Privacy policy
last updated · 28 July 2026
verza ("we", "us") is a South African verification API at verza.dev, operated as a sole proprietorship. This policy explains what personal information we process, why, who we share it with, and your rights under the Protection of Personal Information Act, 2013 (POPIA).
1. What we process
Identity and VAT numbers you submit for verification
This is verza's core function, and it is the one place we deliberately process the least. ID and VAT numbers submitted for validation are checked in memory and never stored, never written to a database, and never logged, not even in anonymised form. Access logs record the request path and HTTP status only; the value you're checking never reaches them. If you validate the same number twice, we have no record that you validated it once.
Payment data
- Pay-per-call (x402): paid endpoints settle in USDC on the Base blockchain via Coinbase's CDP facilitator. The paying wallet address, amount and transaction hash are public blockchain data, not something we collect privately. We don't request or receive any identity information beyond the wallet address.
- Subscription (Paystack): if you subscribe instead of paying per call, Paystack collects and processes your card and billing details directly. We never see or store your card number; we receive your name, email, subscription status and a transaction reference from Paystack.
Account and API key data (subscription tier)
If you create a subscription account: your email address, a password hash (never the raw password), and the API key we issue you.
If you contact us
Your name, email address and message, sent to info@verza.dev.
Automatically
Server access logs record request path and HTTP status only. Never query strings, never request bodies, never the identifiers you're validating.
2. Why we process it
- Running the verification API. Legal basis: contract, since the check can't happen without processing the input, even transiently.
- Billing and subscriptions. Legal basis: contract, handled primarily by Paystack.
- Abuse and fraud prevention, such as telling scraper traffic from genuine buyers. Legal basis: legitimate interest.
- Communication: replying to messages sent to info@verza.dev.
We do not sell data or use it for advertising. verza runs no analytics and no tracking cookies of any kind, so there is nothing to opt out of.
3. Who we share with (sub-processors)
- Coinbase (CDP facilitator): settles x402 payments in USDC on Base. Receives the paying wallet address and amount, not identity data. Global infrastructure.
- Base (public blockchain): x402 payments settle here and are permanently, publicly visible, as with any blockchain payment. That's the nature of the payment rail, not a choice we make about your data.
- Paystack: if you use the subscription tier, Paystack is the payment processor of record for your card and billing details.
- Cloudflare: DNS and edge proxy in front of verza.dev, and email routing for info@verza.dev.
- Google (Gmail): info@verza.dev forwards to a Gmail inbox for handling support requests.
- Our server: self-hosted infrastructure in Cape Town, South Africa.
We do not transfer personal information to any other party. If we add or change a sub-processor, we'll update this list.
4. Cookies and tracking
None. verza runs no analytics, no advertising pixels, and no tracking cookies for the API or the docs site.
5. Your rights under POPIA
- Access the personal information we hold about you, which for the verification API itself is essentially none beyond access logs.
- Correct inaccurate account information.
- Delete your account and associated data: email info@verza.dev and we'll action it within 30 days.
- Object to processing, or lodge a complaint with the Information Regulator of South Africa: inforegulator.org.za.
6. Data retention
- Identity and VAT numbers submitted for validation: never stored, so there's nothing to retain or delete.
- Access logs (path and status only): retained for as long as needed for service operation, metrics and abuse detection.
- Account and subscription data: kept while your account is active, deleted within 30 days of a deletion request.
- Email correspondence: kept in our inbox unless you ask us to delete the thread.
7. International transfers
The Coinbase CDP facilitator and Base settlement run on global infrastructure outside South Africa. Where required by POPIA, these transfers are protected by contractual and legal safeguards equivalent to local protection.
8. Security
Identity and VAT numbers are validated in memory only and never touch disk. The server exposes nothing beyond what's needed to run the API, and since verification inputs are never persisted, there is no verification-data breach to notify.
9. Breach notification
If we discover a security breach affecting personal information we do hold (account or billing data), we will notify affected users and the Information Regulator of South Africa within 72 hours of becoming aware, as required by POPIA section 22.
10. Information Officer
Under POPIA section 55, the operator of verza serves as Information Officer and is contactable at info@verza.dev.
11. Changes
We will post a new "last updated" date at the top of this page when we change anything material.
12. Contact
Privacy questions or deletion requests: info@verza.dev.