Privacy Policy
This Privacy Policy describes how Aether Technology LLC, a Wyoming limited liability company doing business as AddressVerify (“Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects your information when you use our website at addressverify.io, our API services, dashboards, and related tools (collectively, the “Service”). By using the Service, you consent to the practices described in this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
When you create an account, subscribe to a plan, or contact us, we may collect:
- •Account Information: First name, last name, email address, password (stored in hashed form), and company name
- •Billing Information: Payment method details are collected and processed by our third-party payment processor, Stripe. We store a Stripe customer identifier and payment method references but do not store full credit card numbers, bank account numbers, or other sensitive payment credentials on our servers
- •Communication Data: Information you provide when contacting our support team, including email correspondence and any attachments
- •Referral Information: If you participate in our referral program, we collect your referral code, the identity of users you refer, and commission-related data
1.2 Information Collected Through Use of the Service
When you interact with the Service, we automatically collect:
- •API Request Data: The addresses you submit for verification, request timestamps, response times, status codes, and the results returned
- •Usage Metrics: Number of API calls made, subscription usage counts, rate limit consumption, and bulk processing job details
- •Bulk Upload Data: CSV files you upload for batch processing, including the addresses contained within them, and the resulting output files
- •Technical Data: IP address, user-agent string, browser type, operating system, and referring URLs
- •Authentication Data: Login timestamps, session identifiers, and authentication method used (credential-based or Google OAuth)
1.3 Information from Third-Party Services
- •Google OAuth: If you choose to sign in with Google, we receive your name and email address from Google. We do not receive or store your Google password
- •Stripe: We receive transaction confirmations, invoice details, subscription status updates, and payment method metadata from Stripe via webhooks
1.4 Cookies and Similar Technologies
Our Service primarily operates as an API and does not rely heavily on cookies. However, our website and dashboard may use:
- •Essential Cookies: Required for authentication and session management
- •Analytics Cookies: To understand how users interact with our website and improve the Service
You can control cookie settings through your browser. Disabling essential cookies may impair your ability to use the Service.
2. How We Use Your Information
We use the information we collect for the following purposes:
- •Providing the Service: Processing your API requests, validating addresses, returning results, and managing your account
- •Billing and Payments: Processing subscriptions, generating invoices, tracking usage against plan limits, and managing payment methods through Stripe
- •Communication: Sending transactional emails (account verification, password resets, usage alerts, billing notifications, plan change confirmations), and responding to support requests
- •Referral Program: Tracking referral relationships, calculating commissions, and sending referral-related notifications
- •Security and Fraud Prevention: Detecting and preventing unauthorized access, abuse, and fraudulent activity; enforcing rate limits; and monitoring for suspicious behavior
- •Service Improvement: Analyzing usage patterns and performance metrics to improve reliability, accuracy, and features of the Service
- •Legal Compliance: Complying with applicable laws, regulations, legal processes, or governmental requests
We do not use your information for targeted advertising. We do not sell your personal information.
3. How We Share Your Information
We do not sell, rent, or trade your personal information. We may share your information in the following limited circumstances:
3.1 Service Providers
We share information with third-party service providers who assist us in operating the Service, subject to confidentiality obligations:
- •Payment Processing: Stripe processes all billing and payment transactions
- •Email Delivery: We use third-party email service providers to send transactional emails
- •Infrastructure: We use cloud hosting, database, and caching services. All data is encrypted in transit and at rest
- •Monitoring: We may use error tracking and logging services to monitor and improve the Service
3.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests.
3.3 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website of any such change.
3.4 With Your Consent
We may share your information for other purposes with your explicit consent.
4. Data Retention
We retain your information for as long as necessary to fulfill the purposes described in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account plus 30 days after deletion |
| API request logs | 90 days from the date of the request |
| Billing and invoice records | 7 years (for tax and legal compliance) |
| Bulk upload files and results | Automatically deleted within 48 hours of processing |
| Email verification tokens | Automatically deleted 1 hour after creation |
| Authentication sessions | Deleted upon logout or password reset |
| Cached address data | Expires within 24 hours to 7 days |
| Referral transaction records | Duration of account plus 7 years |
| Support communications | 2 years from last communication |
After the applicable retention period, data is permanently deleted or anonymized. You may request earlier deletion of your personal data as described in Section 7.
5. Data Security
We implement commercially reasonable technical and organizational measures to protect your information, including:
- •Encryption in Transit: All data is encrypted using industry-standard TLS/SSL protocols. API keys must be transmitted only over HTTPS
- •Encryption at Rest: Sensitive data stored in our databases is encrypted at rest
- •Password Security: Passwords are cryptographically hashed using bcrypt and are never stored in plaintext
- •Access Controls: Access to production systems is restricted to authorized personnel on a need-to-know basis
- •Infrastructure Security: Hosted with industry-leading cloud providers maintaining SOC 2, ISO 27001, and other certifications
- •Session Management: Authentication tokens are stored securely and invalidated upon logout or password reset
Despite these measures, no method of electronic transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your account credentials and API key.
6. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
6.1 Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the sources, the purpose for collecting, and the third parties with whom we share it.
6.2 Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions (such as data necessary to complete a transaction or comply with legal obligations).
6.3 Right to Correct
You have the right to request that we correct inaccurate personal information that we maintain about you.
6.4 Right to Opt-Out of Sale or Sharing
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
6.5 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
6.6 Exercising Your Rights
To exercise any of the rights described above, please contact us at [email protected]. We will verify your identity and respond within forty-five (45) days.
6.7 Authorized Agents
You may designate an authorized agent to submit requests on your behalf. We may require proof of authorization and identity verification.
6.8 Categories of Personal Information
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email address, IP address, API key | Yes |
| Commercial information | Subscription plan, transaction history, invoice records | Yes |
| Internet or network activity | API usage logs, browser type, referring URLs | Yes |
| Professional information | Company name | Yes |
| Geolocation data | General location derived from IP address | Yes |
7. Your Rights and Choices
Regardless of your location, you may:
- •Access Your Data: View your account information, API usage statistics, and billing history through your account dashboard
- •Update Your Data: Update your name, email, company name, and other profile information through your account settings
- •Delete Your Account: Request account deletion by contacting us at [email protected]
- •Revoke API Key: Regenerate your API key at any time through your account dashboard
- •Manage Email Preferences: Transactional emails cannot be opted out of while your account is active, as they are necessary for Service operation
- •Export Your Data: Request a copy of your personal data in a machine-readable format by contacting [email protected]
8. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].
9. Third-Party Links and Services
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access.
10. International Data Transfers
Our Service is operated from the United States. If you access the Service from outside the United States, you understand and consent to the transfer of your information to the United States, where data protection laws may differ from those in your jurisdiction.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on our website at least thirty (30) days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the changes.
12. Data Breach Notification
In the event of a data breach that compromises your personal information, we will notify affected users via email within seventy-two (72) hours of becoming aware of the breach, as required by applicable law.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Aether Technology LLC
Email: [email protected]
Security Concerns: [email protected]
Website: addressverify.io
For privacy-specific requests, including data access, correction, deletion, or CCPA inquiries, please email [email protected] with the subject line “Privacy Request.”