All policies

Subprocessors

Last updated: July 19, 2026

Verrim uses the following subprocessors to run the Service. Each is bound by terms that limit its use of customer data to providing its service to us. We will update this page before making material changes, and business customers can ask to be notified of changes by emailing hello@verrim.com.

Current subprocessors

Supabase — database, authentication, and file storage for the Service, including certificate files.

Google (Gemini API, paid tier) — AI-assisted reading of certificates and in-product assistance. We do not allow certificate data to be used to train Google’s models.

Groq — backup AI provider for Ask Verrim, our in-product help assistant. Receives the text of help questions only — never certificate files or customer records — when our primary provider is unavailable.

Stripe — payment processing. Card details go to Stripe directly and never touch Verrim’s servers.

Resend — transactional email delivery, such as certificate requests and reminders.

Vercel — application hosting and content delivery.

PostHog — product analytics. Receives usage events and account identifiers only — never certificate contents, customer names, or tax identification numbers.

Government verification sources

When you use permit verification, Verrim queries the relevant state’s public verification source (currently Texas, Iowa, and North Carolina). These are government data sources, not subprocessors. When you connect a store such as Shopify, data flows between Verrim and that platform under your agreement with it.

Contact

hello@verrim.com.

History

  • July 11, 2026First published.
  • July 19, 2026Groq added: backup AI provider for Ask Verrim help questions.