Verra Research Privacy Policy
Version 1.0 Effective Date: June 30, 2026 Last Updated: June 30, 2026
This Privacy Policy describes how Verra Research ("Verra," "we," "us," or "our") collects, uses, shares, and protects information about you when you use the Service. It is incorporated by reference into our Terms of Service.
If you do not agree with this Privacy Policy, do not use the Service.
1. Information We Collect
1.1 Information You Provide
When you create an account or use the Service, you may provide:
- Account information. Name, email address, password (stored as a hash via our authentication provider), profile picture, organization affiliation, and role.
- Profile and preferences. Watchlists, saved notes, research preferences, theme settings, notification preferences, sector and ticker interests.
- Payment information. If you subscribe to a paid plan, billing name, address, and a payment-method token from our payment processor. We do not store full card numbers.
- Communications. Content of messages you send to support, including any attachments.
- Feedback and survey responses. Including any User Content you upload.
1.2 Information Collected Automatically
When you use the Service, we automatically collect:
- Device information. Browser type and version, operating system, device identifiers, and screen resolution.
- Log data. IP address, access times, pages viewed, referring URL, and clickstream data.
- Cookies and similar technologies. Session cookies, authentication tokens, and analytics cookies. See Section 8.
- Usage data. Features used, queries run, content viewed, time spent on the Service, and interaction patterns.
- Performance and crash data. Error reports and diagnostic information.
1.3 Information from Third Parties
We may receive information about you from:
- Authentication providers. If you sign in via Google or another single-sign-on provider, we receive your name, email, and profile picture in accordance with the scopes you authorize.
- Payment processors. Transaction status, last four digits of payment card, and billing zip.
- Analytics and fraud-detection vendors. Aggregated information about your use and behavior.
- Business contacts and references. If you are a prospective enterprise customer, we may receive information from your colleagues or organization.
1.4 Information We Do Not Collect
We do not knowingly collect:
- Information from children under 13. If we learn we have collected such information, we will delete it promptly. See COPPA discussion below.
- Sensitive personal information under California law (e.g., social security number, precise geolocation, racial or ethnic origin) unless you voluntarily provide it.
- Biometric identifiers.
2. How We Use Information
We use information to:
a. Provide, operate, and maintain the Service.
b. Authenticate users and secure accounts, including detecting and preventing fraud, abuse, and security incidents.
c. Process subscriptions and payments.
d. Personalize content (e.g., remember your watchlist and theme).
e. Communicate with you about updates, security alerts, support responses, and other administrative matters.
f. Send marketing communications, subject to your preferences and applicable law. You may opt out at any time.
g. Analyze usage to improve the Service and develop new features. Aggregated or de-identified data may be used without restriction.
h. Comply with legal obligations, respond to legal process, and enforce our Terms.
i. Train, fine-tune, or improve internal AI models, but only on aggregated or de-identified data. We do not use the personally identifiable content of your User Content, queries, or notes to train models that are made available to other customers.
3. Legal Bases for Processing (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on one or more of the following legal bases under the GDPR or its UK and Swiss counterparts:
- Performance of a contract. To provide the Service you have requested.
- Legitimate interests. To operate, secure, and improve the Service; to communicate with users; and to prevent fraud and abuse.
- Consent. Where we rely on your consent (e.g., for certain marketing or non-essential cookies). You may withdraw consent at any time.
- Legal obligation. To comply with applicable law.
4. How We Share Information
We share information only as described below. We do not sell personal information in the traditional sense, and we have not sold personal information in the preceding twelve months. To the extent any sharing of personal information constitutes a "sale" or "sharing" under the California Consumer Privacy Act ("CCPA")/California Privacy Rights Act ("CPRA"), we provide California residents the right to opt out as described in Section 11.
4.1 Service Providers
We share information with third-party vendors who process information on our behalf under contractual confidentiality and data-protection obligations:
- Hosting and infrastructure. Vercel (CDN and edge runtime, U.S.), Cloudflare (CDN and security, U.S.).
- Database and authentication. Supabase (database, authentication, edge functions, U.S.).
- AI and research providers. Perplexity AI (LLM and search), and other LLM API providers as needed.
- Financial data. Finnhub (financial data provider), Yahoo Finance (financial data provider).
- Payments. Stripe (payment processing).
- Email and communications. Gmail/Google Workspace (transactional and marketing email).
- Analytics. Vercel Analytics, and others. Aggregate-only by default.
- Customer support. Internal and contracted support staff.
A current list of subprocessors is available on request to privacy@verraresearch.com.
4.2 Business Transfers
If Verra is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, your information may be transferred as part of that transaction, subject to commercially reasonable confidentiality protections.
4.3 Legal Compliance and Protection
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a subpoena, court order, or other legal process.
- Enforce our Terms or other agreements.
- Protect the rights, property, or safety of Verra, our users, or others.
- Detect, prevent, or address fraud, security, or technical issues.
4.4 With Your Consent
We may share information with your consent or at your direction.
4.5 Aggregated or De-Identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you. We are not obligated to provide the same protections to such information.
5. AI and LLM Processing of Your Data
When you interact with AI features of the Service:
- Prompts. Your prompts are transmitted to our LLM providers (e.g., Perplexity AI) for the sole purpose of generating a response.
- Responses. Stored on our servers to provide the Service and improve quality (e.g., logging for debugging, scoring, or moderation).
- Training. We do not authorize our LLM providers to use your prompts or responses to train their foundation models that are made available to other customers. Where a provider's standard terms allow such use, we contractually opt out where possible.
