Moveris, Inc. ("Moveris," "we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access and use the Moveris Developer Portal, dashboard, APIs, and related services (collectively, the "Services").

1. Scope and Application

This Privacy Policy applies to:

  • Personal information collected through the Developer Portal and dashboard.
  • Data collected in connection with API usage and authentication.
  • Communications with Moveris support and sales teams.

Dual Role Clarification:

  • For Developer Account Data: Moveris acts as a data controller
  • For End-User Data Processed via APIs: Moveris acts as a data processor, and you (the developer) act as the data controller

2. Information We Collect

Developer Account Information:

  • Identity data: Full name, email address, phone number, job title, organization name
  • Authentication credentials and security information
  • Billing and payment information (processed by third-party payment processors)
  • Professional profile information you choose to provide

API Usage and Technical Data:

  • API keys, authentication tokens, and access credentials
  • Usage metrics: Request volumes, response times, error rates, endpoint usage
  • Technical logs: IP addresses, user agents, timestamps, request/response metadata
  • Performance and availability monitoring data

Portal Usage Analytics:

  • Website analytics via cookies and similar technologies
  • Browser type, operating system, device identifiers
  • Navigation patterns, feature usage, and user interactions
  • Session duration and frequency of visits

Communications and Support:

  • Content of support tickets, chat sessions, and email correspondence
  • Feedback, surveys, and beta program participation
  • Marketing preferences and communication history

3. How We Use Your Information

We process your personal information for the following purposes:

Service Provision (Contractual Necessity):

  • Creating and managing your developer account

  • Providing access to APIs, documentation, and portal features

  • Processing API requests and delivering responses

  • Billing and payment processing for paid services

Security and Fraud Prevention (Legitimate Interest):

  • Monitoring for unauthorized access and suspicious activity

  • Detecting and preventing API abuse and rate limit violations

  • Maintaining system security and integrity

  • Conducting security audits and assessments

Service Improvement and Analytics (Legitimate Interest):

  • Analyzing usage patterns to improve Services performance

  • Developing new features and functionality

  • Conducting research and analytics on service usage

  • Optimizing user experience and interface design

Legal Compliance (Legal Obligation):

  • Complying with applicable laws, regulations, and legal processes

  • Meeting financial services and anti-money laundering requirements

  • Responding to lawful government requests and court orders

  • Maintaining records for audit and regulatory purposes

Marketing and Communications (Consent/Legitimate Interest):

  • Sending service announcements and important updates

  • Providing customer support and technical assistance

  • Marketing communications (with your consent where required)

  • Invitations to beta programs and user research

4. Legal Basis For Processing (GDPR)

For individuals in the EU/UK/EEA, we process personal data based on:

  • Contract Performance: To fulfill our obligations under the Terms of Service

  • Legitimate Interests: For security, fraud prevention, analytics, and business operations

  • Legal Compliance: To meet regulatory and legal obligations

  • Consent: For optional marketing communications and certain analytics

You may withdraw consent at any time where processing is based on consent.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share information in the following circumstances:

Service Providers and Partners:

  • Cloud infrastructure providers (AWS, Google Cloud, Microsoft Azure)

  • Analytics and monitoring services (with data processing agreements)

  • Payment processors for billing services

  • Customer support and communication platforms

  • Security and compliance service providers

  • Other services where necessary to execute our contractual obligations with you

Legal Requirements:

  • When required by law, regulation, or valid legal process

  • To protect the rights, property, or safety of Moveris, users, or the public

  • In connection with the investigation of suspected illegal activities

  • To enforce our Terms of Service and other agreements

Business Transactions:

  • In connection with mergers, acquisitions, or asset sales (with appropriate safeguards)

  • To successors or assigns in corporate restructuring

With Your Consent:

  • When you explicitly authorize us to share information

  • For specific purposes disclosed at the time of collection

6. International Data Transfers

Primary Processing Location: Data is primarily processed in the United States where our servers and primary operations are located.

