veriastra_
Legal

Privacy Policy

Last updated August 19, 2026

This Privacy Policy explains how Veriastra, operated by White Cats Software, LLC("we", "us"), handles data when you use our website, free tools, and validation API (the "Service"). We built the Service to be privacy-conscious: we validate data, we do not sell personal data, and we retain the minimum we need.

1. Data we process

Lookup inputs. When you (or a free-tool visitor) submit an email address, phone number, IP address, or domain for validation, we process that value to run the requested checks (syntax, DNS/MX, SMTP, carrier, geolocation, blocklists, etc.). Emails, phone numbers, and IP addresses can be personal data under GDPR/CCPA.

Account & API data. API keys (stored hashed), credit usage, request counts, and — once accounts are available — the email you register with.

Technical logs. Standard request metadata (timestamps, error traces) for reliability and abuse prevention.

2. How we use it

  • To perform the validation or enrichment you request and return the result.
  • To meter usage and enforce plan limits and rate limits.
  • To maintain an aggregate reputation signal (e.g. how often a domain is disposable, or an IP is on a blocklist) that improves accuracy over time.
  • To detect and prevent abuse, fraud, and service disruption.

We do not sell personal data, and we do not use lookup inputs for advertising.

3. Retention

  • Result cache: short-lived per data type (email ~1 day, IP ~7 days, domain ~3 days, phone ~30 days).
  • Bulk job inputs & results: purged after ~30 days, unless the job carries a later retainUntil date.
  • Do-not-call records: kept for five years. 16 CFR 310.5 requires the entity-specific list and the suppressed-number evidence that long; deleting them early would destroy the record the rule exists to preserve.
  • IP reputation records: purged after ~180 days (IPs are reassigned).
  • Phone reputation ledger: raw E.164 plus counters; dropped after a year of inactivity, and removed immediately on a valid erasure request (see §8).
  • Aggregate domain reputation: retained as it reflects domain-level (not individual) behaviour.
  • Backups: seven daily snapshots of the live store. An erasure rewrites the live database; rotated copies fall off within seven days and are not rewritten in place.

4. Third parties

To perform lookups we query public infrastructure such as DNS resolvers, DNS blocklists (DNSBLs), mail servers (SMTP), and public numbering data (NPA-NXX/carrier). We use Cloudflare for DNS/TLS/CDN. We host on a dedicated server. We do not share your lookup inputs with these parties beyond what is technically required to answer the query.

The full list of parties that may process personal data on our behalf, including our payment and sign-in providers, is on the Subprocessors page. We do not sell or share personal data as those terms are defined under the CCPA/CPRA, and we do not use lookup inputs for advertising or to train models for third parties.

5. Cookies

We use a small number of strictly necessary cookies: a session cookie so you stay signed in, and security cookies set by Cloudflare to distinguish humans from automated traffic. These cannot be turned off without breaking sign-in. We do not run advertising or cross-site tracking cookies, and we do not embed third-party marketing pixels. Because of that there is no consent banner to click through: there is nothing non-essential to consent to.

We do count how often each public page is opened, so we can tell which of our guides and comparisons anyone actually reads. That count sets no cookie and stores no identifier, no IP address, no browser details and no referrer — one row per page per day with a number in it, and nothing in that table could be traced to a person, including by us. Query strings are discarded before the path is recorded.

6. International transfers

We operate from the United States and our infrastructure providers are largely US-based, so personal data may be transferred outside your country, including outside the EEA and UK. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum, together with the technical measures described on our Security page.

7. Security

All traffic is encrypted in transit (TLS). API keys are stored hashed (never in plaintext). The Service runs isolated from other applications on its own account with restricted permissions. No system is perfectly secure, but we apply defense-in-depth appropriate to the data we handle. Details, including what we do not claim, are on our Security page.

8. Your rights

Depending on your jurisdiction (e.g. GDPR/UK-GDPR, CCPA/CPRA), you may have rights to access, correct, delete, or export personal data, and to object to or restrict processing. To make a request, email [email protected].

We respond within 30 days and will tell you if we need longer. We may ask for enough information to confirm who you are, but no more than necessary, and we will not charge you unless a request is manifestly excessive. Exercising a right never costs you service or worse treatment.

What a phone erasure request does. Write to [email protected] with the number. We delete it from the phone reputation ledger, the result cache, dashboard lookup history, ordinary bulk-job rows, reverse-lookup audit entries keyed to that number, guest votes, and any idempotency or error row that still carries it. We do notdelete it from a customer's entity-specific do-not-call list, from suppressed-number evidence, or from a bulk job still inside its five-year retainUntil window. Those rows are a legal record, not a cache. We do not edit the FTC/FCC public complaint lists (they are not our copy of a lookup) and we do not rewrite rotated backups. You get a written account of what was erased, what was kept, and why.

If a customer looked you up.Where we processed your data on a customer's instructions, that customer is the controller. Write to us anyway: we will route the request to them, act on our own copy where we can, and tell you what happened. See our GDPR & Compliance page.

You also have the right to complain to your local supervisory authority (in the EEA or UK) if you believe we have handled your data unlawfully. We would appreciate the chance to fix it first.

9. Children

The Service is for business use and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect personal data from children; if you believe a child's data has reached us, contact us and we will delete it.

10. Data controller vs processor

When you submit third-party data (e.g. your customers' emails) through the API, you are the data controller and we act as a processor on your behalf; you are responsible for having a lawful basis to submit that data. For our own site and accounts, we are the controller.

11. Changes & contact

We may update this policy; material changes will be reflected in the "Last updated" date and, where we have your email, notified in advance. Questions: [email protected].Postal contact: White Cats Software, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.