- Confidentiality. Do not submit confidential information, material non-public information, personal health information, or other sensitive data to the Service unless permitted by a separate written agreement with Verra.
6. International Data Transfers
Verra is based in the United States. Information we collect may be processed in the United States and other countries where we, our subprocessors, or our affiliates operate. Data-protection laws in these countries may differ from those in your jurisdiction.
For transfers from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on standard contractual clauses or other approved transfer mechanisms.
By using the Service, you consent to the transfer of your information to any country where Verra or its subprocessors operate.
7. Data Retention
We retain information for as long as necessary to provide the Service and for the purposes described in this Policy. Specific retention periods:
- Account data. For the life of your account plus a reasonable wind-down period (typically 90 days) to allow recovery and export.
- Transaction and billing records. Up to seven (7) years for tax, audit, and accounting purposes.
- Logs and analytics data. Typically 12-24 months, in aggregated form thereafter.
- Backups. Up to 90 days following deletion of source data.
- Legal hold. Indefinite, where required to comply with a legal obligation, resolve a dispute, or enforce our agreements.
You may request deletion of your account at any time. We will delete or de-identify your personal information within a reasonable time, subject to the exceptions above.
8. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage and pixel tags) for:
- Strictly necessary. Authentication, security, load balancing, and core functionality. These cannot be disabled.
- Functional. Theme preference, watchlist persistence, language. Disabling these will degrade your experience.
- Analytics. Aggregate usage and performance.
- Marketing. Limited; we currently do not run third-party advertising on the Service.
You may control cookies through your browser settings. Most browsers allow you to block or delete cookies, but blocking strictly necessary cookies will prevent you from using the Service.
We do not currently respond to "Do Not Track" signals because no industry standard has been finalized.
9. Security
We implement industry-standard administrative, technical, and physical safeguards designed to protect your information, including encryption in transit (TLS 1.2+) and at rest, access controls, and security monitoring. No system is fully secure, and we cannot guarantee the absolute security of your information.
If you believe your account has been compromised, contact security@verraresearch.com immediately. In the event of a data breach, we will notify affected users and regulators in accordance with applicable law.
10. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access. Request a copy of the personal information we hold about you.
- Correction. Request correction of inaccurate or incomplete information.
- Deletion. Request deletion of your personal information, subject to legal retention obligations.
- Restriction. Request that we restrict processing of your information.
- Portability. Request a machine-readable copy of certain data.
- Objection. Object to certain processing (e.g., direct marketing) at any time.
- Withdraw consent. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
- Lodge a complaint. With a supervisory authority in your jurisdiction.
To exercise any of these rights, contact privacy@verraresearch.com. We will respond within the timeframe required by applicable law (typically 30-45 days). We may need to verify your identity before fulfilling certain requests.
We will not discriminate against you for exercising any of these rights.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, in addition to the rights in Section 10, you have the right to:
- Know. Categories of personal information collected, sources, business or commercial purpose, third parties shared with, and specific pieces collected over the prior 12 months.
- Delete. Personal information we collected from you, subject to exceptions.
- Correct. Inaccurate personal information.
- Opt-out of sale or sharing. We do not sell personal information in the traditional sense. To the extent any data-sharing constitutes a "sale" or "sharing" under California law, you may opt out by emailing privacy@verraresearch.com or, where applicable, by enabling Global Privacy Control in your browser.
- Limit use of sensitive personal information. We do not use sensitive personal information for purposes that trigger this right.
- Non-discrimination. We will not discriminate against you for exercising any CCPA/CPRA right.
Categories of personal information collected (CCPA categories): identifiers (A); customer records (B); commercial information (D); internet/network activity (F); geolocation data (G, approximate only); professional/employment information (I); inferences drawn from other categories (K).
Categories of sources: directly from you, from your devices, from third-party authentication providers, and from analytics and fraud-detection vendors.
Business and commercial purposes: providing the Service, security, analytics, communications, legal compliance.
Categories of third parties shared with: service providers as listed in Section 4.1; legal/regulatory recipients as described in Section 4.3; and successors in business transfers as described in Section 4.2.
You may submit a request through privacy@verraresearch.com. You may designate an authorized agent to make a request on your behalf.
12. Children's Privacy (COPPA)
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact privacy@verraresearch.com so we can delete it.
For users between 13 and 16 in California, parental consent considerations under California law apply where relevant.
13. EU/UK/Swiss Users
If you are in the European Economic Area, the United Kingdom, or Switzerland:
- The controller of your personal information is Verra Research.
- You may contact our data protection point of contact at privacy@verraresearch.com.
- You may lodge a complaint with your local supervisory authority.
- Legal bases for processing are described in Section 3.
14. Communications
By creating an account, you consent to receive transactional communications from us (account-related, security, and service updates). You may opt out of marketing communications at any time using the unsubscribe link in any marketing email or by emailing privacy@verraresearch.com. We will continue to send necessary transactional communications.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email and/or in-product banner at least seven (7) days before they take effect, except when shorter notice is required by law. Material changes that affect the way we use previously-collected personal information may require renewed consent. Continued use of the Service after the effective date constitutes acceptance.
16. Contact Us
For privacy questions, requests, or complaints:
Verra Research Email: privacy@verraresearch.com Security: security@verraresearch.com Legal: legal@verraresearch.com
This document was last updated on June 30, 2026. Prior versions are archived and available on request.