Legal

Privacy policy

This Privacy Policy explains how iVisited (“we”, “us”) processes personal data when you use http://91.99.219.18:3002 and related services. It should be read together with our Terms of Use and Cookie Policy.

Last updated 5 August 2026

1. Data controller

The controller of personal data processed through the Service is the operator of iVisited. Privacy requests: privacy@ivisited.com.

2. Data we collect

Depending on how you use the Service, we may process:

  • Account data, name, email, phone, password hash, country/city preferences
  • Order data, destination claimed, amount, status, limited card metadata (such as last four digits) where stored for records
  • Location check data: approximate coordinates and timestamps used to evaluate whether you are within a destination’s verification range
  • Certificate data: certificate number, public codes, destination details, and content shown on public verification or atlas pages
  • Technical data, IP address, device/browser type, pages viewed, and cookie identifiers as described in our Cookie Policy
  • Communications, messages you send to support or legal contacts

3. Why we process data

  • Provide accounts, verification, checkout, and certificates
  • Prevent fraud, abuse, and location spoofing
  • Operate public share pages you choose to distribute
  • Improve reliability, security, and product experience
  • Meet legal, tax, and accounting obligations
  • Measure site usage where you consent to analytics cookies

Legal bases may include contract performance, legitimate interests (security, product improvement), consent (non-essential cookies), and legal obligation.

4. Location information

Location checks request access through your browser or device. You can deny permission, but verification features will not complete without a location reading. We use location data to evaluate range eligibility for the requested destination and to protect the integrity of certificates.

We do not sell precise location streams to data brokers. Public certificate pages may show destination coordinates or place names associated with a verified visit.

5. Sharing

We may share data with:

  • Infrastructure and hosting providers
  • Payment processors needed to complete purchases
  • Analytics or messaging tools you consent to via cookies
  • Professional advisors or authorities where legally required

Public links you share (certificate or atlas URLs) are visible to anyone with the link.

6. Retention

Account and certificate records are kept while your account is active and for a reasonable period afterward for security, disputes, and legal retention. Location check logs may be kept for shorter periods sufficient to operate and secure verification. You may request deletion subject to legal holds.

7. Your rights

Depending on your region, you may have rights to access, rectify, delete, restrict, or port personal data, and to object to certain processing or withdraw consent. Contact privacy@ivisited.com. You may also lodge a complaint with your local supervisory authority.

8. International transfers

If we process data in countries other than your own, we use appropriate safeguards required by applicable law (such as standard contractual clauses where relevant).

9. Children

The Service is not directed to children under 16. If you believe we collected data from a child inappropriately, contact us and we will take appropriate steps.

10. Changes

We may update this Policy. The “Last updated” date will change when we do. Significant changes may also be highlighted in the product or by email where appropriate.