visible to your organization as a Service feature.
  • Support communications — messages you send to support@verityops.ai and related metadata.

3.2 How we use it. To provide, secure, and support the Service; to authenticate you; to bill your organization; to communicate with you about the Service (transactional notices, security alerts, material changes); to enforce our Terms of Service; and to comply with law. We may send product-related announcements to account holders; you can opt out of non-essential emails, but not transactional or security notices while you hold an account.

3.3 AI features and your content. AI features generate draft answers grounded in your organization's own uploaded content. We do not use Customer Content to train AI models. AI inference is performed by our cloud AI infrastructure providers under service terms that prohibit them from retaining inference inputs or outputs or using them to train models; these providers are identified in the Subprocessor List (Section 7).


4. Portal Visitors

This section applies when you visit a Customer's Portal. The Portal belongs to the Customer; we operate the infrastructure on the Customer's behalf.

4.1 What we collect.

  • Email address — collected when you request access to gated content or AI Q&A, used to send a magic-link verification email and to maintain your verified session (via a first-party session cookie).
  • NDA / clickwrap signature records — if the Customer requires you to accept an NDA or other terms, we record your acceptance, including your verified email address, timestamp, the identity of the accepted document, and a SHA-256 fingerprint of the accepted text, so that both you and the Customer have a reliable record of exactly what was accepted.
  • Document-access activity logs — records of your Portal activity, including verification events, documents viewed or downloaded, AI Q&A questions asked, and questionnaire submissions.
  • Technical data — IP address and user-agent, used for rate limiting, abuse prevention, and security.

4.2 Disclosure to the Customer — read this. Your Portal activity is disclosed to the Customer whose Portal you visit. This includes your verified email address, your NDA acceptance records, and your document-access activity logs (which documents you viewed or downloaded, and when). Gated documents you access may also be watermarked with your identity. This disclosure is a core function of the Portal — it is how the Customer knows who has reviewed its security materials. If you do not consent to this, do not verify your email or access gated content.

4.3 Who is responsible. We process Portal Visitor information as a service provider on behalf of the Customer. The Customer determines what content is available, what terms you must accept, and how it uses the activity information disclosed to it. The Customer's own privacy notice governs its use of your information; any NDA you sign is between you and the Customer, not with us. We use Portal Visitor information only to operate the Portal, enforce security and rate limits, and as described in this Policy.

4.4 What we do not do. We do not use Portal Visitor email addresses for our own marketing, and we do not sell or share them (see Section 8.3).


5. Email Correspondents

If you email us (for example, support@verityops.ai or legal@verityops.ai), we collect your email address, the content of your message, and related metadata. We use it to respond, to keep records of the correspondence, and, where relevant, to enforce or defend legal rights. Transactional email is delivered through our email service providers listed in Section 7.


6. How We Use Personal Information — Summary and Legal Bases

We use personal information to:

  1. provide, operate, secure, and support the Website and the Service (performance of contract; legitimate interests);
  2. authenticate users and Portal Visitors and prevent fraud and abuse (performance of contract; legitimate interests; legal obligation);
  3. process subscriptions and payments through our payment processor (performance of contract);
  4. deliver Portal functionality on Customers' behalf, including the disclosures in Section 4.2 (processing on the Customer's documented instructions);
  5. communicate transactional, security, and service notices (performance of contract; legal obligation);
  6. analyze aggregate Website and Service usage to improve our offering, using Usage Data that does not identify individuals (legitimate interests);
  7. comply with law and enforce agreements (legal obligation; legitimate interests).

7. Service Providers (Subprocessors)

We share personal information with service providers that process it on our behalf to run the Website and the Service (cloud hosting and AI inference, application hosting, authentication, payment processing, network and email services, and internal operations tooling).

The authoritative, current list of these providers — including each provider's role and location — is Annex III of our Data Processing Addendum, available at verityops.ai/dpa, which also defines the change-notification mechanics. We maintain one list, there, so it is never out of date in two places. Each provider is bound by contractual terms limiting its use of personal information to providing services to us; for personal information we process on behalf of Customers, these providers act as Subprocessors under the DPA.


8. Other Disclosures

8.1 To Customers. As described in Section 4.2, Portal Visitor information is disclosed to the Customer whose Portal was visited. Workspace activity of Authorized Users is visible to their own organization as a feature of the Service.

8.2 Legal and safety. We may disclose personal information where required by law, subpoena, or legal process; to protect the rights, safety, or property of Company, our customers, or the public; or to enforce our agreements. Where legally permitted, we will notify affected Customers of legal demands for their Customer Content.

