Information we collect
We collect information you provide directly: account registration details (name, email address, organization), gemstone submission data (description, photographs, weight, dimensions, declared origin), evidence files and laboratory reports you upload, payment information processed by our payment processor (Stripe), and communications you send to us. We also collect information generated by your use of the service: authentication and access logs, API request metadata, webhook delivery records, and audit events tied to your account.
How we use your information
We use collected information to: create and maintain your account; process your certification submission through the appropriate evidence tier workflow; communicate the status of your submission and any determination; operate, secure, and improve the platform; comply with our legal obligations; and resolve disputes. We do not use your submitted gemstone or evidence data for any purpose unrelated to your certification submission without your explicit consent.
Data retention
Account information is retained for the life of your account and for a reasonable period thereafter for legal and compliance purposes. Certification records — including submitted evidence, claims, determinations, and credential state — are retained permanently as part of the append-only provenance ledger. Audit events are retained permanently. Payment records are retained as required by applicable financial regulations. You may request deletion of account information; however, issued credentials and their underlying evidence records cannot be deleted because they form part of a governed public registry.
Information sharing
We share your information only as follows: with Stripe, our payment processor, to process subscription and certification fees; with authorized laboratory partners, only where you have submitted their evidence and only to the extent needed to verify authenticity of the evidence document; with service providers who process data on our behalf under confidentiality agreements; with law enforcement or regulators when legally required; and with successors in the event of a corporate transaction, subject to the same obligations in this policy. We do not sell your personal information.
Security
We use industry-standard controls including encryption in transit and at rest, multi-factor authentication requirements for operator access, cryptographic signing of credentials, and key management through our CUSTOS infrastructure. No system is perfectly secure; we will notify you of any breach affecting your personal information as required by applicable law.
Your rights and contact
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal information, or to restrict or object to its processing. To exercise these rights or for any privacy inquiry, contact us at privacy@provenanceverified.org. We will respond within the timeframe required by applicable law.