Verify Way: WhatsApp OTP API Provider

Privacy Policy

Last updated: September 26, 2026

This Privacy Policy explains how VerifyWay collects, uses, stores and discloses personal information when you visit our website, maintain a business account or use our messaging and authentication services. It also explains how we process recipients’ information on behalf of our business customers.

1. Who We Are

VerifyWay is operated by VERIFYWAY, registered in Erbil, Iraq under Registration No. ER365663322, with registration approved on February 15, 2026.

VerifyWay was previously operated by Standing Company and is now registered separately. The companies have common ownership. VerifyWay also maintains a US presence at 5B Stillwell Dr, Salem, Massachusetts, United States. That US address does not replace the Iraqi company details identified above.

2. Scope and Our Role

In this policy, “VerifyWay,” “we,” “us” and “our” refer to the company identified above. “Personal data” means information relating to an identified or identifiable person. “Business customer” means an organization or individual using VerifyWay to send messages or authentication codes. “Recipient” means a person receiving a message through our services.

For website, account administration and business-contact information, we determine how information is used for the purposes explained in this policy. For recipient information submitted by a business customer for message delivery or authentication, we act as a service provider processing that information on the customer’s behalf and according to its instructions.

The business customer is responsible for the purpose of its messages, the lawfulness of its instructions, and providing appropriate privacy information and obtaining any required permissions from recipients. If you receive a code from an organization using VerifyWay, that organization’s privacy policy also applies to its handling of your information.

3. Information We Collect and Process

Business Account and Contact Information

When you create an account, contact us or use our services as a business customer, we may collect information you provide, including your name, business name, email address, phone number, address and support correspondence.

WhatsApp Authentication Data

For our WhatsApp one-time password (OTP) service, the recipient message records we process contain:

  • The recipient’s phone number.
  • The OTP or login code submitted to or generated by the service.
  • The message ID returned by Meta for the WhatsApp message.

We receive the recipient’s phone number and any customer-supplied code from the business customer, rather than collecting them directly from the recipient. Our authentication service does not require clinical records or other health details. Customers should not include unnecessary personal information in authentication requests.

Website and Technical Information

When you use our website or account interface, we may collect technical information such as your IP address, browser type, operating system, pages visited, access times and diagnostic information. This website and account information is separate from the recipient fields described above.

Third-Party Sign-In

If you choose a third-party sign-in option available through our service, we may receive information made available by that provider according to the permissions shown during sign-in, such as your name, email address and account identifier. The provider’s own privacy policy also applies.

4. How We Use Information

We use business-account, contact and technical information to:

  • Create and administer customer accounts and provide the requested services.
  • Respond to enquiries and provide technical support.
  • Communicate service changes, account information and security notices.
  • Maintain and improve website and service functionality.
  • Protect our systems, prevent misuse and investigate technical or security issues.
  • Meet applicable legal obligations and manage contractual matters.

Where permitted by applicable law and subject to any required consent, we may send business customers information about our services. You may opt out of promotional communications by following the instructions provided or contacting us. Necessary account and service notices may still be sent.

Recipient phone numbers and OTP codes are processed to provide the customer’s requested authentication service and necessary support and security. We do not use these recipient records for our own advertising or promotional campaigns, or sell them.

5. Cookies and Similar Technologies

Our website uses cookies and similar technologies for functions such as maintaining sessions, authenticating account users, remembering preferences and recording privacy choices. These may include session cookies, which expire when you close your browser, and persistent cookies, which remain until they expire or are deleted.

Where used, analytics technologies and email beacons may provide information about website activity or whether communications have been opened. Where applicable law requires consent for non-essential technologies, that consent must be obtained before they are used.

You can manage or delete cookies through your browser settings and use any privacy controls provided on our website. Blocking necessary cookies may affect account access or other functions.

6. Service Providers and Disclosures

The providers involved in our WhatsApp authentication service include:

  • Hetzner: provides the hosting infrastructure in Germany on which our service data is stored.
  • Meta and WhatsApp: provide WhatsApp delivery through the Meta WhatsApp Cloud API. The recipient’s phone number and code are transmitted for delivery, and a Meta message ID is returned.

These providers process information under the terms applicable to their services. Their own processing locations, retention practices and legal responsibilities may differ from those of VerifyWay. Our German hosting location does not mean that all Meta or WhatsApp processing takes place in Germany.