8.3 No sale or advertising sharing. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).

8.4 Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy and applicable law; we will provide notice of any resulting change in control or use.

8.5 Aggregate data. We may use and disclose Usage Data — aggregate or de-identified data that does not identify any individual, Customer, or Customer Content — for any lawful purpose, and we commit not to attempt to re-identify it.


9. Security and Data Location

We maintain administrative, technical, and physical safeguards designed to protect personal information, including: encryption in transit (TLS 1.2 or higher) and at rest (AES-256); tenant isolation enforced at the database level via row-level security; managed encryption-key infrastructure; and audit and activity logging. We are pursuing SOC 2 Type II examination; we do not currently claim any certification.

Data location. Personal information is hosted in the United States. If you access the Website, Service, or a Portal from outside the United States, you understand that your information will be transferred to and processed in the United States. The Service is offered to U.S. businesses. Where personal data of non-U.S. data subjects is nonetheless contained in Customer Content, the transfer mechanisms in the Data Processing Addendum (Section 12) apply as a fallback.

No method of transmission or storage is completely secure; we cannot guarantee absolute security.


10. Your Rights and Choices

10.1 Requests. You may request access to, correction of, or deletion of your personal information, or exercise other rights available under applicable law, by emailing legal@verityops.ai. We will verify your request (typically against your verified email address) and respond within the time required by applicable law. We will not discriminate against you for exercising your rights.

10.2 If we hold your data on a Customer's behalf. For personal information we process as a service provider — including Customer Content and Portal Visitor records — your request should generally be directed to the relevant Customer (your employer, or the company whose Portal you visited), which controls that data. If you contact us directly, we will refer your request to that Customer and assist it in responding, as required by our Data Processing Addendum.

10.3 California residents. Depending on applicability thresholds, California residents may have rights under the CCPA/CPRA to know, access, correct, delete, and port personal information, to opt out of sale/sharing (we do not sell or share — see Section 8.3), and to limit use of sensitive personal information (we do not use sensitive personal information for purposes requiring a limit right). You may use an authorized agent, subject to verification. We voluntarily extend the request process described in this Section 10 to all U.S. residents, subject to verification and lawful exceptions.

10.4 EEA, UK, and Swiss residents. Depending on applicability, individuals in these regions may have rights under the GDPR and equivalents to access, rectify, erase, restrict, and port personal data, to object to processing based on legitimate interests, to withdraw consent where processing is based on consent, and to lodge a complaint with a supervisory authority.

10.5 Marketing choices. You may opt out of non-essential marketing emails at any time via the unsubscribe link or by contacting legal@verityops.ai. Transactional and security emails continue while you hold an account or an active Portal session.

10.6 Cookies. Most browsers let you refuse or delete cookies; doing so may break sign-in and verified Portal sessions, which depend on the cookies in Section 2.3.


11. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy:

  • Account data and Customer Content — retained for the life of the Customer's account, then handled per the Terms of Service continuity terms: a 30-day post-termination export window, deletion from the production Service within 30 days after that window closes, and expiration of residual backup copies on a rolling basis (in any event within no more than 35 days, per the Terms of Service, Section 10.4(c)).
  • Portal Visitor records (verification records, activity logs) — retained as part of the relevant Customer's Customer Content and deleted on the same schedule. NDA and clickwrap acceptance records (signer identity, timestamp, identity of the accepted document, and its SHA-256 fingerprint — not the underlying gated documents) are retained for up to seven (7) years from acceptance, as evidence of the agreement for the benefit of the Customer and the accepting party, and are then deleted.
  • Billing records — retained as required for tax, accounting, and audit purposes.
  • Website analytics and server logs — retained for short operational windows appropriate to security and performance analysis.
  • Email correspondence — retained as long as reasonably necessary for the purpose of the correspondence and any related legal obligations.

12. Children

The Website, the Service, and Portals are business tools and are not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact legal@verityops.ai and we will delete it.


13. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a revised effective date. For material changes, we will provide notice — via the Service, email to account holders, or a prominent Website notice — before the change takes effect. Your continued use after the effective date constitutes acceptance of the updated Policy.


14. Contact Us

  • Privacy requests and questions, and legal notices: legal@verityops.ai
  • Support: support@verityops.ai

VerityOps is a trade name of Singleton Ventures LLC, a Utah limited liability company (United States). Mailing address: Singleton Ventures LLC, 7533 S Center View Ct, Ste N, West Jordan, UT 84084, USA.