Privacy policy.

How Verial collects, uses, and protects data for brands and their customers.

Last updated 17 August 2026

Who this applies to

Verial is a product registration and verification service for brands (“you”, when you run a Verial account, or “the brand”) and the people who scan or enter a Verial code to verify a product (“customers”). This policy covers both. Where a brand collects its customers' data through Verial, the brand is generally responsible for that data as the controller, and Verial acts as the processor running the underlying service.

Information we collect

Account and brand information. Name, email, and password (or sign-in credentials) for the person creating a Verial account, plus brand profile details like logo, colours, and business description.

Product and code data. Products, batches, and the unique codes generated for them, along with any custom attributes a brand attaches (batch, edition, size, and similar).

Customer registration data. When someone verifies and registers a product for the first time, we collect the name, email, and phone number they submit on the verification page.

Scan and verification logs. Timestamps, approximate location, and outcome (first verification, duplicate, or void) for each scan, used for analytics and duplicate-scan detection.

Usage and device data. Standard technical data such as IP address, browser type, and pages visited, collected automatically when you use the site or app.

How we use this information

To operate the verification and registration flow, generate and track codes, detect duplicate or suspicious scans, provide account and billing support, send service-related emails (including replies to the contact form), and improve the product. We do not use customer registration data for advertising, and we do not sell personal data to third parties.

Who we share it with

We use third-party infrastructure providers to run Verial, including database and hosting infrastructure, and email delivery for transactional messages and contact form submissions. If a brand connects a store integration (for example Shopify or WooCommerce), order and product data flows between that platform and Verial to power the integration. We share data with these providers only as needed to run the service, under their own security and confidentiality commitments, and never sell it.

Data retention

We keep account, product, and registration data for as long as a brand's account is active, and for a reasonable period afterwards to meet legal, accounting, or dispute-resolution obligations. A brand can request deletion of its account and associated data at any time by contacting us.

Your rights, and PDPA

Depending on where you're located, you may have rights to access, correct, or request deletion of your personal data. For users in Malaysia, we aim to handle personal data consistently with the Personal Data Protection Act 2010 (PDPA), including limiting what a scanner can see about a previous registrant (we show “already registered on [date]” rather than any personal details) and never displaying one customer's information to another. To exercise these rights, contact us at support@verial.io. If you're a customer of a brand using Verial and want your data corrected or removed, you can also reach out to that brand directly, since they control the registration.

Security

Every brand's data is isolated at the data layer, so one brand can never see or change another brand's products, codes, or customer registrations. We use industry-standard measures such as encryption in transit and access controls, but no system is completely secure, and we can't guarantee absolute protection against every possible breach.

Children's privacy

Verial isn't directed at children, and we don't knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, contact us and we'll remove it.

Changes to this policy

We may update this policy as Verial changes. If we make a material change, we'll update the date at the top of this page.

Contact us

Questions about this policy or your data can be sent to support@verial.io or via our contact page.