VeriField ("we", "us", "our") operates the VeriField mobile applications and the web platform at verifield.com.ng, including the organisation console and related APIs at api.verifield.com.ng. This Privacy Policy explains what information we collect, why we collect it, how it is stored, and the choices available to you.
VeriField is designed for zero-trust field verification—especially election result capture and corporate field accountability in Africa. Some data (such as sealed verification evidence) is intentionally immutable for integrity and legal defensibility.
1. Who this applies to
- Field agents using the VeriField iOS or Android app to capture and submit verified reports (for example EC8A result sheets or site visit evidence).
- Organisation administrators using the VeriField web console to manage staff, review submissions, run war-room operations, and export evidence.
- Platform operators (VeriField super administrators) who configure system-wide settings.
2. Information we collect
Account & identity
- Name, email address, organisation/tenant assignment, and role.
- Authentication credentials, session tokens, and (where enabled) email OTP / MFA codes.
- Device binding identifiers used to associate an agent account with a single approved handset.
Field capture & evidence data
- Photographs captured through the in-app live camera (gallery import is not permitted for primary evidence capture).
- On-image watermarks containing GPS coordinates, accuracy estimates, timestamps, and assigned location / polling unit identifiers.
- Cryptographic signatures, SHA-256 hashes, previous-hash chain values, and related integrity metadata for each submission.
- Optional OCR / AI extraction outputs derived from submitted images (for example EC8A party totals), which may be reviewed and corrected by authorised reviewers.
Technical, diagnostics & analytics
- App version, OS version, and basic device integrity / attestation signals.
- Server logs (IP address, request timestamps, error diagnostics) for security and reliability.
- Crash and usage analytics (for example Firebase Crashlytics / Analytics) to improve stability—collection is configured according to platform release settings.
3. Camera, location, and device permissions (mobile)
The VeriField mobile apps request sensitive device permissions only to perform field verification. Apple App Store and Google Play reviewers should note the following precise uses:
Camera
- Purpose: live capture of EC8A forms, invoices, or other assigned field evidence with edge-aligned document scanning where enabled.
- Use:images are watermarked, cryptographically signed, uploaded to VeriField servers for the agent's organisation, and may be used to generate evidence certificates and audit trails.
- Not used for: unrelated advertising, social sharing, or continuous background camera recording.
Location (when in use / foreground)
- Purpose: prove the agent is physically present at the assigned polling unit or site; watermark captures; enforce proximity validation (approximately 20 metres).
- Collection timing: primarily while the agent is actively using capture flows in the foreground.
- Storage: coordinates, accuracy, and timestamps are stored with the verification record and may appear on certificates and admin dashboards.
Background location
- VeriField's core product requirement is location at capture time (foreground / when in use). If a future release enables limited background location (for example offline sync reliability or continuity of a capture session), that use will remain limited to verification integrity and will be disclosed in an updated Privacy Policy and in-app permission prompts before collection expands.
- We do not sell location data and do not use location for third-party advertising.
Device identifiers
- Used to bind an agent to one device, reduce cloning/emulator abuse, and support security attestation.
- Combined with account credentials to prevent unauthorised multi-device access to the same field agent profile.
4. How we use information
- Authenticate users and enforce device binding for field agents.
- Validate proximity, signatures, and integrity before accepting submissions.
- Store verification records for organisational review, war-room operations, and EC8A rollups.
- Generate Section 84-style evidence certificates and hash-chain audit exports.
- Detect fraud, abuse, and security incidents; maintain platform reliability.
- Provide customer support to organisations and (where appropriate) agents.
5. Legal bases (where applicable)
We process data to perform our contract with your organisation, to comply with legal obligations, and where necessary for legitimate interests in securing field evidence and preventing election or corporate fraud. Organisations deploying VeriField remain responsible for informing their agents of the lawful basis applicable in their jurisdiction (including Nigerian data protection requirements where relevant).
6. Sharing & disclosure
- Within your organisation: tenant administrators and authorised reviewers can access submissions for their organisation.
- Service providers: infrastructure, email delivery, analytics/crash reporting, and AI extraction providers process data only to deliver the Service under contractual controls.
- Legal: we may disclose information if required by law, court order, or to protect rights, safety, and the integrity of sealed evidence.
- No sale of personal information: we do not sell personal data for advertising.
7. Data retention
- Account profile data is retained while the account is active and for a reasonable period afterward for security, dispute resolution, and legal compliance.
- Verification evidence, cryptographic receipts, and hash-chain records may be retained for longer periods—including after account deactivation—because immutability and auditability are core product and legal features. Where deletion of an account is requested, we remove or de-identify personal account identifiers where feasible, while sealed evidence required for organisational or legal integrity may persist in anonymised or organisation-controlled form.
8. Security
We use industry-standard controls including encrypted transport (HTTPS/TLS), access controls, device binding, cryptographic signatures, and append-oriented evidence storage. No method of transmission or storage is 100% secure; organisations must also protect admin credentials and review permissions carefully.
9. Your rights
Depending on applicable law, you may request access, correction, or deletion of personal account data, or raise a complaint with your organisation or a supervisory authority. Field agents should usually start with their organisation administrator. Account deletion instructions are published at verifield.com.ng/delete-account.
10. Children
VeriField is not directed to children under 16. We do not knowingly collect personal information from children under 16.
11. International processing
Data may be processed on servers or by providers located outside your country. We take steps appropriate to the sensitivity of verification evidence and contractual relationships with processors.
12. Changes
We may update this Policy to reflect product, legal, or operational changes. The "Last updated" date will change when we do. Material changes will be highlighted on this page or communicated to organisation administrators where appropriate.
13. Contact
Privacy questions: privacy@verifield.com.ng
Support: verifield.com.ng/support
