VERIFAB
Why nowHow it worksWhy VerifabPricing
Sign inStart free

⚠️ DRAFT for legal review. This document was assembled by engineering from an audit of what the Verifab application actually processes and stores. It is not legal advice and must be reviewed, completed, and approved by a qualified data-protection lawyer before it is published. Every [PLACEHOLDER] must be filled in, and the subprocessor list, retention periods, transfer mechanisms, and legal bases must be verified against the live infrastructure and your jurisdiction.

Privacy Policy

1. Who we are

Verifab ("Verifab", "we", "us") provides a software platform that helps fashion and apparel brands create, host, and manage Digital Product Passports (DPPs) in line with the EU Ecodesign for Sustainable Products Regulation (ESPR).

  • Legal entity: [REGISTERED COMPANY NAME]
  • Registered address: [ADDRESS]
  • Company number: [NUMBER]
  • Data protection contact: [privacy@verifab.io / DPO CONTACT]

This policy explains what personal data we process, why, and the rights you have.

2. Our two roles: controller and processor

Verifab processes personal data in two distinct capacities, and different parts of this policy apply depending on the data:

  • As a controller — for personal data about our own customers: the individuals who create and administer a Verifab account on behalf of a brand (e.g. account name, work email, login credentials, billing contact). We decide how and why this data is processed.
  • As a processor, on behalf of a brand (our customer, who is the controller) — for personal data that a brand chooses to put into the platform to build its passports or collect supply-chain information, for example supplier contact details collected through Verifab's supplier-request workflows. Here the brand determines the purposes; we act on the brand's documented instructions under our customer terms / data processing terms. Supplier and other third-party data subjects should direct requests to the relevant brand; we will assist that brand as its processor.

3. Personal data we process

We keep this deliberately narrow. As controller, we process:

Category Examples Source
Account & identity data Name, work email, hashed login credentials, authentication session You, at signup/login (stored in our database via Supabase)
Billing & subscription data Plan, billing status, subscription identifiers Generated when you subscribe; card details are handled by Stripe, not by us
Brand / product content you enter Brand profile, product and passport data, material/traceability fields Entered by you into the platform
Technical & diagnostic data Error reports, stack traces, technical context for reliability Captured automatically via Sentry (with personal-identifier collection disabled — see §6)
Analytics data Aggregate, non-identifying page/visit counts Collected via cookieless analytics (Plausible) — no personal data, no cross-site tracking

As processor on behalf of a brand, we may store supplier/third-party contact data (e.g. a supplier's name and email) that the brand collects through the platform. We process this only to provide the service to that brand.

We do not intentionally collect special-category data, and the platform is not intended for children.

4. Why we process it, and our legal bases (UK/EU GDPR)

Purpose Legal basis
Create and operate your account; provide the platform Contract (Art. 6(1)(b))
Take payment and manage subscriptions (via Stripe) Contract; legal obligation for tax/accounting records
Keep the service secure, reliable, and debug errors (Sentry) Legitimate interests (Art. 6(1)(f)) — running a secure, working service
Understand aggregate usage to improve the product (Plausible, cookieless) Legitimate interests — statistical measurement without identifying you
Retain passport/DPP records where regulation requires Legal obligation and/or the brand's compliance need under ESPR
Send service, transactional, and lifecycle emails (via Resend) Contract; any lifecycle/marketing sends rely on consent or legitimate interests with an opt-out — [LEGAL TO CONFIRM]

Where we rely on legitimate interests, you can object (see §9).

5. Cookies and similar technologies

Verifab sets only strictly-necessary cookies (authentication session and an onboarding-state cookie) and uses cookieless analytics. Because we set no non-essential cookies, no consent banner is required. Full detail — including how to object to analytics — is in our Cookie Notice.

6. Third parties and subprocessors

We share personal data only with the service providers needed to run the platform, each under a data processing agreement. [LEGAL/ENGINEERING TO CONFIRM each provider's processing location, DPA, and transfer safeguards before publication.]

Subprocessor Purpose Personal data involved
Supabase Application database & authentication Account data, content you enter, session
Vercel Application hosting / delivery Technical request data (e.g. IP at the edge)
Stripe Payment processing (hosted checkout) Billing contact, payment data (held by Stripe)
Sentry Error monitoring & reliability Diagnostic/technical data — sendDefaultPii disabled, so IP/user identifiers are not sent by default
Plausible Cookieless, privacy-friendly analytics No personal data (no cookies, no cross-site identifiers)
Resend Transactional, service & lifecycle email delivery Recipient email, message content
Backblaze B2 Object/file storage (e.g. passport assets, backups) Files and their contents as uploaded
n8n (hosted on Railway) Workflow automation, incl. supplier-data collection Supplier contact data processed on a brand's behalf

Note on Stripe: payment card details are entered on Stripe's hosted checkout and are processed by Stripe as a controller/processor in its own right; we do not receive or store full card data.

7. International transfers

Some subprocessors may process data outside the UK/EEA. Where they do, transfers are protected by an appropriate safeguard (e.g. UK IDTA / EU Standard Contractual Clauses or an adequacy decision). [LEGAL TO CONFIRM the actual transfer mechanism per subprocessor.]

8. Retention

  • Account data: kept for the life of your account and then deleted or anonymised within [PERIOD], subject to legal-hold exceptions below.
  • Billing records: retained as required by tax/accounting law (typically [6–7 YEARS — CONFIRM]).
  • Passport / DPP records: the platform enforces retention (records are soft-deleted, not hard-deleted) to meet DPP data-availability obligations under ESPR — including keeping passport data available for the period the regulation requires even after an account closes. Specific ESPR retention periods must be confirmed by legal against the final regulation and any delegated acts. [CONFIRM exact period.]
  • Diagnostic data (Sentry): retained per the provider's default window [CONFIRM].

9. Your rights

Subject to UK/EU GDPR, you may request to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing (including processing based on legitimate interests, and any direct marketing); and port your data. You may also withdraw consent where we rely on it, and lodge a complaint with a supervisory authority (in the UK, the ICO).

Some rights are limited where we must retain records to meet a legal obligation (e.g. ESPR passport retention, tax records) — we will explain this if it applies to your request.

To exercise any right, contact [privacy@verifab.io]. For supplier/third-party data a brand collected through Verifab, contact the relevant brand (the controller); we will support them as processor.

10. Security

We use industry-standard measures including encryption in transit, access controls, row-level security in the database, and the principle of least privilege. No system is perfectly secure; we work to protect your data and will notify you and regulators of a qualifying breach as required.

11. Changes to this policy

We may update this policy; we will change the "last updated" date and, for material changes, notify account holders.

12. Contact

[REGISTERED COMPANY NAME] — [privacy@verifab.io] — [ADDRESS].

VERIFAB

Digital Product Passports for fashion brands.

PRODUCT

How it worksWhy VerifabPricing

COMPANY

AboutESPR guideContact

LEGAL

PrivacyCookiesTerms

© 2026 Verifab Ltd. All rights reserved.

Verifab tracks ESPR and its delegated acts. This site is not legal advice.