RapidVerify ("we", "us", "our") is an API-first verification platform used by businesses ("Customers") to confirm end-user eligibility for hero discounts, sweepstakes and driver underwriting. This policy explains what we collect, how we use it and the choices you have.
1. Who this applies to
This policy covers visitors to verify-heroes-pro.emergent.host, authenticated dashboard users and end users whose data is submitted through our APIs. If you are an end user (e.g. a veteran submitting a DD-214, or a sweepstakes entrant), the business that collected your data is the data controller; RapidVerify processes it on their behalf.
2. What we collect
- Account data — name, email, password hash, plan tier, Stripe customer ID.
- Verification records — the email address / document image submitted, the resulting verdict (verified / rejected / review), confidence score, latency, IP, timestamp and the API key used.
- Sweepstakes entries — name, email, date of birth, state, country, consent checkboxes and any eligibility-category proof provided.
- DriveScan MVR data — driver name, DOB, license class, violation and accident records extracted from uploaded Motor Vehicle Records. Winners on high-value prizes may also submit W-9 tax IDs (SSN / EIN), which we encrypt at rest with AES-GCM.
- Product analytics — pageviews, session recordings and click events via PostHog (aggregate; no free-text PII).
- Support — messages you submit through the contact form.
3. How we use it
- To deliver the verification, sweepstakes and DriveScan services you or your business requested.
- To surface usage, error and delivery diagnostics in the admin dashboard.
- To bill and reconcile subscriptions via Stripe.
- To send transactional email (winner notifications, contact-form receipts, affidavit reminders) via Resend.
- To run one-time AI extraction of MVR documents via Emergent-managed LLM providers (OpenAI, Google Gemini). Images are sent to the provider for the single scan and are not used to train models.
- To improve product reliability (error monitoring, aggregate analytics).
4. Retention & encryption
- Document images submitted for verification are read once by the AI extractor and are not persisted to our database — only the verdict + non-PII metadata is stored.
- W-9 tax IDs (SSN / EIN) are encrypted at rest with AES-GCM using an environment-scoped key. Only the sweepstakes-admin role can decrypt for the 1099 CSV export.
- Verification logs and sweepstakes entries are retained for as long as the Customer's account is active, or 7 years for records with tax implications, whichever is longer.
- Customers can delete their own records via the dashboard at any time.
6. Your rights (GDPR / CCPA)
If you are an end user in the EU, UK or California, you have the right to access, correct, delete, port and object to processing of your personal information. Because we process end-user data on behalf of our Customers, please submit requests to the business that collected your data. If they are unresponsive, email us at privacy@rapid-verify.com and we will route it appropriately.
7. Security
All traffic is served over TLS. Passwords are hashed with bcrypt. Tax IDs and other sensitive PII are encrypted at rest. Access to production data is limited to authorised RapidVerify personnel under a written confidentiality obligation. Suspected security issues can be reported to security@rapid-verify.com.
9. Children
RapidVerify is not directed at children under 13. Sweepstakes hosted by our Customers require entrants to be at least 18 (or the Customer's configured minimum age).
10. Changes to this policy
We'll post material changes on this page with an updated date. Continued use after a change constitutes acceptance.
11. Contact
Questions? Email privacy@rapid-verify.com.