Privacy · effective 2026-10-03

Privacy policy

Plain-English version: we collect only what we need to deliver the audit, to run this website, and to comply with Canadian, US, and where applicable EU privacy law. We don't sell data. We don't run third-party ad trackers on this site.

On this page
  1. What we collect
  2. What we don't do
  3. Third parties we use
  4. Your rights
  5. Contact for privacy matters
  6. Changes to this policy

What we collect

When you fill out a form on this site

We collect the fields you submit (name or brand, business email, ASIN, message). Form data is processed by our own web application, no third-party form processor, and stored in our contact system for as long as we're in an active business conversation. If no engagement follows and neither of us has written for 12 months, the request is deleted automatically.

When we send you an outbound email

We collect: the business email address, the source URL where it was published, the date we found it, and the consent basis under which we're contacting you (typically CASL §10(9)(b), implied consent via conspicuous publication). We keep this record for 3 years after the last contact, because under CASL the sender has to be able to prove the consent basis, and then delete it. An unsubscribe request is kept for as long as we send email, so we never write to you again.

When you become an audit client

We collect: your listings, product pages, ad creative, and email flows, only what you send us or point us at.

Who sees it. The licensed pharmacist who reviews and signs your file sees your client material: the copy, the files you upload and the draft findings. They are an independent contractor bound by a written confidentiality agreement, and they work on your material only inside our own systems. Nobody else outside Claims Verified sees it, apart from the service providers listed below.

How long we keep it. We keep every signed file and the working papers behind it (the copy as captured, the draft findings, the reviewer’s edits and the record of signing) for 15 years from the date the file is signed or declined. That is the longest period in which a claim about the work can be brought, and the reviewer may need the record to answer a question from their licensing body. Nothing is deleted before then unless the law requires it. The rest of your engagement material is kept for the length of the engagement plus 3 years.

Records of what was agreed and done

When you tick a terms box (on a request form, at checkout, or when you first set your dashboard password) we record the time, your IP address, your browser’s user-agent string, the version of the terms and of this policy, and a SHA-256 fingerprint of their exact text. We also keep a dated, tamper-evident log of payments, deliveries, signatures, the emails we send you and any deletion or privacy request. These records are kept for 15 years, like the signed file, because they are what either of us would rely on if something were disputed. They are kept even where a request that never became an engagement is deleted at 12 months; a deletion is logged against a fingerprint of the email address, not the address.

Website analytics

We count page views with a first-party beacon on our own domain. Nothing identifies you. We do not use Google Analytics, Facebook Pixel, or any third-party JavaScript tracker on this site. First-party cookies are set only where functionally required: CSRF protection on forms, the sign-in session for dashboard accounts, and a cookie that keeps the same version of the site design for a week. A form you have started may be kept in your own browser’s storage until you send it; it is not sent to us until you do.


What we don't do

  • We do not sell, rent, or share your data with third parties for their marketing purposes.
  • We do not enrich your submitted information with data from third-party brokers.
  • We do not run behavioral advertising against this site.
  • We do not use your audit content to train AI models. Findings are generated with a fixed prompt against your specific copy. Nothing you send is used for model improvement.

Third parties we use

  • Anthropic, provider of the Claude API we use for standards matching. Content submitted for audit is processed via their API. Per Anthropic's business terms, API content is not used for model training. See their privacy policy.
  • Stripe, payment processing. Card details go to Stripe and never reach us; we receive your name, email, the amount and what you bought. See Stripe’s privacy policy.
  • Railway, our website host. Standard access logs.
  • Cloudflare, DNS and email routing for our domain. Mail sent to our addresses transits Cloudflare Email Routing.
  • Our email provider, outbound email delivery for engagement correspondence and, where applicable, warm-outreach infrastructure.

Your rights

Under Canadian law (PIPEDA + CASL)

  • Right to access what personal information we hold about you.
  • Right to correction of inaccurate personal information.
  • Right to withdraw consent to further contact, see unsubscribe.
  • CASL: you can require us to stop sending commercial electronic messages within 10 business days.

Under EU law (GDPR), if you're in the EU

  • Right of access, rectification, erasure, and restriction of processing.
  • Right to data portability.
  • Right to lodge a complaint with your supervisory authority.
  • Legal basis for our processing: (a) legitimate interest for outbound contact of business email addresses conspicuously published for business purposes, and (b) contract for audit clients.

Under US state law (CCPA/CPRA for California residents, and similar)

  • Right to know what personal information is collected and how it's used.
  • Right to delete personal information we have collected from you. Signed files and their working papers are kept for 15 years (see above) and are deleted earlier only where the law requires it.
  • Right to opt out of “sale” or “sharing” of personal information, we don't do either.

To exercise any of these rights, email audit@claimsverified.org with “Privacy request” in the subject line. We respond within 30 days for most requests and within CASL's 10-business-day window for unsubscribes.


Contact for privacy matters

Claims Verified
Attention: Privacy Officer
1200 Bay Street, Suite 1201, Toronto, ON M5R 2A5, Canada
228 Park Ave S, New York, NY 10003, USA
Email: audit@claimsverified.org

Changes to this policy

If we materially change how we collect or use personal information, we'll update this page and change the “effective” date at the top. Prior versions are retained on request.