Other providers may process website or business-account information where necessary to support the relevant function. Common ownership with another company does not, by itself, authorize unrestricted access to recipient information.

We may disclose information where required by applicable law or a valid legal request, or where lawfully necessary to protect rights, investigate misuse or address security incidents. Any disclosure of customer-controlled recipient information remains subject to applicable law and our obligations to that customer.

If our business undergoes a merger, acquisition or transfer, personal information may be transferred where lawful and subject to appropriate confidentiality and protection. We will provide notice where required.

7. Hosting and International Processing

Our service data is hosted by Hetzner in Germany. Authorized personnel may access systems remotely from Iraq and other locations where they work, using secured access controls. Remote access is distinct from the location where data is hosted.

Using our services may involve processing outside your country, including through Meta and WhatsApp. Applicable data-protection and international-transfer requirements must be addressed for the relevant service and customer. This policy does not replace any required contractual safeguards, regulatory notification or authorization.

8. Data Retention

WhatsApp OTP Records

We retain WhatsApp OTP records, including the recipient’s phone number, stored code and Meta message ID, for one year from the creation of each record. Records are then automatically deleted from our active database.

OTP codes expire after three minutes. Expiry means that a code is no longer valid for authentication; it does not mean that its stored content is immediately deleted. Stored code content is subject to the one-year retention period described above.

Backups

Our backups operate on a seven-day overwrite cycle. After a record is deleted from the active database, residual backup copies are overwritten within a further seven days.

These periods apply to records and backups under VerifyWay’s control. They do not determine Meta’s or WhatsApp’s separate retention periods or delete messages already delivered to recipients’ devices.

Account and Website Information

Business-account, contact and website information is retained for as long as necessary for the relevant purpose, including providing services, supporting accounts, protecting systems and meeting applicable legal obligations. The appropriate period depends on the type of information and the reason it is held.

9. Security and Confidentiality

We use technical and organizational safeguards to protect personal information. These include:

  • Encryption in transit and at rest.
  • Multifactor authentication (MFA) for administrative access.
  • IP allowlisting to restrict administrative connections.
  • Access restricted to authorized personnel for service-related purposes.
  • Encrypted backups.

Encryption at rest includes protection at the storage level. It does not prevent authorized applications and personnel from accessing information where needed to operate the service. No method of transmission or storage can guarantee absolute security.

10. Your Rights and Data Deletion

Depending on applicable law, you may have rights to access, correct or delete your personal information, restrict or object to certain processing, receive a portable copy of information, withdraw consent where processing relies on it, or complain to a competent data-protection authority.

To make a request concerning your VerifyWay account or information you supplied directly to us, email [email protected]. For account deletion, use the subject “Delete My Account” and identify the account concerned. Do not send passwords or active OTP codes.

We may request proportionate information to verify your identity or authority before acting. Some information may need to be retained where required or otherwise permitted by applicable law; we will explain any applicable limitation.

If your information was submitted by a business customer, please contact that organization first. We will assist the customer with applicable requests according to its instructions and our legal obligations. You may also contact us for assistance identifying the appropriate route.

11. Children’s Information

Our business-account services are intended for organizations and authorized business users, rather than for children to register independently. Business customers may serve recipients of different ages. Those customers are responsible for assessing requirements relating to children’s information and obtaining parental or other authorization where required. Concerns about a child’s information can be sent to [email protected].

12. Customer Processing Documentation

Business customers requiring a written data processing and confidentiality agreement or supporting information for a regulatory filing should contact [email protected]. This Privacy Policy explains our practices; it does not replace a separately executed agreement where one is required.

13. Links to Other Websites

Our website may contain links to third-party websites. Their operators are responsible for their own privacy practices. Please review their policies before providing information.

14. Changes to This Privacy Policy

We may update this policy to reflect changes to our services, practices or legal requirements. We will publish the revised version here and update the date above. Where required, we will provide additional notice or obtain consent before relevant changes take effect.

15. Contact Us

For privacy questions, data requests or processing documentation, contact:

VERIFYWAY
Registration No. ER365663322
Ankawa, 4 Towers, Tower A, Floor 8, Office 40B
Erbil 44003, Iraq
Email: [email protected]