Privacy Policy
Last updated: August 2026
Vericoo is committed to protecting your privacy. This policy explains what data we collect, how we use it, who we share it with, and the choices you have.
1. Who we are
Vericoo operates a digital identity card platform that lets individuals and organisations create, manage, and share QR-coded identity cards. When we say "we", "us", or "our", we mean Vericoo and its operators. Questions? Email us at [email protected].
2. Data we collect
- Account information: your name, email address, and a hashed password. If you enable two-factor authentication (2FA), we also store a 2FA secret and hashed backup codes. We never store passwords, PINs, or backup codes in plain text.
- Card data: information you (or an issuing organisation) put on an identity card — which may include medical details (blood type, allergies, medications, conditions), emergency contacts, employment or membership details, vehicle details, insurance details (provider, policy/member numbers, coverage dates), and event/ticket details (event name, ticket or barcode number). You control what is stored and what is publicly visible.
- PIN-protected sections: some sections (e.g. insurance) can be locked behind a PIN you set. The PIN is stored hashed; unlocking issues a short-lived access token.
- Scan events: when your QR code is scanned we log the date and time, the scanner's IP address, an approximate location (country and city derived from that IP), and the browser/device user-agent. This powers your scan-history dashboard. Scans do not require the scanner to log in and we do not identify who scanned.
- Organisation data: if an organisation issues your card, it may pre-fill fields and can see the scan history for cards it issued. We keep organisation audit logs of administrative actions.
- Technical data: standard server logs (IP, browser type, pages accessed) for security and performance.
- Enquiries: if you contact us or submit an enquiry form, we keep what you send us.
3. How we use your data
We use your data to provide and improve the service: to render your card when its QR code is scanned; to send scan notifications (if enabled); to let you sign in and manage cards; to let your organisation manage cards it issued; to generate optional AI first-responder summaries (see §4); and to maintain security, prevent abuse, and debug issues.
We do not sell your data, use it for advertising, or use your card contents to train AI models.
4. AI-assisted features
Some features use a third-party AI provider to process card content:
- First-Responder Summary (optional): when enabled by your issuing organisation, we send the card's medical fields (name, date of birth, blood type, allergies, medications, conditions) and emergency-contact details to an AI provider to generate a short plain-language summary shown to anyone who scans the card.
- Translation: to show a card or its summary in another language, the relevant text may be sent to the AI provider for translation.
Our current AI provider is Anthropic (Claude); depending on configuration it may instead be OpenAI or Google (Gemini). These providers process the data only to return the requested result and, under their API terms, do not use it to train their models. AI-generated summaries are convenience aids and may be inaccurate — see our Terms of Service. Organisations can turn this feature off; doing so stops new AI processing.
5. Who can see your card data
- Public fields: anyone who scans your QR code sees the fields marked visible. No login is required to scan.
- Hidden / PIN-protected fields: fields marked hidden are never shown on a scan; PIN-protected sections are shown only after the correct PIN is entered.
- Organisation admins: if your card was issued by an organisation, its administrators can view the data for cards they issued.
- Platform administrators: Vericoo staff access data only for security incidents, legal obligations, or at your request.
6. Data storage and security
Data is stored in encrypted databases on reputable cloud infrastructure. Passwords are hashed with bcrypt (cost factor 12); PINs and 2FA backup codes are also hashed. Short-lived unlock and session tokens are held in an in-memory store (Redis) and expire automatically. No system is completely secure; we will notify you promptly of any breach affecting your personal data.
7. Data retention
We keep your account and card data while your account is active. Deleting a card removes it from public access immediately and hard-deletes it within 30 days. Deactivating your account retains data for 90 days for reactivation, after which personal data is permanently deleted except where the law requires otherwise. Scan logs are retained for up to 24 months.
8. Cookies
We use only the cookies necessary to run the service — a session cookie to keep you signed in and a CSRF token to protect form submissions. We do not use advertising cookies, tracking pixels, or third-party analytics.
9. Third-party sub-processors
We share data with these providers only as needed to run the service:
- Cloud database & hosting — stores your encrypted data.
- Azure Blob Storage — stores uploaded images (logos, sponsor logos, photos), served over HTTPS.
- Resend — delivers invitation, notification, and password-reset emails.
- AI provider (Anthropic / OpenAI / Google) — processes card content for summaries and translation (see §4).
- Redis — short-lived tokens, sessions, and cache.
Some of these providers may process data outside your country; we rely on their standard safeguards for such transfers.
10. Your rights
You may request access to, correction of, deletion of, or a machine-readable copy of your personal data, and you may object to specific processing. Email [email protected]; we respond within 30 days.
11. Children's privacy
Vericoo is not directed at children under 13, and we do not knowingly collect their data. Cards for children are created by an adult who is responsible for the accuracy and appropriateness of the data.
12. Changes to this policy
We may update this policy and will notify registered users of material changes by email at least 14 days before they take effect. The current version is always available at this URL.
13. Contact
Questions or requests: [email protected].
© 2026 Vericoo