Last Updated: January 10, 2026
Do Authentication Inc. ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our mobile applications, access our API, or use any of our services (collectively, the "Service").
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
We may collect personal information that you voluntarily provide to us when you:
This information may include:
When you access the Service, we automatically collect certain information, including:
We may receive information about you from third parties, including:
We use the information we collect for the following purposes:
If you are located in the European Economic Area (EEA) or United Kingdom (UK), our legal basis for collecting and using your personal information depends on the specific information and context:
We may share your information in the following circumstances:
We share information with third-party vendors, consultants, and service providers who perform services on our behalf, including payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance. These providers are contractually bound to protect your information and may only use it for the purposes we specify.
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service of any change in ownership or uses of your personal information.
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court, government agency, or law enforcement). We may also disclose information when we believe in good faith that disclosure is necessary to:
We may share your information with third parties when you have given us explicit consent to do so.
We may share aggregated or de-identified information that cannot reasonably be used to identify you. For example, we may share statistics about authentication trends, counterfeit patterns, or service usage without identifying individual users.
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider:
Authentication Records: We retain authentication records, including submitted photographs and certificates, indefinitely to maintain the integrity of our certificate verification system and to support our Financial Guarantee program.
Account Information: We retain account information for as long as your account is active. If you request account deletion, we will delete or anonymize your personal information within 90 days, except where retention is required by law or for legitimate business purposes.
We implement appropriate technical and organizational security measures designed to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These measures include:
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
You have the right to request access to the personal information we hold about you and to receive a copy of your data in a structured, commonly used, machine-readable format.
You have the right to request correction of any inaccurate or incomplete personal information we hold about you.
You have the right to request deletion of your personal information, subject to certain exceptions (such as legal obligations or ongoing disputes).
You have the right to request restriction of processing or to object to our processing of your personal information in certain circumstances.
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time.
You may opt out of receiving marketing communications from us by clicking the "unsubscribe" link in any email or by contacting us directly. Note that you may still receive transactional or service-related communications.
To exercise any of these rights, please contact us at privacy@doauthentication.com. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
We use cookies and similar tracking technologies to collect and store information about your interactions with the Service.
Most web browsers are set to accept cookies by default. You can usually choose to set your browser to remove or reject cookies. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of the Service.
Some browsers include a "Do Not Track" (DNT) feature. Because there is no accepted standard for how to respond to DNT signals, we do not currently respond to DNT browser signals.
The Service may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to third-party services, and we are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party services you access.
We may use the following categories of third-party services:
Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that are different from the laws of your country.
When we transfer personal information from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18 without verification of parental consent, we will delete that information as quickly as possible. If you believe we might have any information from or about a child under 18, please contact us at privacy@doauthentication.com.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
To exercise your CCPA rights, please contact us at privacy@doauthentication.com or call us at 1-800-XXX-XXXX. You may also designate an authorized agent to make a request on your behalf.
If you are a Nevada resident, you have the right to opt out of the sale of certain personal information to third parties. We do not currently sell personal information as defined under Nevada law. If you have questions, please contact us at privacy@doauthentication.com.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service prior to the change becoming effective. We encourage you to review this Privacy Policy periodically for any changes.
Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Do Authentication Inc.
Privacy Team
Email: privacy@doauthentication.com
If you are located in the EEA or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.