Legal
Privacy Policy
Effective August 25, 2026
What we collect
Verqaro collects the information needed to provide property due-diligence reports: your name, email address, and profile image when you sign in; property addresses and parcel details you submit; report history; purchase and transaction references; and basic security and diagnostic data such as session, device, and request information.
Google sign-in
If you choose Google sign-in, we use only the basic identity information Google shares for authentication, such as your name, email address, profile image, and account identifier. We use it to create and secure your Verqaro account. We do not use Google user data for advertising or sell it to third parties.
How we use information
- Create, deliver, and store the reports you request.
- Authenticate your account and prevent fraud or abuse.
- Process purchases, issue credits, and maintain transaction records.
- Operate, secure, troubleshoot, and improve Verqaro.
- Meet legal, tax, accounting, and compliance obligations.
Service providers and public records
We use service providers that help run Verqaro, including Cloudflare for hosting, security, and data storage; Google for optional sign-in; and Paddle for payment processing. Property reports may combine information from public agencies and other identified data sources. These providers process information under their own terms and privacy commitments. We do not sell personal information.
When you use address suggestions, partial street-address text is sent to Smarty to return matching U.S. addresses. We retain only the address you select for your requested property dossier. Smarty suggestions do not establish parcel identity or property evidence; Verqaro verifies supported coverage through the official-source process described in Methodology.
Raw evidence retention
Production processing is limited to report requests that pass the live coverage and release gates. Verqaro may retain the exact bytes of successful source responses as restricted raw evidence for audit and dispute resolution. This raw evidence can include the property coordinates or parcel identifiers sent with a source request as request provenance. Raw evidence is available only to Verqaro operators, is not provided through a customer or public route, and is scheduled for deletion after 90 days. The live R2 lifecycle rule is externally verified before production processing is enabled. Account closure cannot safely identify individual raw-evidence objects, so it does not delete them by broad bucket scan.
Retention and security
Source evidence journal entries are deleted after 400 days by scheduled maintenance. The journal stores an opaque report identifier, source endpoint without request parameters, outcome, counts, fingerprints, and timestamps; after account closure, its report row contains no submitted address, parcel identifier, or report payload.
Pseudonymous Paddle customer and transaction references, credit and reservation history, signed billing events received after closure, opaque account and report identifiers, the closure timestamp, and the 400-day journal may remain for payment reconciliation, disputes, abuse prevention, and operational audit. A valid signed Paddle event received after closure is recorded as billing audit only and cannot create a credit, transaction entitlement, or active subscription for the closed account. Paddle and other service providers may also retain records under their own legal obligations and privacy terms. Retained billing and closure audit records currently have no automated deletion schedule; contact privacy@verqaro.com for a case-specific retention request.
We use access controls, encrypted connections, restricted secrets, and other reasonable safeguards, but no online system can guarantee absolute security.
Your choices
A signed-in user can use the Close account control or DELETE /api/account/delete by entering CLOSE MY ACCOUNT. You must cancel an active subscription, finish any pending Paddle checkout or wait until it has been unchanged for 24 hours, and wait for report processing or credit settlement to finish before closure.
Closure revokes sessions and linked sign-in accounts, replaces the name and email with an unreachable tombstone, removes submitted address, city, state, postal code, parcel identifier, and report payload, and revokes unused report credits. An unsettled checkout blocks closure for 24 hours after its latest local update. At exactly 24 hours it expires locally and is removed only as part of closure; a later signed Paddle completion is retained as audit only and cannot create an entitlement for the closed account. Local expiry does not cancel a provider-side transaction; contact support@verqaro.com if Paddle completes it after closure. Cached report PDFs are deleted only under each closed report’s exact private prefix; the durable per-report purge record remains after success, and hourly maintenance repeatedly rechecks closed report prefixes, including previously successful purges and failed or late cache writes. Signing in later with the same email creates a separate account and does not restore closed-account data or credits.
For access, correction, or help with closure, email privacy@verqaro.com from the email address on your account. You can also stop using Google sign-in and revoke Verqaro access from your Google account settings.
Children and changes
Verqaro is not directed to children under 13. We may update this policy as the service changes and will post the current version here with a revised effective date.
Contact
Privacy questions or data requests: privacy@verqaro.com.