PRIVACY POLICY & CONSUMER HEALTH DATA NOTICE

Effective Date: June 29, 2026     

Last Updated: June 29, 2026

This Privacy Policy (the “Policy”) describes how Velvet Verify (“the App,” “we,” “us,” or “our”) collects, uses, discloses, and protects the information of individuals who use the Velvet Verify mobile application, website, and related services (“you” or “your”). It also serves as our Consumer Health Data Privacy Notice for residents of states that regulate consumer health data, including Washington and Nevada. This Policy should be read together with our End User Agreement. The App is intended only for adults aged eighteen (18) or older.

1. OUR APPROACH TO YOUR HEALTH INFORMATION

Velvet Verify is built around data minimization. Identifiable health information you submit (including uploaded documents and STI status information) is automatically deleted within twenty-four (24) hours of submission. After an automated review (which may use artificial intelligence) determines a document’s “Verified” or “Not Verified” status, the identifiable documentation is destroyed. We retain only limited deidentified metadata (such as a verification status flag, test category, and timestamp, from which direct and reasonably linkable identifiers have been removed) for the sole purpose of operating the App’s Sharing Window and Exposure Alert functions and maintaining the security and integrity of the App.

We are not a “Covered Entity” or “Business Associate” under HIPAA and do not receive protected health information from a Covered Entity. We do not sell your personal information or your consumer health data.

2. INFORMATION WE COLLECT

We collect only the categories of information needed to operate the App. Sensitive categories are noted in italics.

  • Account identifiers, such as name or chosen display name, email address or mobile number used for authentication, and an account identifier.
  • Demographic information you choose to provide.
  • Health information — STI status and uploaded testing documentation — which is processed for verification and then deleted within twenty-four (24) hours as described above. HSV-1 and HSV-2 are excluded from the App’s scope and are not processed, verified, or used for alerts.
  • Device and network activity, such as IP address, device identifiers, and app interaction logs, used for security and to operate the service.

We do not collect your Social Security number, bank account number, or payment card numbers through the App’s verification or matching features. If subscription billing is offered, payment is processed by a third-party payment processor and we do not store full payment card numbers.

3. HOW WE USE INFORMATION

We use the information we collect to:

  • perform the automated Verification Service and assign “Verified” / “Not Verified” status;
  • operate the Sharing Window and Exposure Alert functions at your direction;
  • authenticate your account and communicate service-related notices;
  • maintain the security, integrity, and proper functioning of the App;
  • comply with legal obligations and respond to lawful requests; and
  • perform analysis and product improvement using deidentified data only.

We will not use information for materially different, unrelated, or incompatible purposes without first providing notice and, where required, obtaining your consent.

4. CONSENT FOR CONSUMER HEALTH DATA

Where required by law (including the Washington My Health My Data Act and the Nevada consumer-health-data law), we obtain your separate, affirmative consent to collect your consumer health data, and a further separate consent to share it. Agreeing to use the App is not, by itself, consent to share your consumer health data with another User. Sharing occurs only when you separately authorize it through the App, and only while a Sharing Window is open. You may withdraw consent at any time, which may limit or end your ability to use the App’s sharing features.

5. HOW WE SHARE INFORMATION

We share information only as follows:

  • At your direction. Test Results are shared with another User only when you authorize that sharing, and only while the applicable Sharing Window is open.
  • Service providers. With vendors that process information on our behalf under contractual confidentiality and use restrictions (for example, hosting and security providers). Service providers may not use the information for their own purposes.
  • Legal and safety. To comply with law, valid legal process, or to protect rights, property, or safety.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to applicable law and consistent with this Policy.

We do not sell personal information or consumer health data, and we do not share consumer health data except as you direct or as expressly described above. We have not sold any personal information in the preceding twelve (12) months.

6. DATA RETENTION

We retain identifiable health information only for up to twenty-four (24) hours, after which it is automatically deleted. We retain deidentified metadata only as long as necessary to operate the Sharing Window and Exposure Alert functions and to maintain security. Account identifiers are retained for the life of your account and for a limited period afterward as required by law or to resolve disputes, after which they are deleted or deidentified.

7. DATA SECURITY

We implement reasonable administrative, technical, and physical safeguards designed to protect information, consistent with applicable law, including the New York SHIELD Act and applicable California requirements. However, no method of transmission or storage is one hundred percent (100%) secure, and we cannot guarantee absolute security.

8. YOUR PRIVACY RIGHTS

Depending on your state of residence, you may have some or all of the following rights, subject to legal exceptions: to confirm whether we process your information; to access it; to correct inaccuracies; to delete it; to obtain a portable copy; to opt out of sale, sharing, or targeted advertising (we do not sell or share for these purposes); to limit use of sensitive information; and to withdraw consent to processing of consumer health data.

To exercise these rights, submit a request to support@velvetverifyapp.com. We will verify your identity before responding. You may use an authorized agent where permitted by law. We will not discriminate against you for exercising your rights. If we decline a request, we will explain why, and where required (for example, under the Virginia VCDPA) you may appeal by contacting support@velvetverifyapp.com.

9. STATE-SPECIFIC DISCLOSURES

9.1  California (CCPA/CPRA)

California residents have the rights to know, delete, correct, and opt out of sale/sharing, and to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. The categories we collect and the purposes are described in Sections 2–5.

9.2  Virginia (VCDPA)

Virginia residents have the rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, sale, and certain profiling. Because STI status and related information are “sensitive data” under the VCDPA, we process such data only with your opt-in consent, and you may appeal a denied request as described in Section 8.

9.3  New York

We maintain reasonable safeguards consistent with the New York SHIELD Act. We make no representation that the App provides medical advice or diagnostic services; verification is an automated authentication process only. Nothing here waives non-waivable rights under New York General Business Law §349 or §350.

9.4  Washington (My Health My Data Act) and Nevada (SB 370)

This Policy serves as our Consumer Health Data Privacy Notice. We collect consumer health data only with your affirmative consent, share it only with your separate authorization, and do not sell it. You have the rights to confirm collection, sharing, and selling; to access your consumer health data; to withdraw consent; and to request deletion, including deletion by our service providers, as required by applicable law.

9.5  Other States

Residents of other states with comprehensive privacy or consumer-health-data laws may have similar rights and may exercise them as described in Section 8, to the extent required by applicable law.

10. CHILDREN

The App is intended only for adults aged eighteen (18) or older. We do not knowingly collect information from anyone under eighteen. 

11. UPDATES TO THIS POLICY

We may update this Policy from time to time. We will post the updated Policy with a revised “Last Updated” date and, where required by law, provide additional notice. Material changes affecting consumer health data will be made prospectively and, where required, with renewed consent.

12. CONTACT US

If you have questions about this Policy or your privacy rights, contact our Privacy Office:

Velvet Verify — Privacy Office

Velvet Verify Inc.

support@velvetverifyapp.com

44-70 21st Street, #3113

Long Island City, NY 11101