1. Who we are

Visibility Cloud, Inc. ("we") operates visibility.cloud. The services publish an item-level chain-of-custody record built on EPCIS 2.0 and CBV 2.0: written material, worked illustrative traces, and machine-readable surfaces addressed to software readers as much as to people, together with the developer and standards doors of the same family. The two doors a reader can use on the site are a segment seat list and a get-started interview.

This policy covers these surfaces:

  • visibility.cloud
  • epcis.dev
  • transactions.dev
  • barcoding.dev
  • barcodes.do

Privacy questions go to legal@visibility.cloud.

2. What we collect

We collect the categories below. This table is the complete list.

CategoryWhat it containsWhy we collect it
What you tell usthe email address you give the seat list or the get-started interview, the segment you choose, the answers you give, anything you type into a free-text field, the ending the interview reached and the receipt token this origin mints for that row, the month a conversation was requested, and whatever you write to us directlyanswering you, and following up about the thing the address was given for
The network a request came fromthe IP address and its network prefix, the autonomous system number, the organization that operates that network, and the addresses any proxy in front of you declared it was forwarding for — kept beside the address the network itself observed, not in place of itoperating and securing the services, and understanding which organizations read them
Approximate location, derived from that networkcountry, region and its standard code, city, metro area, postal area, time zone and continent, plus the data center that served the request, and an approximate point on the map worked out from the same address — recorded as the estimate it is, with the method that produced it and the fact that no accuracy figure came with it. One network’s estimate about another, never a device locationunderstanding readership, and detecting abuse that clusters by place
A first-party identifier, outside the EUone cookie named _id, holding a random identifier and nothing else — no name, no address, nothing you typed. It lasts two years, is sent only back to this origin, and page scripts cannot read it. Visitors Cloudflare places in the EU are not given it at alltelling a returning visit from a new one when the network underneath you changes — mobile to wifi, office to home — which the address and the network number cannot do
Device, connection and automation signalsthe user agent, the HTTP protocol, the TLS version and cipher and fingerprints computed from the shape of the TLS handshake, round-trip time, language and content preferences, client hints, the names and order of the headers your client sent — never their values — the platform’s bot score and its JA3/JA4 handshake fingerprints where the plan supplies them, and our own typed judgment of the caller — a person, a known AI agent, a verified crawler, a suspected scraper, or unknown — with the signals behind it and the version of the judgment that made ittelling human readers from automated ones, and stopping abuse, scraping and attack traffic
Privacy preferences you sendwhether your request carried a Do Not Track or Global Privacy Control headerso a preference we are asked to honor is one we actually wrote down
What was requested, and what was returnedthe method, path, query string, response status, which representation was served, the declared type and size of anything submitted — never its contents — and the momentoperating the services and reading traffic over time
How the request arrivedthe referring page and its host, the origin a machine-to-machine call declared, the relationship the browser declares between that page and ours, whether the browser fetched the page speculatively rather than because you asked for it, and any campaign tags on the addressunderstanding what brings readers here — and not counting a browser’s guess as somebody reading
A verified identity, where one is offeredif a caller signs its request, the signature, what it covers, and the address saying whose key it is; if a request arrives signed in, the account and organization identifiers and a SHA-256 of your lower-cased address — never the address, and never a display nameknowing which callers can be held to what they claim, rather than taking every claim on trust
The join key, where there is onea receipt token this origin minted, or a SHA-256 of your lower-cased address — never the address itself. Request bodies, form fields, Authorization headers, any cookie other than the one named above, and the value of any header not named above are never recorded at allconnecting a request to something you gave us, without putting your address in the request log
Aggregate site analyticsCloudflare Web Analytics measurements: pages read, how readers arrive, and general traffic patterns, reported in aggregate and without cookiesunderstanding how the services are used

3. How we use it

We use personal information to provide the services, keep them secure, keep required records, and comply with law — the purposes stated in the table above, and nothing else.

We do not sell personal information. We do not build advertising profiles. We do not use personal information to train machine-learning models.

4. Who processes it for us

These are the vendors and affiliates that process personal information on our behalf, and what each one does. This list is the complete list.

ProcessorRoleNote
Cloudflarehosting, edge network and security; the runtime the services execute in, the databases they write to, and Cloudflare Web AnalyticsThe services run on a global network, so information about your use of them may be processed outside your own country, including in the United States. Cloudflare also keeps its own short-retention log of requests, as it does under any site on its network.
Slacknotifying our own team when someone joins the seat list or completes the interviewThe notification carries what you typed — the address, the segment and the answers — and nothing derived from the request.
Google Workspacethe mailboxes on these domains: email you send us and email we send you

Each processor is bound by contract to process personal information only to provide its service to us.

5. How long we keep it

DataKept forBecause
The IP address on a request recordthirty daysinvestigating abuse and attack traffic while it is still live
The rest of a request recordfour hundred daysreading readership — in particular automated readership — across a full year and its comparison year
The seat list, the interview, requested conversations, and correspondencewhile we are in touch with you about what you gave the address for, and deleted when you askfollowing up about the thing you asked for

When a period ends we delete the data or irreversibly anonymize it.

6. Email

We send transactional email (service notices) and, with your consent, marketing email. Every marketing email carries an unsubscribe link, and unsubscribing is immediate.

7. Your rights

Where the law where you live grants you rights over your personal information — access, correction, deletion, portability, objection, or others — we honor them. Send requests to legal@visibility.cloud. We verify identity before acting, respond within the time the applicable law sets, and never charge for a first request or treat you differently for making one.

8. Security

Data is encrypted in transit. Access is credentialed and logged. If a breach affects your personal information, we notify you and the required regulators within the deadlines applicable law sets.

9. Children

The services are not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact legal@visibility.cloud and we will delete it.

10. Changes

When this policy changes we post the new version with a new effective date. For material changes we give prominent notice before the change takes effect. Where a change requires consent, we obtain it first.

11. Contact

Visibility Cloud, Inc. Email: legal@visibility.cloud Disputes: legal@visibility.cloud

This policy is a notice of our data practices, not a contract. The terms governing use of the services — including governing law (the State of Delaware, United States) and dispute resolution — are in the terms of service.