VERI5ME
PRIVACY NOTICE

Privacy Policy

Last updated: 11 July 2026. This notice explains how Veri5me handles candidate, business, payment, provider, and platform-security data across web, API, and mobile workflows.

Information We Handle

Account and organisation dataName, email, role, organisation profile, ABN/ACN, billing contact, access permissions, MFA state, and audit metadata.
Verification request dataPurpose, template, selected checks, consent status, ETA, workflow state, invite history, candidate actions, and report metadata.
Candidate evidenceIdentity, address, work-rights, qualification, employment, referee, property, tenancy, or other evidence requested by a selected workflow.
Provider and decision dataProvider job status, source references, result summaries, agent notes, QA outcomes, adverse-result review notes, and confidence metadata.
Payment and billing dataQuote snapshots, Stripe customer/session/payment IDs, GST, provider costs, invoices, refunds, credits, disputes, and billing audit events.
Security and operations dataSession records, device/IP/user-agent metadata, notification delivery logs, webhook events, incident records, and retention/legal-hold records.

Purpose-Limited Collection

Veri5me collects personal information only where it is reasonably needed to create an account, request or complete a verification workflow, process payment, issue reports, support candidate rights, secure the platform, or meet legal and operational obligations.

Business customers must choose checks that are relevant to the stated role, engagement, tenancy, property, or compliance purpose. Candidates can see the purpose and requested categories before providing consent.

Consent, Access, Correction, Dispute, And Withdrawal

Candidates can request access to their records, correction of inaccurate information, dispute review of an outcome, or withdrawal of consent from the portal or mobile app.

Some requests may pause report release, apply a compliance hold, or limit deletion while Veri5me investigates, preserves evidence, or meets legal, audit, provider, or regulatory obligations.

Australian Storage And Processing

Sensitive verification documents and records are designed to be stored in Australian-region Firestore and Cloud Storage resources before production candidate document handling.

Operational controls include private object storage, signed download URLs, direct-write blocking for sensitive collections, retention policies, audit events, and legal holds.

Overseas Processors And Providers

Stripe, Resend, monitoring tools, cloud infrastructure services, and selected verification providers may process limited operational or payment data outside Australia.

Outbound emails and push notifications are designed to be notification-only. Veri5me does not attach raw verification evidence or sensitive report results to transactional messages.

Retention, Deletion, And De-Identification

Raw evidence, reports, audit events, billing records, and candidate profile data are governed by retention policies based on data type, workflow state, legal hold status, dispute status, and operational need.

Deletion sweeps are audit logged. Legal holds, open disputes, provider obligations, tax/accounting records, fraud prevention, or regulatory requirements may extend retention.

Security, Breaches, And Audit

Veri5me uses role-based access, privileged MFA challenges, server-side workflow enforcement, private storage, signed URLs, webhook signature verification, redacted logs, and audit trails for sensitive actions.

Suspected privacy or security incidents are triaged through the incident register. Where a notifiable data breach threshold is met, the response workflow supports affected-user and regulator notification preparation.

Marketing Consent

Transactional messages for security, consent, evidence, workflow, referee, billing, and report milestones are separate from marketing messages and may be required to deliver the service.

Marketing is optional and preference-based. Opting out of marketing does not disable required transactional or security notifications.

Candidate Requests

Candidates can submit access, correction, dispute, or withdrawal requests from My Checks. Verified support requests may also be directed to privacy@veri5me.com.au.

Production Approval

Police, official identity, tenancy, property/title, and other regulated workflows require approved provider access, privacy impact review, security review, and final Australian legal approval.