Privacy Policy
Last updated: 12 June 2026
Vouch is an email verification API operated by Datapad B.V. (“Datapad”, “we”). This policy explains what we do with personal data — including what happens to an email address when you verify it — and the choices you have.
The short version: Vouch never sends email to verify an address, and when you verify one we store only the domain (for example gmail.com) together with the result — not the full address or the part before the @.
Who we are
Datapad B.V. is the data controller for the processing described here. For any privacy question, or to exercise your rights, contact us at [email protected].
Information we process
Addresses you verify (the API)
When you call GET /v1/verify, we process the email address in the request to run the checks — syntax, MX lookup, a live SMTP RCPT TO probe and catch-all detection. The address is used only in memory to perform these checks and is not saved to our database. For metering and billing we store one usage record per call containing the domain of the address, the verdict and reason code, how long the check took, the API key that made the call, and a timestamp — not the local-part, and not the full address.
Account and API keys
For account holders we store:
- your account email address;
- a one-way hash of each API key — we never store the key itself, only the last four characters so you can recognise it;
- a customer identifier that links your account to billing, your remaining credit balance, and created and last-used timestamps.
Billing
Payments are handled by the Datapad customer portal. Vouch does not receive or store your card details — only the customer identifier and your credit balance.
Website analytics
On our marketing pages we use Google Analytics 4 with Google Consent Mode v2. Analytics cookies are off by default: until you accept them in the cookie banner, Google receives only aggregated, cookieless signals. If you accept, Google sets the analytics cookies listed below. You can change your choice at any time from the “Cookie settings” link in the footer.
Sign-in and server logs
When you sign in to the dashboard we set a session cookie to keep you authenticated. As with any service, our infrastructure also records standard technical logs — such as IP address, user agent and request time — to operate the service securely and prevent abuse.
Cookies and local storage
| Name | Type | Purpose | Retention |
|---|---|---|---|
vouch_session | Cookie · necessary | Keeps you signed in to the dashboard; holds a signed token with your customer ID and email. | Until it expires or you sign out |
vouch-consent | Local storage · necessary | Remembers your cookie choice so we don’t ask again. | Until you clear it |
_ga, _ga_* | Cookie · analytics | Google Analytics — distinguishes visitors and sessions. Set only after you accept. | Up to ~13 months |
Why we are allowed to process it
Under the GDPR we rely on:
- Performance of a contract — to provide the verification API and run your account.
- Legitimate interests — to secure the service, prevent abuse, and understand product usage at the domain level. We do not store the addresses you verify.
- Consent — for analytics cookies, which you can withdraw at any time.
- Legal obligations — for example, keeping billing records.
Who we share it with
We do not sell personal data. We share it only with the service providers that help us run Vouch, under appropriate agreements. These include our application and database platform (Appwrite), Google (Analytics), our CDN and edge provider (Cloudflare), our hosting provider (IONOS), and the Datapad portal for sign-in and billing. When you verify an address, our server also connects to the recipient’s mail provider as part of the SMTP check.
International transfers
Some providers (such as Google) may process data outside the European Economic Area. Where that happens, the transfer is covered by safeguards such as the European Commission’s Standard Contractual Clauses.
How long we keep it
We keep account and usage data for as long as your account is active and as needed for billing, security and legal obligations, after which we delete or anonymise it. Analytics data is retained according to our Google Analytics configuration.
Your rights
If you are in the EEA or the UK, you have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent. To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.
Security
Traffic is served over HTTPS. API keys are stored only as one-way hashes, and sensitive values are encrypted at rest. No method of transmission or storage is completely secure, but we work to protect your data appropriately.
Children
Vouch is a tool for businesses and developers and is not directed at children.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “last updated” date at the top of this page.
Contact
Questions about this policy or your data? Email [email protected].