VertexY
How it worksPricingDocs
Sign inTry the engine

Legal

Privacy Policy

How VertexY collects, uses, shares, retains, and protects personal information.

Effective Date

August 10, 2026

Questions about this document can be sent to support@getvertexy.com.

On this page

OverviewInformation We CollectHow We Use InformationHow We Share InformationData RetentionSecurityInternational TransfersCookies and Similar TechnologiesYour RightsChildrenChanges and Contact
1

Overview

VertexY provides fraud detection, risk scoring, and graph intelligence services for business customers. This Privacy Policy explains how VertexY collects, uses, discloses, and protects personal information when organizations evaluate, buy, deploy, and use the platform.

It applies to our public website, the product interfaces and APIs, support channels, and related business operations. It does not override separate contractual commitments made in a subscription agreement, data processing addendum, or security exhibit; where those conflict with this policy, the agreement governs.

Controller and processor roles

These two roles are separate and it matters which one applies to a given piece of data:

  • For our own website visitors, account holders, billing contacts, and support correspondents, VertexY acts as a controller and decides how that information is used.
  • For the service data a customer sends us to assess — transaction, device, network and identity signals about their end users — VertexY acts as a processor, acting on that customer’s instructions. Requests from an end user about that data are directed to the customer who controls it.
2

Information We Collect

Account and business information

Names, work email addresses, job titles, company names, billing contacts, and administrative login details, collected when a customer registers or interacts with us.

Service data submitted for assessment

Data a customer sends through our APIs, dashboards, webhooks, and integrations. Depending on the customer’s implementation this may include device, network, transaction, behavioural, and identity-related signals needed to assess risk.

Indicator values such as email, phone, device and payment identifiers are stored as keyed hashes by default rather than as readable values. Readable storage is opt-in per field and controlled by the customer’s administrator.

Usage, diagnostic and security telemetry

Login events, feature usage, request metadata, browser details, IP addresses, audit events, and operational logs, used to secure the platform, monitor performance, prevent abuse, and improve the service.

Public sandbox

The interactive sandbox accepts only constrained synthetic aliases, documentation-reserved IP addresses, and structured demo values; personal-information fields are rejected. It stores no result and creates no assessment record tied to you. The browser may keep up to ten runs in page memory until you refresh or navigate away. We record anonymous aggregate run events and hashed IP counters for rate limiting and product analytics.

Do not send us special-category data, government identifiers, full payment card numbers, or authentication credentials. The service is not designed to receive them, and our ingestion path redacts values that resemble them.

3

How We Use Information

Purposes and the basis on which we rely.
PurposeCategories usedBasis
Provide and maintain the platformAccount data, service dataContract performance
Authenticate users and secure accountsAccount data, security telemetryContract performance; legitimate interests
Detect and prevent abuse of our own serviceSecurity telemetryLegitimate interests
Operate billing and enforce plan limitsAccount data, usage meteringContract performance
Provide supportAccount data, support correspondenceContract performance
Improve reliability and product featuresAggregate usage and diagnosticsLegitimate interests
Meet legal and audit obligationsAccount data, audit logsLegal obligation

Where we use customer service data beyond delivering the service to that customer, we do so only as permitted by the applicable agreement and law.

Automated processing

The platform produces an automated risk score and a recommended action. VertexY does not execute the resulting business decision. The customer’s own systems and staff decide whether to allow, review, or decline, and retain responsibility for that outcome, including any human review they choose to apply.

AI assistance features

Optional AI features summarise evidence the platform already holds. They are read-only: they never alter a score, an action, a review outcome, or a policy. They run only on evidence assembled server-side within the customer’s own tenant, are disabled unless a company administrator enables them, and are configured so provider requests are not retained for provider model training.

4

How We Share Information

We do not sell personal information and we do not share it for cross-context behavioural advertising. We share it with service providers that help us operate the platform, each authorised to use it only to provide services to VertexY.

Categories of subprocessor. The current list for a given subscription is available on request.
CategoryPurpose
Cloud infrastructure and hostingRuns the application, databases, and graph storage
Transactional emailVerification, notification, and scheduled report delivery
Payments and subscription billingCheckout, invoicing, and subscription lifecycle
Product analytics and error monitoringUsage measurement and fault diagnosis
AI model providerOptional AI assistance features only, when enabled by an administrator

We may also disclose information when required by law, legal process, or a government request; to protect the rights, safety, and security of VertexY, our customers, or others; or in connection with a merger, acquisition, financing, or asset sale, in which case we will continue to protect it in line with this policy.

5

Data Retention

Indicative retention. Specific periods may be adjusted by contract or by a customer’s configuration.
DataRetention
Account and billing recordsFor the life of the account, then as required for tax and legal obligations
Risk assessments and evidenceFor the retention window configured by the customer administrator
AI conversations and artifactsSession-only, 7, 30, or 90 days, selected by the customer administrator
Audit logsRetained to support security review and customer audit obligations
Operational and security logsA short rolling window sized for incident investigation
Public sandbox runsNot stored

Customer administrators may request deletion or return of certain customer data in line with the applicable contract and the technical limits of the service. Backup copies and security logs may persist for a limited period until they are overwritten or expire on their normal schedule.

6

Security

  • Encryption in transit for all API and dashboard traffic.
  • Authenticated encryption at rest for sensitive stored fields, including AI evidence snapshots and artifact content.
  • Keyed hashing of risk indicators, so stored identifiers are not readable by default.
  • Tenant scoping enforced at every backend boundary, with the tenant identity taken from the authenticated session rather than the request body.
  • Role and permission checks on privileged actions, with audit logging of administrative and export events.
  • Signed, replay-protected ingestion for server-to-server event delivery.

No system is perfectly secure and we do not claim otherwise. We hold no third-party security certification at this time; where a page or document would normally cite one, it states the absence instead.

7

International Transfers

VertexY and its service providers may process information in countries other than the one where it was collected. Where we transfer personal information across borders, we rely on the safeguards required by applicable law, such as standard contractual clauses, and we contract our subprocessors to equivalent obligations.

8

Cookies and Similar Technologies

  • Strictly necessary cookies keep you signed in and protect authenticated requests. These cannot be disabled without breaking the product.
  • Product analytics measure how the website and dashboard are used, so we can find what is confusing or slow.
  • We do not use advertising or cross-site tracking cookies.

Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in.

9

Your Rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal information, to receive a portable copy, and to withdraw consent where we rely on it. You may also have the right to complain to your local supervisory authority.

If you are an end user of one of our customers, that customer controls the data submitted about you. We will refer your request to them and support them in responding.

To make a request, email support@getvertexy.com. We will verify the request appropriately before acting on it, and we will not treat you differently for exercising these rights.

10

Children

VertexY is a business-to-business service and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

11

Changes and Contact

We may update this policy as the service changes. When a change is material we will update the effective date above and, for customers, provide notice through the account or by email before it takes effect.

Questions about this policy, or a request to exercise your rights, can be sent to support@getvertexy.com.

VertexY
GitHubLinkedIn

Product

  • Pricing
  • Security

Docs

  • Quickstart
  • API reference
  • Sandbox

Company

  • About
  • Support
  • Privacy
  • Terms

© 2026 VertexY. Built independently.

Leave a review