# Privacy policy — visibility.cloud

Effective 2 August 2026. Visibility Cloud, Inc.

What visibility.cloud collects when you use this site, what we do with it, who we share it with, and how to reach us about it.

## 1. Who we are

Visibility Cloud, Inc. ("we") operates visibility.cloud. The services publish an item-level chain-of-custody record built on EPCIS 2.0 and CBV 2.0: written material, worked illustrative traces, and machine-readable surfaces addressed to software readers as much as to people, together with the developer and standards doors of the same family. The two doors a reader can use on the site are a segment seat list and a get-started interview.

This policy covers these surfaces:

- visibility.cloud
- epcis.dev
- transactions.dev
- barcoding.dev
- barcodes.do

Privacy questions go to [legal@visibility.cloud](mailto:legal@visibility.cloud).

## 2. What we collect

We collect the categories below. This table is the complete list.

| Category | What it contains | Why we collect it |
| --- | --- | --- |
| What you tell us | the email address you give the seat list or the get-started interview, the segment you choose, the answers you give, anything you type into a free-text field, the ending the interview reached and the receipt token this origin mints for that row, the month a conversation was requested, and whatever you write to us directly | answering you, and following up about the thing the address was given for |
| The network a request came from | the IP address and its network prefix, the autonomous system number, and the organisation that operates that network | operating and securing the services, and understanding which organisations read them |
| Approximate location, derived from that network | country, region, city, postal area, time zone and continent, plus the data centre that served the request — one network’s estimate about another, never a device location | understanding readership, and detecting abuse that clusters by place |
| Device, connection and automation signals | the user agent, the HTTP protocol, the TLS version and cipher and a fingerprint computed from the shape of the TLS handshake, round-trip time, language and content preferences, client hints, the platform’s bot score and its JA3/JA4 handshake fingerprints where the plan supplies them, and our own typed judgement of the caller — a person, a known AI agent, a verified crawler, a suspected scraper, or unknown — with the signals behind it | telling human readers from automated ones, and stopping abuse, scraping and attack traffic |
| What was requested, and what was returned | the method, path, query string, response status, which representation was served, and the moment | operating the services and reading traffic over time |
| How the request arrived | the referring page and its host, the relationship the browser declares between that page and ours, and any campaign tags on the address | understanding what brings readers here |
| The join key, where there is one | a receipt token this origin minted, or a SHA-256 of your lower-cased address — never the address itself. Request bodies, form fields, cookies and Authorization headers are never recorded at all | connecting a request to something you gave us, without putting your address in the request log |
| Aggregate site analytics | Cloudflare Web Analytics measurements: pages read, how readers arrive, and general traffic patterns, reported in aggregate and without cookies | understanding how the services are used |

## 3. How we use it

We use personal information to provide the services, keep them secure, keep
required records, and comply with law — the purposes stated in the table above,
and nothing else.

We do not sell personal information. We do not build advertising profiles. We
do not use personal information to train machine-learning models.

## 4. Who processes it for us

These are the vendors and affiliates that process personal information on our
behalf, and what each one does. This list is the complete list.

| Processor | Role | Note |
| --- | --- | --- |
| Cloudflare | hosting, edge network and security; the runtime the services execute in, the databases they write to, and Cloudflare Web Analytics | The services run on a global network, so information about your use of them may be processed outside your own country, including in the United States. Cloudflare also keeps its own short-retention log of requests, as it does under any site on its network. |
| Slack | notifying our own team when someone joins the seat list or completes the interview | The notification carries what you typed — the address, the segment and the answers — and nothing derived from the request. |
| Google Workspace | the mailboxes on these domains: email you send us and email we send you |  |

Each processor is bound by contract to process personal information only to
provide its service to us.

## 5. How long we keep it

| Data | Kept for | Because |
| --- | --- | --- |
| The IP address on a request record | thirty days | investigating abuse and attack traffic while it is still live |
| The rest of a request record | four hundred days | reading readership — in particular automated readership — across a full year and its comparison year |
| The seat list, the interview, requested conversations, and correspondence | while we are in touch with you about what you gave the address for, and deleted when you ask | following up about the thing you asked for |

When a period ends we delete the data or irreversibly anonymize it.

## 6. Email

We send transactional email (service notices) and, with your consent,
marketing email. Every marketing email carries an unsubscribe link, and
unsubscribing is immediate.

## 7. Your rights

Where the law where you live grants you rights over your personal information —
access, correction, deletion, portability, objection, or others — we honor
them. Send requests to [legal@visibility.cloud](mailto:legal@visibility.cloud).
We verify identity before acting, respond within the time the applicable law
sets, and never charge for a first request or treat you differently for making
one.

## 8. Security

Data is encrypted in transit. Access is credentialed and logged. If a breach
affects your personal information, we notify you and the required regulators
within the deadlines applicable law sets.

## 9. Children

The services are not directed to children under 13, and
we do not knowingly collect their personal information. If you believe a child
has provided us personal information, contact [legal@visibility.cloud](mailto:legal@visibility.cloud) and we
will delete it.

## 10. Changes

When this policy changes we post the new version with a new effective date. For
material changes we give prominent notice before the change takes effect. Where
a change requires consent, we obtain it first.

## 11. Contact

> **Visibility Cloud, Inc.**
> Email: [legal@visibility.cloud](mailto:legal@visibility.cloud)
> Disputes: [legal@visibility.cloud](mailto:legal@visibility.cloud)

This policy is a notice of our data practices, not a contract. The terms
governing use of the services — including governing law (the State of Delaware, United States)
and dispute resolution — are in the [terms of service](/terms/).