
Verify Before You Meet
Stay safer by confirming who you are meeting before the first encounter.
Privacy Policy / Política de Privacidad
Last updated: June 2026
Welcome to VeraID. We built this platform to help keep travelers safe in Colombia. We take your privacy seriously and want to be transparent about how we handle your data. This policy covers both our English-speaking visitors and our Spanish-speaking providers.
Bienvenido a VeraID. Esta política cubre tanto a visitantes de habla inglesa como a proveedores de habla hispana.
1. Who We Are / Quiénes Somos
VeraID is a voluntary identity verification and personal safety platform operating in Colombia. The data controller (responsable del tratamiento) is Foti Enterprise SAS, NIT 900884199, located in Medellín, Colombia.
Email: [email protected]
Website: veraid.org
We operate under applicable laws including Colombian Ley 1581 de 2012 (Personal Data Protection) and applicable United States privacy regulations for our US-based visitors.
2. Where This Policy Applies
This Privacy Policy applies to the VeraID mobile application and any related services we operate. It applies to all users regardless of location, with specific provisions for Colombian residents under Ley 1581 de 2012 and for California residents under the California Consumer Privacy Act (CCPA).
3. Data We Collect / Datos que Recopilamos
Data you give us:
For visitors we collect: full name, email address, WhatsApp phone number, passport number (optional), emergency contact name and phone number (optional), and a referral code if provided by a provider.
For service providers we collect: full legal name, cédula number, date of birth, WhatsApp phone number, face photo, cédula front and back photos, health certificate documents (optional), bank account details for commission payouts (optional), and biometric identity verification data (facial match and liveness) processed through our verification partner to confirm the person is real and matches their ID.
For all users we collect: safety reports you submit including descriptions and photos, and check-in records including timestamps and provider codes.
Data generated automatically:
When you use VeraID we keep basic technical and security logs, such as account login events, needed to operate and protect the service. We do not run advertising or analytics tracking, and we do not collect precise geolocation data.
4. How We Use Your Data / Cómo Usamos sus Datos
We use your data to operate the VeraID platform including verifying provider identities, enabling visitor check-ins, processing safety reports, sending WhatsApp notifications, managing subscriptions, and processing referral commissions.
We use your data to keep the platform safe including reviewing safety reports, investigating flagged providers, and suspending accounts that violate our terms.
We do not use your data for advertising. We do not sell your data to any third party under any circumstances. No usamos sus datos para publicidad. No vendemos sus datos a terceros bajo ninguna circunstancia.
5. Sensitive Data / Datos Sensibles
Some data we process is sensitive under Ley 1581: biometric data (facial match and liveness during identity verification) and health certificate documents. You are not obligated to provide sensitive data. Biometric identity verification is required to become a verified provider; health documents are entirely voluntary. We collect sensitive data only with your prior, express, and informed consent, captured at registration.
Algunos datos son sensibles conforme a la Ley 1581: datos biométricos (verificación facial y prueba de vida) y documentos de salud. Usted no está obligado a suministrar datos sensibles. La verificación biométrica es necesaria para ser un proveedor verificado; el documento de salud es voluntario. Solo los tratamos con su autorización previa, expresa e informada.
6. How We Share Your Data / Cómo Compartimos sus Datos
Provider face photos and first names are visible to verified visitors who look up their TRU code. No other personal data is shared publicly. Cédula numbers and documents are never shown to visitors.
We use the following service providers (encargados), who process your data solely to operate our platform and are bound by their own privacy and security obligations: Supabase (data storage, database, and hosting), Didit (identity and biometric verification), RevenueCat and Apple (subscription management and payment processing), and Ultramsg (WhatsApp notifications).
Some of these providers process data outside Colombia (for example, Didit in the European Union). By accepting this policy you authorize this international transfer, which is carried out under adequate security standards.
We may disclose your data to law enforcement or courts if required by Colombian law, US law, or a valid court order.
We will never share your cédula number, passport number, bank account details, health documents, or emergency contact information with any third party except as required by law or as needed to perform the verification described above.
7. Data Security / Seguridad de Datos
All data is stored securely using Supabase with encrypted databases. Photos and documents are kept in private storage and are accessible only through short-lived signed links to authorized roles. Sensitive operations run server-side only. We apply industry standard security measures to protect your personal information.
While we take security seriously, no system is completely secure. If you believe your account has been compromised please contact us immediately at [email protected]
8. WhatsApp Communications
By providing your WhatsApp number you consent to receiving safety notifications, account updates, and referral commission alerts from VeraID via WhatsApp. You may opt out at any time by contacting [email protected]
Al proporcionar su número de WhatsApp, acepta recibir notificaciones de seguridad, actualizaciones de cuenta y alertas de comisiones de VeraID por WhatsApp. Puede cancelar en cualquier momento contactando [email protected]
9. Health Information / Información de Salud
Health certificate documents submitted by providers are used solely to display a voluntary health verification badge on their profile. Documents are reviewed manually by VeraID staff and are never shared with any third party. Submission is entirely voluntary.
10. Your Rights / Sus Derechos
For all users: You have the right to access, correct, update, and request deletion of your personal data at any time. You can delete your account directly in the app or by contacting [email protected]
For Colombian residents (Ley 1581 de 2012): Usted tiene derecho a conocer, actualizar, rectificar y suprimir sus datos personales, solicitar prueba de la autorización otorgada, ser informado sobre su uso, y revocar la autorización. Para ejercer estos derechos contacte [email protected]. Atenderemos consultas en un máximo de diez (10) días hábiles y reclamos en un máximo de quince (15) días hábiles, conforme a la ley.
For California residents (CCPA): California residents have the right to know what personal data we collect, the right to delete personal data, and the right to opt out of the sale of personal data. VeraID does not sell personal data. To exercise your rights contact [email protected]
For all US residents: You have the right to access and delete your personal data. VeraID does not engage in targeted advertising or data sales. Contact [email protected] to exercise your rights.
11. Data Retention / Retención de Datos
We retain your data for as long as your account is active. When you delete your account your personal data is removed within 30 days. Check-in logs and safety reports are anonymized rather than deleted, as they serve as safety records.
For safety, when a provider is suspended or reported we permanently retain a one-way, irreversible hash of their cédula together with a history flag. This record contains no readable ID number, name, photo, or contact details. Its sole purpose is to protect visitors and prevent a person from escaping their safety history by deleting and re-registering.
We may retain certain data longer if required by Colombian or US law or if needed to resolve an ongoing safety investigation or legal matter.
12. Children / Menores de Edad
VeraID is not intended for users under 18 years of age. We do not knowingly collect data from minors. Age verification is required during registration. If you believe a minor has registered please contact us at [email protected]
13. Changes to This Policy / Cambios a esta Política
We may update this policy from time to time. We will notify registered users of significant changes via WhatsApp or email before they take effect. Continued use of the app after changes constitutes acceptance of the updated policy.
14. Contact / Contacto
For any privacy questions, data requests, or complaints:
Foti Enterprise SAS (VeraID)
NIT 900884199
Email: [email protected]
Website: veraid.org
Medellín, Colombia
For Colombian residents with unresolved complaints you may contact the Superintendencia de Industria y Comercio (SIC) at www.sic.gov.co
For California residents with unresolved complaints you may contact the California Privacy Protection Agency at cppa.ca.gov
VeraID · Foti Enterprise SAS · Medellín, Colombia · June 2026
