Legal

Privacy Policy

Draft version · last updated [DATE] · effective from [LAUNCH DATE]

This is a working draft, not a published legal document. It reflects Birel's actual data-handling design so a lawyer has real substance to review – not a generic template. Confirm applicable regimes (GDPR, UK GDPR, CCPA/CPRA, state privacy laws) and have it reviewed before publishing or relying on it.
The core principle: we minimize what we keep. Birel is built to answer one question – "is the threshold crossed?" – without becoming a repository of anyone's financial life. Where a data point isn't needed to answer that question, we don't retain it.

1. Who we are

This Privacy Policy explains how Birel ("we," "us") handles personal information when you use our website, request a verification, complete a verification as a Prover, or otherwise interact with our Service. It should be read together with our Terms of Service.

2. What we collect

WhoWhat we collect
RequestersName, email, phone (optional), company/agency name, billing information, requests you send (threshold, purpose label, recipient contact).
ProversName and contact details you provide to complete a verification; identity-verification data collected by our KYC provider; a one-time connection token from your bank/brokerage/wallet provider; the resulting yes/no threshold outcome.
EveryoneStandard technical data (IP address, device/browser type, pages visited) collected for security and basic analytics.

3. What we deliberately don't keep

This is the section most privacy policies don't need, and the one that matters most here:

  • We do not store your bank or brokerage account balance, statements, or transaction history.
  • We do not store your account or routing numbers, or your crypto wallet address, beyond the moment needed to compute a threshold result.
  • We do not see or store your bank, brokerage, or wallet login credentials – these are entered directly with the relevant provider, never with Birel.
  • We do not sell personal information, and we do not aggregate or publish verification data as a market-data or research product.

4. How we use information

  • To operate the verification flow: matching a Prover's confirmed identity to the connected financial source, computing whether a threshold is met, and issuing a badge.
  • To operate accounts, billing, and support for Requesters and Agency subscribers.
  • To maintain a security and audit log of verification events (see Section 6) in case a badge or verification is disputed.
  • To comply with legal obligations, including responding to lawful requests from authorities.
  • To improve the Service, using aggregated or de-identified data wherever possible.

5. Third parties we share information with

We rely on regulated service providers to perform parts of the verification process. Categories include:

  • Open-banking / data-aggregation providers (e.g., Plaid and equivalent UK/EU aggregators) – to establish a read-only connection to a bank or brokerage account and return a balance-threshold result.
  • Identity-verification (KYC) providers – to confirm that the person completing a verification is who they claim to be.
  • Blockchain infrastructure providers – to read publicly available wallet balances after a wallet-signature check.
  • Payment processors – to bill Requesters and Agency subscribers. We do not store full payment card numbers ourselves.
  • Hosting, email, and support infrastructure providers, bound by confidentiality and data-processing agreements.

We do not share Prover financial data with the Requester who initiated a verification, beyond the threshold result itself, purpose label, and (where the Prover has not chosen anonymity) their name.

6. Retention

  • Verification outcome records (threshold, level, dates, purpose label) are retained for [XX months] for audit, dispute-resolution, and fraud-prevention purposes, then deleted or anonymized.
  • Bank/brokerage/wallet connection tokens are retained only as long as needed to service an active or "live" badge, and are revoked and discarded on expiry or revocation.
  • Account and billing information is retained for as long as your account is active and as required by applicable tax and accounting law thereafter.

7. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise these rights, contact privacy@birel.io. We will respond within the timeframe required by applicable law.

[Placeholder – add jurisdiction-specific detail: GDPR Article 15–22 rights for EU/UK users, CCPA/CPRA rights and "Do Not Sell/Share" mechanics for California residents, etc., once your legal counsel confirms which regimes apply to your user base.]

8. Security

We use industry-standard technical and organizational safeguards, including encryption in transit and at rest, access controls, and regular review of our data-minimization practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. International transfers

We may process and store information in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers of personal information out of the EEA or UK.

10. Cookies and analytics

We use a limited set of cookies and privacy-respecting analytics to understand site usage and improve the Service. We do not use third-party advertising cookies or sell data derived from site analytics.

11. Children's privacy

Birel is not directed at children under 18 and we do not knowingly collect personal information from them.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email before they take effect.

13. Contact

Questions about this Privacy Policy can be sent to privacy@birel.io.

.BIREL Terms Privacy REAL BIREL CERTIFICATES LIVE ONLY ON BIREL.IO – CHECK THE ADDRESS BAR