VeriViaje
Counsel-ready pilot draft

Comprehensive Privacy Notice

Version 2026-06-23-pilot-v3. This draft is operationally complete but requires fixed-fee Mexican counsel review before a paid launch.

Controller

VeriViaje Protection, located at the address provided before launch, is responsible for the processing described in this notice. Privacy and ARCO requests may be submitted to our privacy request form.

People and information covered

This notice covers prospective and invited customers, vendor representatives, references, account users, and people who contact VeriViaje.

  • Identity and contact information: name, email, optional phone, country, account and verification status.
  • Event and vendor information: destination, dates, service category, vendor names, websites, representatives, quotes, deadlines, and stated concerns.
  • Case evidence: contracts, invoices, payment instructions, communications, references, public profiles, and information contained in those materials.
  • Service records: messages, reports, decisions, complaints, support contacts, and consent evidence.
  • Security information: hashed network identifiers, bounded device labels, sessions, access logs, malware results, integrity hashes, and incident records.

The verification-only pilot does not request government IDs, CURP, RFC, facial biometrics, handwritten signatures, full payment-card details, or supplier onboarding documents. Do not upload them unless VeriViaje later provides a separately reviewed collection process.

Primary purposes

  • Evaluate pilot requests and create invited accounts.
  • Review vendor identity consistency, business presence, contracts, invoices, requested payment details, references, public information, and risk signals.
  • Communicate about missing evidence, case progress, reports, support, complaints, and privacy requests.
  • Authenticate users, prevent abuse, scan uploads, investigate security events, maintain audit trails, and protect people and the service.
  • Comply with legal duties, establish or defend claims, and respond to competent authorities.

VeriViaje does not use pilot evidence for unrelated advertising, sell personal data, or enable third-party behavioral advertising. A new purpose incompatible with this notice will require a revised notice and, where required, new consent.

Secondary purposes and product research

Where permitted, VeriViaje may use account, inquiry, case-workflow, support, outcome, and service-usage information to measure demand, improve verification methods, train personnel, detect recurring risk patterns, develop new trust and safety features, prepare aggregate business metrics, and contact prospective or former users about VeriViaje services. Refusing or opposing these secondary purposes does not prevent delivery of the primary verification service.

You may oppose or limit these secondary uses at any time through the privacy request form. VeriViaje may retain and use information that has been aggregated or de-identified so it no longer reasonably identifies a person, including for research, statistics, service improvement, and fraud-prevention pattern analysis, and will not attempt to re-identify it.

Vendor and third-party information

Customers must share only information reasonably necessary for verification and which they are authorized to provide. VeriViaje may also consult lawful public sources. When information was not obtained directly from the person concerned, VeriViaje will handle notice and rights requests according to applicable law and will not treat unlawfully sourced material as public information.

Processors and international handling

VeriViaje uses service providers acting under instructions to host and protect the pilot: Render for application and PostgreSQL hosting, Cloudflare R2 for private object storage, and Resend for transactional email. These providers may process information outside Mexico. ClamAV scans uploads inside the application container. Professional legal, accounting, security, or technical advisers may receive limited information when necessary and subject to confidentiality.

Information may be transferred to another independent recipient only when permitted by law, authorized where required, necessary to establish or defend a claim, or requested by a competent authority. VeriViaje does not send customer evidence to vendors or references without a case-specific operating decision and appropriate notice.

Security and confidentiality

Controls include invitation-only production access, role restrictions, administrator MFA, private storage, encrypted local development storage, authenticated downloads, malware and file-signature checks, integrity hashes, session controls, audit logging, incident records, backups, and retention reviews. No system eliminates every risk.

Retention

  • Unconverted pilot, contact, and vendor inquiries: retained for up to 12 months for follow-up, demand analysis, duplicate prevention, and service improvement, then deleted or de-identified unless a lawful reason requires more time.
  • Closed-case evidence and operational case content: retained for up to five years after case closure when reasonably needed for report accountability, complaints, disputes, fraud prevention, or the establishment or defense of claims.
  • Security credentials and temporary verification records: generally 7 to 90 days after expiry or use, according to record type.
  • Account, consent, report, complaint, support, audit, security, and legal records: generally retained for up to five years after the relevant relationship or matter ends, or longer where a specific legal duty or limitation period applies.
  • Backups are overwritten through controlled rotation cycles. Aggregated or de-identified statistics that no longer reasonably identify a person may be retained indefinitely.

Retention periods are maximum operating periods, not a promise to keep every record for their full duration. VeriViaje may delete information earlier when it is no longer necessary. A documented legal hold may temporarily suspend deletion where information is needed for a complaint, dispute, investigation, security incident, or legal obligation.

Your choices and ARCO rights

You may request access, rectification, cancellation, opposition, limitation of use, or revocation of consent through the privacy request form or at the monitored privacy email. We will verify identity before disclosing or changing information. The pilot workflow targets a decision within 20 days of receiving the request and, when approved, execution within the following 15 days, subject to applicable lawful exceptions.

A request should include your name, contact email, relationship to VeriViaje, the right being exercised, enough detail to locate the information, and supporting information for corrections. We will request only the identity evidence reasonably necessary for the request.

Security incidents

If a security breach significantly affects a person's property or moral rights, VeriViaje will investigate, contain, document, and notify affected people without undue delay so they can protect themselves, as required by applicable law.

Changes

Material changes will be identified by a new version and publication date. Where a change creates a new purpose requiring consent, VeriViaje will request it before that processing begins.

Privacy Notice Terms of Use

VeriViaje Protection