International Transfer Safeguards: For transfers from the EU/UK/EEA, we implement appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission

  • Adequacy decisions where available

  • Additional technical and organizational measures as required

Data Processing Agreements: We will execute Data Processing Agreements (DPAs) with customers who act as data controllers for end-user data processed through our APIs.

7. Data Retention

Retention Principles: We retain personal information only as long as necessary for the purposes outlined in this Privacy Policy and as required by law.

Specific Retention Periods:

  • Active Account Data: Retained while your account is active and for legitimate business purposes

  • API Usage Logs: Retained for 2 years for security and analytical purposes

  • Support Communications: Retained for 3 years after issue resolution

  • Financial Records: Retained for 7 years as required by applicable accounting and tax laws

Data Deletion: Upon account closure, we will delete or anonymize your personal information within 90 days, except where retention is required by law or for legitimate business purposes such as fraud prevention.

8. Security Measures

Moveris implements comprehensive security measures consistent with SOC 2 Type II controls:

Technical Safeguards:

  • Encryption in transit using TLS 1.3 or higher

  • Encryption at rest using AES-256 or equivalent

  • Regular security assessments and penetration testing

  • Vulnerability management and patch deployment

  • Network security controls and monitoring

Administrative Controls:

  • Employee background checks and security training

  • Role-based access controls with principle of least privilege

  • Multi-factor authentication for administrative access

  • Regular access reviews and deprovisioning procedures

  • Incident response and disaster recovery plans

Physical Security:

  • Secure data centers with environmental and access controls

  • Redundant infrastructure and backup systems

Third-Party Audits: We undergo annual SOC 2 Type II audits by independent certified public accounting firms.

9. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

Access and Portability:

  • Right to access your personal data and receive a copy

  • Right to data portability in a structured, machine-readable format

Correction and Completion:

  • Right to correct inaccurate or incomplete personal data

  • Right to update your account information

Deletion and Restriction:

  • Right to erasure ("right to be forgotten") in certain circumstances

  • Right to restrict processing under specific conditions

Objection and Withdrawal:

  • Right to object to processing based on legitimate interests

  • Right to withdraw consent where processing is consent-based

Automated Decision-Making:

  • Right not to be subject to solely automated decision-making, including profiling

Exercising Your Rights: To exercise these rights, contact us at privacy@moveris.com. We will respond within one month as required by GDPR Article 12. We may require identity verification before processing requests.

10. Cookies and Tracking Technologies

Types of Cookies Used:

  • Essential Cookies: Necessary for portal functionality and security

  • Analytics Cookies: To understand usage patterns and improve services

  • Preference Cookies: To remember your settings and preferences

Cookie Management: You can manage cookie preferences through your browser settings. Note that disabling essential cookies may impair portal functionality.

Third-Party Analytics: We may use third-party analytics services (such as Google Analytics) with appropriate privacy safeguards and data processing agreements.

11. Children's Privacy

The Developer Portal is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to delete such information promptly. Developer assumes all responsibility, legal and otherwise, for any violation of children’s privacy laws related to Developer’s use of Services.

12. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to Know: Categories and specific pieces of personal information collected

  • Right to Delete: Request deletion of personal information

  • Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)

  • Non-Discrimination: We will not discriminate against you for exercising CCPA rights

To exercise these rights, contact us at privacy@moveris.com.

13. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify relevant supervisory authorities within 72 hours where required by law

  • We will notify affected individuals without undue delay when required

  • We will provide information about the nature of the breach and steps taken to address it

14. Privacy Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Notification of Changes:

  • Material changes will be communicated via email or prominent notice in the Developer Portal

  • We will provide the effective date of any updates

  • Continued use of the Services after changes constitutes acceptance of the updated Privacy Policy

15. Contact Information and Data Protection Officer

General Privacy Inquiries: Moveris, Inc.
3911 4th St., Lubbock, TX 79415
Email: privacy@moveris.com

Secure More Customers.
Stop More Fraud.

Protect your business with frictionless, psychophysiology-based verification that AI can’t fake.

Schedule a Demo