Scope of this notice
This notice explains how LegitVerif collects, uses, stores and discloses personal information in connection with legitverif.com and any related pages, forms or mailing lists (together, the Service). It applies to all users, whether they read published entries or make contact with us. It does not apply to any external website reached through a link on legitverif.com.
The controller is the operator of LegitVerif. Questions may be sent to contact@legitverif.com. This version is current for 2026 and replaces any earlier notice published on the Service.
Categories of personal information
The table below sets out every category of personal information the Service handles, where it comes from and why it is held. Nothing outside these categories is collected deliberately.
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Identity details | Name or alias supplied in a form field | Provided by the user | Addressing correspondence and matching later messages to an existing thread |
| Contact details | Email address, optional telephone number, country of residence | Provided by the user | Replying to enquiries and, where requested, arranging an introduction |
| Report content | Free text describing an incident, names of operators, dates, screenshots or documents attached by the user | Provided by the user | Assessing the report, informing editorial research, and answering the user |
| Technical data | IP address, browser and device type, operating system, referring page, pages viewed, timestamps | Collected automatically by the web server and analytics tags | Delivering pages, security logging, abuse prevention and audience measurement |
| Cookie identifiers | Session identifier, consent record, analytics identifier | Set by the Service or by an analytics provider | Session continuity, storing the user preference, aggregate statistics |
| Correspondence | Emails to and from contact@legitverif.com, including attachments | Provided by the user | Handling the enquiry and keeping a record of it |
| Subscription data | Email address and subscription status on an alerts list | Provided by the user | Sending the warnings the user asked to receive |
Users are asked not to submit banking credentials, passwords, wallet seed phrases, identity document scans or health information. Such material, if it arrives, is deleted on sight and never entered into any record system.
Lawful basis for each activity
Processing on the Service rests on three bases. Consent covers analytics cookies, subscription emails and any introduction to an independent legal adviser. Legitimate interests covers server logging, security, abuse prevention, editorial research into reported operators and ordinary correspondence with a user who has written in. Legal obligation covers retention or disclosure where a court order, statutory notice or binding regulatory request applies.
Where legitimate interests are relied on, LegitVerif has weighed the interest of publishing accurate warnings about online financial fraud against the privacy expectations of the individuals concerned. A user who disagrees may object by writing to contact@legitverif.com.
The contact form and referral to an independent adviser
The form on legitverif.com exists so that a person affected by a fraudulent operator can describe what happened and ask questions. Submission is voluntary and only the fields marked as required must be completed.
LegitVerif is a publisher. It does not act for users, does not represent them before any body, and does not handle money on their behalf. Where a user asks for it, and only after a clear and separate instruction, a summary of the report may be passed to an independent legal adviser or law firm so that the user can be contacted about reporting procedures to regulators and authorities. Consent may be withdrawn at any point before the introduction is made.
Advisers introduced in this way are separate practices with their own privacy notices. Once an introduction has occurred, the adviser is a controller in its own right, and enquiries about its handling of personal information go to that practice.
Cookies and similar technologies
Cookies are small files stored by the browser. The Service uses the minimum set below and operates no advertising or cross site tracking cookies.
| Cookie type | Purpose | Duration | Can it be refused |
|---|---|---|---|
| Strictly necessary | Maintains the session, protects forms against automated abuse, keeps pages loading correctly | Session, deleted when the browser closes | No, the Service will not function without it |
| Consent record | Remembers the choice a user made in the cookie banner so the banner is not shown repeatedly | Twelve months | No, but it stores only a preference value |
| Analytics | Counts visits, measures which entries are read, records approximate country and device class | Up to twenty four months | Yes, refuse in the banner or clear cookies at any time |
| Embedded media | Set by a video or map provider when such content appears in an entry | Set by that provider | Yes, by declining the embed |
| Preference | Stores display choices such as text size or theme | Six months | Yes, with no loss of core function |
Browser settings can block or delete cookies for legitverif.com entirely. Doing so may mean a preference is asked for again on each visit.
How long records are kept
Nothing is kept indefinitely. Each record type has a defined period and a defined event that starts the clock.
| Record | Retention period | Trigger for deletion |
|---|---|---|
| Contact form submission with no reply requested | Six months | Date of submission |
| Correspondence thread with a user | Twenty four months | Date of the last message in the thread |
| Report passed to an independent adviser with consent | Thirty six months | Date the introduction was made |
| Server access logs | Ninety days | Date the log line was written |
| Analytics data in aggregate form | Twenty six months | Date of collection |
| Alerts list subscription | Until unsubscribe, then thirty days | Unsubscribe request |
| Records subject to a legal hold | Until the hold is lifted | Written release of the hold |
Who receives personal information
Personal information is never sold, rented or traded. Disclosure is limited to the recipients below.
| Recipient type | Example | What is shared | Basis |
|---|---|---|---|
| Hosting provider | The company operating the servers behind legitverif.com | All data stored on the platform, at rest | Processor under written contract |
| Email provider | The mailbox service behind contact@legitverif.com | Message content and sender details | Processor under written contract |
| Analytics provider | An audience measurement service | Technical data and page view events | Consent |
| Independent legal adviser | A law firm assisting with reports to regulators | Contact details and the report summary only | Explicit instruction of the user |
| Professional advisers | Lawyers or insurers acting for LegitVerif | Only what is relevant to the matter | Legitimate interests |
| Authorities | A regulator, police force or court | Only what the notice or order requires | Legal obligation |
Rights and how to exercise them
Depending on where a user lives, the following rights may apply: access to a copy of the personal information held, correction, erasure, restriction of processing, objection to processing based on legitimate interests, portability, and withdrawal of consent. Rights are not absolute and some are limited where a publisher relies on freedom of expression protections.
- Send the request to contact@legitverif.com with the words data request in the subject line.
- State which right is being exercised and which records it concerns.
- Supply enough to link the request to an existing record, usually the email address originally used.
- Expect an acknowledgement within seven days and an answer within one month.
- Where a request is refused, the refusal will name the exemption relied on.
A user who is not satisfied may complain to the data protection supervisory authority in their country of residence. Doing so does not remove the option of raising the matter with LegitVerif first.
Security
The Service runs over encrypted connections. Administrative access is limited to the few people who need it, protected by strong credentials and second factor authentication. Attachments are scanned before being opened. Backups are encrypted and access to them is logged.
No system is perfect. If a breach occurs that is likely to risk the rights of users, the supervisory authority is notified within the statutory window and affected users told directly where the risk is high.
International transfers and children
Some providers operate servers outside the country where a user lives. Where personal information moves across borders it is protected by an adequacy decision, by standard contractual clauses, or by an equivalent safeguard permitted under the applicable law. The mechanism relied on for a named provider may be requested at contact@legitverif.com.
The Service is written for adults. It is not directed at children and no part of it is designed to attract them. Users under sixteen should not submit personal information through any form on legitverif.com. If a child has done so, the record is deleted promptly and any introduction request based on it is cancelled.
Changes to this notice
This notice is reviewed at least once each calendar year and whenever the Service changes in a way that affects personal information. The version in force is the one published on legitverif.com, and the effective date on the page shows when it took effect. During 2026 any material change is flagged on the page for a reasonable period.
Continued use after a change takes effect indicates acceptance. Users who object may stop using the Service and ask, at contact@legitverif.com, for any record held about them to be deleted, subject to the retention rules above.
