Privacy Policy
Effective Date: January 1, 2026 · Last Updated: August 26, 2026
1. Overview & Data Philosophy
TokenVerifyAPI.com ("TokenVerify", "we", "us", or "our"), operated by Quite Good Project, provides sub-50ms deterministic B2B trust verification, EU/UK/US tax ID validation, disposable email detection, and phone risk APIs for autonomous AI agents and developer checkout rails.
We are committed to strict data minimization. Our engine queries open cryptographic algorithms (Modulo 11/97 & ISO 7064 checksums) and public DNS/MX infrastructure in real time. We do not broker, sell, or collect consumer personal data or private end-user messages.
2. Information We Collect
When you use TokenVerify services, we collect only the minimum data necessary to provide and secure our infrastructure:
- Account & Billing Information: Your email address and Stripe customer ID when you create an account or subscribe to a paid tier. Payment card details are processed directly by Stripe and never touch our servers.
- API Usage Telemetry: Request timestamps, API key hashes, verified lead domains, latency metrics, and monthly credit usage to enforce rate limits and billing quotas.
- Technical Logs: IP addresses and HTTP user agents accessing our public web endpoints for DDoS prevention and rate limiting.
3. How We Process B2B Verification Queries
When an API client or agent queries a verification endpoint (e.g. POST /v1/verify/b2b-lead), our engine executes deterministic checksum calculations and DNS MX queries.
- Zero Data Resale: Verification payloads (emails, phone numbers, tax IDs) are processed transiently in edge memory to compute risk verdicts and are never stored or sold to third-party data brokers.
- Caching: Validated tax registrations and MX domain classifications may be cached in edge memory for up to 30 days to optimize global latency.
4. Data Sharing & Sub-Processors
We do not sell, rent, or trade customer data. We share information only with essential infrastructure sub-processors:
- Stripe, Inc. — Subscription billing and payment processing.
- Cloudflare, Inc. — Global edge compute and DNS routing.
- Unkey.dev — API key generation and edge rate limiting.
5. GDPR, UK DPA & CCPA Rights
Under the UK General Data Protection Regulation (UK GDPR), EU GDPR, and California Consumer Privacy Act (CCPA), you have the right to access, rectify, or request the erasure of your personal account data at any time.
To exercise your data rights or request account deletion, contact us directly at privacy@tokenverifyapi.com.
6. Contact Information
TokenVerifyAPI.com is operated by Quite Good Project.
For privacy inquiries, security reports, or data protection questions:
Email: support@quitegoodproject.com
Website: https://quitegoodproject.com