Privacy Policy
Last updated 26 July 2026 · VeroTag is operated by Yurai Technologies
VeroTag records the provenance of physical collectibles. You scan an NFC tag attached to an item, register details about it, and the result is a passport that anyone can verify. This policy explains exactly what we store, what is public, and what never leaves your account.
The most important thing to understand: a VeroTag passport is designed to be publicly verifiable. Some of what you enter is deliberately published so a buyer can check an item. Other information is private and never appears on a public page. The table below shows precisely which is which.
What we collect, and what is public
Account information
| Data | Visibility |
|---|---|
| Email address | Private. Never shown on a passport page. |
| Password | Handled by Google Firebase Authentication. We never see or store it. |
| Account identifier | Private. Deliberately stripped from every public response. |
Item information
| Data | Visibility |
|---|---|
| Title, category, format, set or series, year, manufacturer, item number, edition or variant, rarity, grade, description | Public on the item's passport page. |
| Photograph of the item | Public on the passport page, served through our servers rather than linked directly. |
| NFC tag identifier | Partly public. Only the last portion is displayed; the rest is masked, so the full identifier cannot be copied from a public page. |
| Registration date and provenance events | Public, without identifying who performed them. |
| Estimated value, purchase price, acquisition date, personal notes, condition notes, storage location | Private. Visible only to you. These are stored separately and are never included in any public page or public data response. |
Technical information
- Timestamps for registration, updates and synchronisation.
- Identifiers generated on your device for each item.
- Standard server logs, including IP address, kept for security and diagnostics.
How we use it
- To create and display item passports, and to let anyone verify an item.
- To operate your account and synchronise items between your device and our servers.
- To assess and display a trust status for each item, based on how it was registered.
- To keep the service secure, diagnose faults and prevent abuse.
We do not sell your information, and we do not use it for advertising.
Who else processes it
Google Firebase provides our authentication, database, file storage and server infrastructure. Data is processed on Google Cloud in the United States under Google's terms as our data processor.
We plan to add a blockchain minting service and an item-valuation service in future. They are not active today, and this policy will be updated before any information is shared with them.
Public passports and search engines
Passport pages are reachable by anyone with the link, which is the point — it is how a buyer verifies an item. Pages are currently marked so search engines do not index them, but a link you share can be shared onward by whoever receives it. Treat anything in the public columns above as information you are choosing to publish.
Your choices
- Correct it. Edit any item in the app. Changes to core identifying details are recorded as an amendment on the item's history rather than silently overwritten.
- Delete it. Delete a single item in the app, or delete your entire account from Sync → Account → Delete account. Deleting your account permanently removes your account, your items, their photos and all of your private information, and releases your NFC tags so they can be registered again. This cannot be undone.
- Get a copy. Contact us and we will provide the information associated with your account.
Depending on where you live, you may have additional rights over your personal information, including access, correction, deletion and portability. Contact us to exercise them.
How long we keep it
Account and item information is kept until you delete the item or your account. Server logs are kept for a limited period for security and diagnostic purposes. Deleting your account removes your data from our active systems; residual copies may persist briefly in encrypted backups before being overwritten.
Security
Data is transmitted over encrypted connections and stored on Google Cloud infrastructure. Access to private item information is restricted to your own account by server-side rules, not merely hidden in the interface. No system is perfectly secure, and we cannot guarantee absolute security.
Children
VeroTag is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.
Changes
We will update this policy as the service develops, and will change the date at the top. Material changes affecting how your information is used will be communicated in the app.
Contact
Questions, requests, or privacy concerns: contact@yuraitech.com