Last updated August 25, 2026
IntroVerify is operated by IntroVerify, LLC ("IntroVerify," "we," "us"), a Nevada limited liability company. For the personal information described in this policy, IntroVerify, LLC is the data controller, except where Section 4 says we act on an artist's instructions. You can make a privacy request through our privacy request form, or reach us about anything in this policy at privacy-noticesintroverify.com.
IntroVerify helps artists confirm details about potential buyers before starting a commission. That means we handle information about two groups of people:
When you create and use an artist account we collect your email address, the display name you choose, the page address we assign you, your timezone, your plan and billing status, messages you send our support team, and the IP address and approximate country of the connection you sign up from. If you connect a payout account or pair an API client or the browser extension, we hold the identifiers needed to keep those working.
When you complete a verification we ask for your name, your general location, and your email address. If a check escalates, we ask for a mobile phone number so we can send a one-time code by SMS. We never ask buyers for passwords or government ID.
While a verification is in progress we collect signals about the connection and device being used, because those signals are how the check works:
When generating a code, an artist may enter a freeform label to remember who the code was for, for example a social handle, an email address, or a note like "guy from the convention." This is personal information about the buyer that the buyer did not provide to us and may not know we hold. Artists may also mark how a commission turned out. We treat labels and outcome marks as confidential: they are visible only to the artist who created them, we process them only on that artist's instructions, and we never use them for anything beyond helping the artist identify and manage their own sessions. For this information the artist is responsible for what they record. If you send us a request concerning a label (Section 11), we pass it to the artist and assist them in responding.
Card details, for artist subscriptions and for buyer good-faith payments, are entered directly with Stripe, our payment processor. Card numbers never reach our servers. From Stripe we receive the outcome of a charge, the country a card was issued in, and dispute status, and we keep a record of the consent a buyer gave before paying.
We use the information above solely to run the service. Where the GDPR or UK GDPR applies, the legal basis for each purpose is noted.
We do not use personal information for advertising, we do not sell it, and we do not share it for targeted advertising, with or without a Global Privacy Control signal.
Verification signals are scored automatically, and the score determines whether a check asks for more proof: an escalated phone step, or a good-faith payment. The verdict shown to the artist is produced the same way. The decision that matters, whether to take the commission, is always made by the artist, a human being, and a verdict never blocks a buyer from anything on its own. If you believe a check reached a wrong result, you can contest it and ask for human review through our support page, and where your local law grants rights around automated decision-making, this is how you exercise them with us.
The artist who requested a check sees the verdict and a short plain-language summary of what was checked, which steps the check asked for and whether the buyer completed each one, the country the buyer said they were in, the approximate country the check resolved, the buyer's email address once verified, and the status of any good-faith payment. We do not disclose to artists: the buyer's name, phone numbers, IP addresses, device signatures, or the internal scoring detail behind a verdict.
We share personal information only with the providers below, each bound by a data processing agreement:
Each provider above processes information on our behalf and only for the purpose we set, with one addition. The IP address reputation and geolocation provider also uses the addresses we send it to maintain and improve its own fraud-detection data, acting as its own controller for that use. We receive nothing from it beyond the result of our check.
Beyond that, we disclose personal information only when required by law or legal process, to protect the rights, safety, or property of IntroVerify, our artists, or buyers, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to the transferred information.
We are based in the United States and store and process information there. If you are in the EEA, the UK, Switzerland, Canada, Australia, or New Zealand, your information is transferred to the United States. For transfers from the EEA and UK we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or on a provider's certification under the EU-U.S. Data Privacy Framework and its UK Extension. For transfers from Switzerland we rely on the Standard Contractual Clauses as amended for Swiss law, or on a provider's certification under the Swiss-U.S. Data Privacy Framework. Which mechanism applies depends on the provider, each of which is listed in Section 7.
We keep information longer only where a specific law, dispute, or legal hold requires it.
All traffic is encrypted in transit, including between our own systems, and the databases behind the service are encrypted at rest. One-time codes are stored hashed. Identifiers used for cross-service abuse detection are stored as hashes keyed with a secret. Card data is handled entirely by Stripe. Access to production systems is restricted to those who need it to operate the service. No system is perfectly secure, and if a breach affects your personal information we will notify you and the relevant authorities as the law requires.
Wherever you are, you can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, through our privacy request form, or by emailing privacy-noticesintroverify.com. For a label an artist recorded (Section 3.4), the artist is responsible for that information: we pass your request to them and assist them in responding. The form confirms your request by sending a one-time code to the email address or phone number it concerns; that confirmation, or an equivalent check for emailed requests, is how we verify a request comes from the person it concerns or from an authorized agent. We respond within the time your local law sets (30 to 45 days in most places, extendable where the law allows). We never charge for a first request and never treat anyone differently for making one. Some information is exempt from deletion while we are legally required to keep it or while it is genuinely needed to prevent fraud; if we rely on an exemption we will say so.
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, including the right to object to processing based on legitimate interests, and the right to withdraw consent at any time where consent is the basis. You may lodge a complaint with your supervisory authority: in Ireland, the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk); or the authority where you live. We have no establishment in the EEA or the UK, so we have appointed a representative you can contact instead of us if you prefer. Section 16 has the details.
