AsliVerify

Legal

Privacy Policy

Last updated: 18 July 2026

Who we are.AsliVerify Inc. (“AsliVerify”, “we”, “us”) is a Toronto, Ontario, Canada corporation. Questions about this policy go to hello@asliverify.com.

What we collect and why.

DataWhyRetention
Photo of the item at customer homeRun image-match verification, attach to the return record90 days, anonymized aggregate retained
Photo at drop-off counterRe-verify the item is the same90 days
SKU, customer ID, timestampBind the verification to the right return7 years (audit defence)
Geolocation of scan eventsGeo-fence verification against registered drop-off locations30 days, then aggregated
JWT token + hashTime-lock the QR pass to the right customer and item24 hours from issuance (active); hash retained for audit
Audit log entries (verdict, IP, manager ID)Chargeback evidence, fraud pattern analysis7 years

What we don't do.

We do not sell personal data. We do not use customer photos to train third-party AI models. We do not retain raw customer-photo data beyond the audit window defined above. We do not share identifiable images with brands that are not the brand of the return in question.

PIPEDA commitments.

AsliVerify is Canadian-founded and PIPEDA-compliant by design. We operate under the principle of minimum necessary data, limit PII access to authorized personnel under signed confidentiality, document data flows, and will respond to a written access request within 30 days at hello@asliverify.com.

Cross-border data.

Customer-photo artifacts are stored in Canada by default. For enterprise customers outside Canada, regional residency can be configured per the master service agreement. Audit-trail identifiers may transit across borders for fraud-pattern aggregation; raw photo data does not.

Your rights.

Customers may request access to or deletion of return-photo data by emailing hello@asliverify.com with their order number. We respond within 30 days. Brand administrators may request a summary report of all returns processed under their account at any time through the dashboard.

Subprocessors.

[List subprocessors with location + function + URL — populate before launch.]

Changes to this policy.

Material changes will be announced on this page with at least 30 days notice and emailed to active brand administrators.