Privacy Policy
Effective Date: July 29, 2026
1. Introduction
VectorGuard Labs ("we," "us," or "our") operates the Verified Credentials platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including the hosted API at vercre.vectorguardlabs.com and the open-source SDK.
By using the Service, you consent to the practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: When you onboard, we generate a DID and API key associated with your account.
- Contact Information: Email address provided during registration or correspondence.
- Payment Information: Billing details processed through Stripe. We do not store full credit card numbers on our servers.
- Support Communications: Messages you send to us via email or contact forms.
2.2 Information Collected Automatically
- Usage Data: API call logs, request timestamps, endpoints accessed, and response codes.
- Device Information: IP address, browser type, operating system (for web-based interactions).
- Performance Data: Latency metrics, error rates, and system health information.
2.3 Information We Do NOT Collect
- The content of credentials you issue (PII of your end users)
- Private keys (encrypted at rest; we cannot access plaintext key material)
- The identity of credential subjects unless you explicitly provide it
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and manage billing
- Monitor usage for rate limiting and plan enforcement
- Send service-related communications (outage notices, billing alerts)
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
4. On-Chain Data
When credentials are anchored on-chain (Base network), the following data becomes publicly and permanently visible:
- Credential hash (SHA-256 of the signed JWT)
- Issuer DID
- Timestamp of attestation
- Revocation status
Important: On-chain data is immutable and cannot be deleted. No personally identifiable information is stored on-chain — only cryptographic hashes and DIDs. You should not anchor credentials if you require the ability to fully erase attestation records.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
- Service Providers: Stripe for payment processing, cloud infrastructure providers for hosting.
- Legal Requirements: When required by law, subpoena, or government request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
- With Your Consent: When you explicitly authorize disclosure.
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest
- Private key encryption using Fernet (HKDF-SHA256 derived keys)
- Role-based access control with three-tier authentication
- Regular security monitoring and automated alerting
- Infrastructure-level protections (rate limiting, DDoS mitigation)
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your information as follows:
- Account data: Retained while your account is active, deleted 30 days after account termination.
- API logs: Retained for 90 days for operational purposes.
- Billing records: Retained for 7 years as required by tax and financial regulations.
- On-chain data: Permanently stored on the blockchain (cannot be deleted).
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal retention requirements)
- Object to or restrict certain processing activities
- Data portability (receive your data in a structured format)
- Withdraw consent at any time (where processing is based on consent)
To exercise these rights, contact us at pavon@vectorguardlabs.com. We will respond within 30 days.
Note: Data anchored on-chain cannot be deleted due to the immutable nature of blockchain technology. This is disclosed prior to any on-chain anchoring action.
9. Cookies and Tracking
The Verified Credentials API does not use cookies. Our website may use minimal analytics to understand traffic patterns. We do not use third-party advertising trackers.
10. International Data Transfers
Our servers are located in the United States. If you access the Service from outside the US, your information may be transferred to and processed in the United States. By using the Service, you consent to this transfer.
11. Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us:
- Email: pavon@vectorguardlabs.com
- Website: vectorguardlabs.com