Where a state privacy law (such as the California Consumer Privacy Act as amended, or the laws of Colorado, Connecticut, Virginia, Texas, and other states) applies to us, you have the rights to know, access, correct, and delete personal information, and to receive a portable copy. The categories we collect are described in Section 3: identifiers, commercial information, internet and device activity, coarse geolocation, and inferences used solely for fraud prevention. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, so there is nothing to opt out of on those grounds. If we decline a request, you may appeal by replying to our response, and we will answer the appeal within the time your state's law sets. Residents of Puerto Rico, Guam, and the U.S. Virgin Islands have the same rights described in this section.
We handle personal information consistently with PIPEDA. You may access and correct your information and withdraw consent (which may end our ability to run a verification). Your information is stored in the United States as described in Section 8. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
You may access and correct your information under the Australian Privacy Act 1988 or the New Zealand Privacy Act 2020. Your information is disclosed overseas to the United States as described in Section 8. Complaints go first to us at the address above; if unresolved, to the Office of the Australian Information Commissioner (oaic.gov.au) or the Office of the New Zealand Privacy Commissioner (privacy.org.nz).
Under the Federal Act on Data Protection you have the rights of access, rectification, erasure, objection, and data portability, and the right to withdraw consent at any time where consent is the basis. Your information is transferred to the United States as described in Section 8. We have no establishment in Switzerland, so we have appointed a representative you can contact instead of us; Section 16 has the details. You may also complain to the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
We use only cookies the service needs to function, all of them our own: a cookie that keeps an artist signed in, a cookie that carries a pass showing you entered a valid invitation code while the site is invitation-only, and, if you arrive through a promotional link, a cookie that remembers that offer until it expires so the price you were shown is the price you are charged. None is readable by scripts in your browser. Your light-or-dark theme choice and which sections you left expanded are stored in your own browser and never sent to us. We use no analytics cookies, no advertising cookies, and no third-party trackers, and buyers completing a verification are given no cookie at all. The device signature described in Section 3.3 is computed only during a verification, for fraud prevention only.
The IntroVerify browser extension is optional, and installing it changes nothing about what we collect from buyers.
It stores one thing on your own computer: an access token you granted it by approving it while signed in. You can disconnect that token at any time from your account, or from the extension itself, and it stops working immediately.
It reads page content only on Instagram, X, Etsy and ArtStation, only on the conversation you have open, and only when you ask it for a code. What it reads is the handle of the person you are talking to, which it offers as the private label on the code it generates. If you highlight text and use the right-click menu, it reads what you highlighted and offers that as the label instead. Apart from what you highlight yourself, it does not read your messages, it does not send page content to us, and it does nothing at all on any other site.
Codes it generates are the same codes generated from your dashboard, and are covered by the rest of this policy.
IntroVerify is for adults. Artist accounts require you to be at least 18, the service is directed at working artists and their buyers, and we do not knowingly collect personal information from anyone under 18. If you believe we hold information about a child, tell us and we will delete it.
When we change this policy we will update the date at the top, and for material changes we will notify artists by email before the change takes effect. The current version is always at this address.
We are the data controller described in Section 1, and we answer every
question about this policy and every privacy request ourselves.
Privacy requests:
our privacy request form or
privacy-noticesintroverify.com
Everything else, including anything about the service itself:
careintroverify.com
Who should write to our representative. DataRep acts for us in the EU and EEA, the United Kingdom, and Switzerland. Write to them if you live in one of those places, or if you are a supervisory authority in one of them, and your question is about how we handle personal information. From anywhere else, or about anything else, careintroverify.com reaches us directly and will answer you sooner: DataRep acts for us only on data protection matters in the jurisdictions above, and has to forward everything else to us before it can be dealt with.
We have no establishment in the European Union. Under Article 27 of the GDPR, IntroVerify, LLC has appointed Data Protection Representative Limited (trading as DataRep) as its representative in the EU and EEA. You may contact DataRep about anything relating to our processing of your personal information, and supervisory authorities may do the same. DataRep keeps a contact location in every EEA country; the address below is the one for Ireland, and the full list is here if another is closer to you.
DataRep
77 Camden Street Lower
Dublin
D02 XE80
Ireland
Under Article 27 of the UK GDPR, IntroVerify, LLC has appointed Data Protection Representative Limited (trading as DataRep) as its representative in the United Kingdom.
DataRep
107-111 Fleet Street
London
EC4A 2AB
United Kingdom
Under Article 14 of the Swiss Federal Act on Data Protection, IntroVerify, LLC has appointed Data Protection Representative Limited (trading as DataRep) as its representative in Switzerland.
DataRep
Leutschenbachstrasse 95
Zurich
8050
Switzerland
Address your letter to DataRep, not to IntroVerify: post sent to these addresses in our name rather than theirs is unlikely to reach anyone. Say that you are writing about IntroVerify, LLC, and DataRep will pass it to us. DataRep also takes requests through their own online form at datarep.com/data-request.