1. Who we are
Visibility Cloud, Inc. ("we") operates visibility.cloud. The services publish an item-level chain-of-custody record built on EPCIS 2.0 and CBV 2.0: written material, worked illustrative traces, and machine-readable surfaces addressed to software readers as much as to people, together with the developer and standards doors of the same family. The two doors a reader can use on the site are a segment seat list and a get-started interview.
This policy covers these surfaces:
- visibility.cloud
- epcis.dev
- transactions.dev
- barcoding.dev
- barcodes.do
Privacy questions go to legal@visibility.cloud.
2. What we collect
We collect the categories below. This table is the complete list.
| Category | What it contains | Why we collect it |
|---|---|---|
| What you tell us | the email address you give the seat list or the get-started interview, the segment you choose, the answers you give, anything you type into a free-text field, the ending the interview reached and the receipt token this origin mints for that row, the month a conversation was requested, and whatever you write to us directly | answering you, and following up about the thing the address was given for |
| The network a request came from | the IP address and its network prefix, the autonomous system number, the organization that operates that network, and the addresses any proxy in front of you declared it was forwarding for — kept beside the address the network itself observed, not in place of it | operating and securing the services, and understanding which organizations read them |
| Approximate location, derived from that network | country, region and its standard code, city, metro area, postal area, time zone and continent, plus the data center that served the request, and an approximate point on the map worked out from the same address — recorded as the estimate it is, with the method that produced it and the fact that no accuracy figure came with it. One network’s estimate about another, never a device location | understanding readership, and detecting abuse that clusters by place |
| A first-party identifier, outside the EU | one cookie named _id, holding a random identifier and nothing else — no name, no address, nothing you typed. It lasts two years, is sent only back to this origin, and page scripts cannot read it. Visitors Cloudflare places in the EU are not given it at all | telling a returning visit from a new one when the network underneath you changes — mobile to wifi, office to home — which the address and the network number cannot do |
| Device, connection and automation signals | the user agent, the HTTP protocol, the TLS version and cipher and fingerprints computed from the shape of the TLS handshake, round-trip time, language and content preferences, client hints, the names and order of the headers your client sent — never their values — the platform’s bot score and its JA3/JA4 handshake fingerprints where the plan supplies them, and our own typed judgment of the caller — a person, a known AI agent, a verified crawler, a suspected scraper, or unknown — with the signals behind it and the version of the judgment that made it | telling human readers from automated ones, and stopping abuse, scraping and attack traffic |
| Privacy preferences you send | whether your request carried a Do Not Track or Global Privacy Control header | so a preference we are asked to honor is one we actually wrote down |
| What was requested, and what was returned | the method, path, query string, response status, which representation was served, the declared type and size of anything submitted — never its contents — and the moment | operating the services and reading traffic over time |
| How the request arrived | the referring page and its host, the origin a machine-to-machine call declared, the relationship the browser declares between that page and ours, whether the browser fetched the page speculatively rather than because you asked for it, and any campaign tags on the address | understanding what brings readers here — and not counting a browser’s guess as somebody reading |
| A verified identity, where one is offered | if a caller signs its request, the signature, what it covers, and the address saying whose key it is; if a request arrives signed in, the account and organization identifiers and a SHA-256 of your lower-cased address — never the address, and never a display name | knowing which callers can be held to what they claim, rather than taking every claim on trust |
| The join key, where there is one | a receipt token this origin minted, or a SHA-256 of your lower-cased address — never the address itself. Request bodies, form fields, Authorization headers, any cookie other than the one named above, and the value of any header not named above are never recorded at all | connecting a request to something you gave us, without putting your address in the request log |
| Aggregate site analytics | Cloudflare Web Analytics measurements: pages read, how readers arrive, and general traffic patterns, reported in aggregate and without cookies | understanding how the services are used |
3. How we use it
We use personal information to provide the services, keep them secure, keep required records, and comply with law — the purposes stated in the table above, and nothing else.
We do not sell personal information. We do not build advertising profiles. We do not use personal information to train machine-learning models.
4. Who processes it for us
These are the vendors and affiliates that process personal information on our behalf, and what each one does. This list is the complete list.
| Processor | Role | Note |
|---|---|---|
| Cloudflare | hosting, edge network and security; the runtime the services execute in, the databases they write to, and Cloudflare Web Analytics | The services run on a global network, so information about your use of them may be processed outside your own country, including in the United States. Cloudflare also keeps its own short-retention log of requests, as it does under any site on its network. |
| Slack | notifying our own team when someone joins the seat list or completes the interview | The notification carries what you typed — the address, the segment and the answers — and nothing derived from the request. |
| Google Workspace | the mailboxes on these domains: email you send us and email we send you |
Each processor is bound by contract to process personal information only to provide its service to us.
5. How long we keep it
| Data | Kept for | Because |
|---|---|---|
| The IP address on a request record | thirty days | investigating abuse and attack traffic while it is still live |
| The rest of a request record | four hundred days | reading readership — in particular automated readership — across a full year and its comparison year |
| The seat list, the interview, requested conversations, and correspondence | while we are in touch with you about what you gave the address for, and deleted when you ask | following up about the thing you asked for |
When a period ends we delete the data or irreversibly anonymize it.
6. Email
We send transactional email (service notices) and, with your consent, marketing email. Every marketing email carries an unsubscribe link, and unsubscribing is immediate.
7. Your rights
Where the law where you live grants you rights over your personal information — access, correction, deletion, portability, objection, or others — we honor them. Send requests to legal@visibility.cloud. We verify identity before acting, respond within the time the applicable law sets, and never charge for a first request or treat you differently for making one.
8. Security
Data is encrypted in transit. Access is credentialed and logged. If a breach affects your personal information, we notify you and the required regulators within the deadlines applicable law sets.
9. Children
The services are not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact legal@visibility.cloud and we will delete it.
10. Changes
When this policy changes we post the new version with a new effective date. For material changes we give prominent notice before the change takes effect. Where a change requires consent, we obtain it first.
11. Contact
Visibility Cloud, Inc. Email: legal@visibility.cloud Disputes: legal@visibility.cloud
This policy is a notice of our data practices, not a contract. The terms governing use of the services — including governing law (the State of Delaware, United States) and dispute resolution — are in the terms of service.