Policy overview
This Privacy Policy explains how Verified by Toni, Inc. processes information for identity checks, face/liveness checks, business onboarding, partner consent, billing, fraud prevention, and support.
1. Information Toni Collects
- Account data such as name, email, phone number, authentication records, account settings, support messages, and consent records.
- Didit collects identity documents and verification evidence in its hosted flow. Toni receives provider references, decisions, check results, timestamps, and identity attributes needed for configured checks, such as name and age-threshold results.
- Didit processes face and liveness captures. Toni stores result records rather than a gallery of ID photos or biometric images. Billing records include payment references, credit purchases, and itemized verification charges; Stripe processes payment details.
2. Business and Representative Data
Business onboarding collects legal name, entity type and structure, state of formation, website, EIN where required, DBA, address, size, and intended use. Representative information includes legal name, date of birth, address, phone number, and the requested last four SSN digits. Company review can require additional information. Collection does not mean an automated EIN or SSN lookup has occurred.
3. Device, Security, and Usage Data
Toni may collect IP address, device identifiers, browser details, session metadata, geolocation signals derived from IP, risk indicators, attempted actions, page events, audit logs, and partner redirect details to secure accounts, prevent abuse, diagnose issues, and prove consent.
4. How Toni Uses Information
- Create and secure Toni accounts, verify contact methods, and authenticate users.
- Run identity proofing, face match, liveness, fraud prevention, company review, and reverification workflows.
- Issue partner-scoped verification claims after consent and maintain records of what was shared, with whom, and when.
5. How Toni Shares Information
Toni may share limited verification claims with partner websites only when permitted by consent, contract, law, or security necessity. Toni may also share information with service providers that process data for Toni, legal or regulatory recipients when required, and security recipients when needed to prevent fraud or abuse.
6. Data Retention
Toni retains information for as long as needed to provide verification, support partner assertions, maintain audit records, comply with legal duties, resolve disputes, prevent fraud, and enforce agreements. Provider-held ID and biometric evidence follows separate provider retention and deletion processes. It is not automatically erased when you return to Toni. A deletion request may require coordination with providers and assessment of records that must be retained.
7. User Controls and Privacy Rights
- Users can request access, correction, deletion, export, partner revocation, or review of certain personal information, subject to identity confirmation and legal exceptions.
- Users can revoke partner connections in App Connections. This does not erase information already received by a partner or automatically terminate that partner's sessions. Toni may retain records of past consent and verification.
- Depending on location, users may have additional rights under state, federal, biometric, consumer privacy, or data protection laws.
8. Security
Toni uses authenticated access, role-based permissions, security audit records, and signed partner results. These controls reduce risk but do not guarantee complete security. Raw ID photos and biometric images are not included in partner assertions.
9. Children and Sensitive Use Cases
Toni is intended for adults. Toni should not knowingly collect information from children or be used for high-risk decisions unless the partner has appropriate legal authority, disclosures, consents, and compliance controls.
10. Contact
Privacy questions, data requests, biometric/liveness questions, or concerns about partner sharing can be submitted through Toni support.