Jump to section
Privacy Policy
Effective October 4, 2026
This Privacy Policy explains how 4Sure Technologies LLC, which operates Authentify ("Authentify," "we," "us"), handles information in connection with the Authentify API, dashboard, consent widget, and related services (the "Service"). It is written for two different audiences, described separately below: our business customers, and the retail end users our customers' agents may act on behalf of.
1. If you are a business customer (or someone at one)
When your organization signs up for Authentify, we collect the information needed to create and run your account: company name, contact name and email, password (stored as a salted hash, never in plain text), billing address, and billing details handled directly by Stripe (we do not store card numbers).
We also log activity you generate through the dashboard and API: agents and rules you configure, authorization requests and decisions, and administrative actions like inviting operators or approving transactions. We use this information to operate the Service, bill you, respond to support requests, and secure the platform, including through the rate-limiting and anomaly-detection checks described on our Trust & Security page.
We do not sell this information, and we do not use it to train models outside of operating and improving the Service.
2. If you were shown the Authentify consent widget
If one of our customers' agents needs your approval to act on your behalf, you may see the Authentify consent widget embedded in that customer's app. In that flow, we are a data processor acting on our customer's instructions, not the party you have a direct relationship with; that customer, and its own privacy policy, governs the underlying relationship with you.
What we process is limited to: the identifier your bank or fintech assigns you (referred to in our API as end_user_id), which is opaque to us and set by them, not something we collect independently; the scope and expiration of the consent you grant or decline; and, if step-up identity verification is used, a redirect through your own institution's authentication flow, the credentials for which we never see.
We retain consent records for as long as the underlying agent relationship is active, plus the period needed for audit and dispute purposes described in Section 5. You can ask the institution that showed you the widget to revoke your consent at any time; revocation takes effect on that agent's next authorization check.
3. What we don't collect
We don't require or store government ID numbers, account numbers, or transaction contents beyond what a customer chooses to pass us as part of an authorization request, for example a transaction amount or entity identifier needed to evaluate a rule.
We don't track individuals across unrelated websites, and the Service does not use advertising cookies.
4. Subprocessors
We use the following subprocessors to run the Service: Vercel (application hosting, storage for documents you upload, and site analytics and performance monitoring); Supabase (Postgres database hosting); Redis Ltd., through Redis Cloud (short-lived consent-session data and rate-limit counters); Stripe (billing and payment processing); Resend (transactional email); and Chatbase (the support chat assistant on our website and dashboard). When the assistant loads, Chatbase receives standard request data such as your IP address and browser details, plus anything you type into it. It is never loaded on end-user approval pages or in the consent widget. Each is bound by its own data processing terms; Vercel's are summarized on our Trust & Security page.
To make audit records independently verifiable, we send a cryptographic hash of each batch of records to FreeTSA, a public timestamping authority. FreeTSA receives only that hash, never the records themselves or any personal data. We will update this list before adding a new subprocessor.
5. Retention and deletion
Account and billing information is retained for as long as your account is active and for a limited period after closure for legal, tax, and audit purposes. Authorization audit logs are retained per the regulatory retention windows referenced on our Trust & Security page.
You can request deletion of account data that we are not otherwise required to retain by contacting us at the address below.
6. Security
We use encryption in transit and at rest, scoped API keys, and continuous monitoring for anomalous activity. Full detail is on our Trust & Security page.
7. Your rights
Depending on where you're located, you may have rights to access, correct, or delete personal data we hold, or to object to certain processing. Business customers can exercise these rights for their own account data directly through the dashboard, or by contacting us.
Retail end users should start with the institution that showed them the widget, since that institution controls the underlying data; we will support their request wherever we are the ones holding the relevant data.
8. Children
The Service is not directed to, and we do not knowingly collect information from, individuals under 18.
9. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected in the effective date above and, for business customers, communicated to the contact on file.
10. Contact
Questions about this policy, or requests regarding your data, can be sent to legal@authentify.bz.