What we collect
When you fill out a form on this site
We collect the fields you submit (name or brand, business email, ASIN, message). Form data is processed by our own web application — no third-party form processor — and stored in our contact system for as long as we're in an active business conversation. If we don't hear back and you don't hear from us within 12 months, we delete the record.
When we send you an outbound email
We collect: the business email address, the source URL where it was published, the date we found it, and the consent basis under which we're contacting you (typically CASL §10(9)(b), implied consent via conspicuous publication). We retain this record for as long as CASL requires (3 years post-last-contact) so we can prove consent basis if asked.
When you become an audit client
We collect: your listings, product pages, ad creative, and email flows — only what you send us or point us at. We store these for the length of the engagement plus 3 years for our own audit-defense records, then delete unless you request longer retention (e.g. for insurance purposes).
Website analytics
We use server-side request counts to know which pages get read. We do not use Google Analytics, Facebook Pixel, or any third-party JavaScript tracker on this site. No cookies are set for visitors browsing the site; a session cookie is used only where functionally required (e.g. form submission protection).
What we don't do
- We do not sell, rent, or share your data with third parties for their marketing purposes.
- We do not enrich your submitted information with data from third-party brokers.
- We do not run behavioral advertising against this site.
- We do not use your audit content to train AI models. Findings are generated with a fixed prompt against your specific copy; nothing you send is used for model improvement.
Third parties we use
- Anthropic — provider of the Claude API we use for rubric matching. Content submitted for audit is processed via their API; per Anthropic's business terms, API content is not used for model training. See their privacy policy.
- Railway — our website host. Standard access logs.
- Cloudflare — DNS and email routing for our domain. Mail sent to our addresses transits Cloudflare Email Routing.
- Our email provider — outbound email delivery for engagement correspondence and, where applicable, warm-outreach infrastructure.
Your rights
Under Canadian law (PIPEDA + CASL)
- Right to access what personal information we hold about you.
- Right to correction of inaccurate personal information.
- Right to withdraw consent to further contact — see unsubscribe.
- CASL: you can require us to stop sending commercial electronic messages within 10 business days.
Under EU law (GDPR), if you're in the EU
- Right of access, rectification, erasure, and restriction of processing.
- Right to data portability.
- Right to lodge a complaint with your supervisory authority.
- Legal basis for our processing: (a) legitimate interest for outbound contact of business email addresses conspicuously published for business purposes, and (b) contract for audit clients.
Under US state law (CCPA/CPRA for California residents, and similar)
- Right to know what personal information is collected and how it's used.
- Right to delete personal information we have collected from you.
- Right to opt out of “sale” or “sharing” of personal information — we don't do either.
To exercise any of these rights, email audit@claimsverified.org with “Privacy request” in the subject line. We respond within 30 days for most requests and within CASL's 10-business-day window for unsubscribes.
Contact for privacy matters
Claims Verified
Attention: Privacy Officer
1200 Bay Street, Suite 1201, Toronto, ON M5R 2A5, Canada
Email: audit@claimsverified.org
Changes to this policy
If we materially change how we collect or use personal information, we'll update this page and change the “effective” date at the top. Prior versions are retained on request.