Privacy Policy
This Privacy Policy explains how Codebled (exact registered entity name & address) ("OwnVouch," "we," "us") collects, uses, shares, and protects information when you use the OwnVouch app and related services (the "Service"). It applies to anyone who creates an account, registers a device, or otherwise uses the Service.
If you do not agree with this policy, please do not use the Service.
1. Information we collect
Account information. Email address and/or phone number, and, if you sign in with a third-party provider, the identifier and basic profile data (name, email) shared by Google or Apple.
Identity verification (KYC) data. To confirm that the person completing an ownership transfer is who they claim to be, we (or a third-party verification vendor acting on our behalf, currently KYC vendor name) collect identity verification data, which may include a government-issued ID, a selfie or liveness check, name, date of birth, and the verification result. We do not store this data ourselves beyond what is necessary to record that verification occurred — see Retention below.
Device data. Device identifiers (such as serial number or IMEI), device model, ownership history, warranty and repair records, and any supporting evidence you upload to a device's passport.
Transaction data. Records created during an ownership transfer or hand-off: the terms both parties agreed to (warranty status, included accessories, condition, and any private price note), timestamps, and the identities of the parties involved.
Approximate location. A coarse, city-level location derived from your IP address at the time of certain actions (for example, registering a device or reporting one lost). We do not collect precise GPS location.
Communications data. OTP codes and account-related messages sent to you by email, SMS, or WhatsApp, and delivery metadata from our messaging provider.
Audit and security data. An append-only log of account and device events (logins, transfers, status changes). Periodically, a cryptographic digest (a Merkle root) summarizing recent audit entries is anchored to a public blockchain for tamper-evidence. Only cryptographic hashes are anchored on-chain — no personal data, device identifiers, or document contents are ever written to the blockchain, and nothing anchored there can later be edited or removed.
Usage and device information. Standard technical data such as app version, operating system, crash logs, and general usage events, collected to keep the Service working and secure.
2. How we use this information
- Create and secure your account, and authenticate you via one-time codes or third-party sign-in
- Verify the identity of parties to an ownership transfer and confirm ownership claims
- Operate the device registry: registration, transfer, household sharing, lost/stolen reporting, and the public "is this device reported lost or stolen" check
- Detect and prevent fraud, abuse, and prohibited conduct (see our Acceptable Use Policy)
- Send transactional communications (OTP codes, transfer notifications, security alerts)
- Comply with legal, tax, anti-fraud, and anti-money-laundering obligations where applicable
- Maintain the audit trail that makes ownership records trustworthy
- Improve and secure the Service (aggregated, wherever possible de-identified)
We do not sell your personal information, and we do not use your identity-verification data for advertising.
3. Legal bases for processing (EEA/UK users)
Where the UK/EU GDPR applies, we rely on: performance of a contract (running the registry and transfers you request), legitimate interests (fraud prevention, security, the audit trail), legal obligation (KYC/AML record-keeping where required), and consent (for identity verification and optional communications, which you can withdraw at any time, though this may prevent you from completing a transfer).
4. Who we share information with
- Identity verification vendor (KYC vendor name) — to perform the verification check itself
- Google and Apple — if you use Sign in with Google or Sign in with Apple, to authenticate you
- Twilio — to deliver OTP codes by SMS and WhatsApp
- Cloud infrastructure and hosting providers — to run and store the Service
- Other users, in limited form — a device's lost/stolen status and a masked identifier (never your full name, email, or phone) are visible to someone performing a public ownership check on that device; the counterparty to a transfer sees the transaction terms and identity information needed to complete it
- Law enforcement or regulators, where required by law, to investigate fraud, or to respond to a valid legal request
- A successor entity, if OwnVouch is involved in a merger, acquisition, or asset sale, subject to this policy continuing to apply to your data
Each of these third parties processes data under its own privacy policy and terms; the relevant ones are linked from our Contact page.
5. International data transfers
Your information may be processed in countries other than the one where you live, including governing law country. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
6. Data retention
We retain account and device data for as long as your account is active, and for a limited period after closure to resolve disputes, satisfy legal and audit obligations, and prevent re-registration of a fraudulently reported device. Identity-verification and transaction records that function as financial/anti-fraud records are typically retained for KYC retention period after the relevant transaction, or longer where required by applicable law. Audit-log hashes anchored on-chain are, by design, permanent and cannot be deleted — they contain no personal data.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, export (data portability), or restrict our use of your personal information, and to object to or withdraw consent for certain processing. You can exercise most of these directly in the app (Settings) or by contacting us at privacy@ownvouch.com. See Account & Data Deletion for how account and data deletion specifically works, including what cannot be deleted (anchored hashes, and records we are legally required to retain).
EEA/UK residents may also lodge a complaint with their local data protection authority.
California residents have rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to opt out of "sale" or "sharing" — we do not sell or share personal information for cross-context behavioral advertising.
Other jurisdictions (e.g. India's DPDP Act) may grant equivalent rights; we honor applicable local law.
8. Children's privacy
The Service is not directed to, and we do not knowingly collect personal information from, anyone under minimum age · 18. If you believe a child has provided us with personal information, contact us at privacy@ownvouch.com and we will delete it.
9. Security
We use industry-standard technical and organizational measures (encryption in transit, access controls, hashed/append-only audit logging) to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Cookies and tracking
This website uses only the cookies necessary for it to function. The OwnVouch app itself does not use advertising cookies or third-party trackers.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the app or by email before they take effect. The "Effective date" above reflects the latest revision.
12. Contact us
Codebled
registered address
privacy@ownvouch.com