This Privacy Policy describes how DevizeScore(“DevizeScore”, “we”, “us”, “our”) collects, uses, shares, and protects information in connection with:
- the website https://devizescore.com(the “Website”);
- the DevizeScore merchant dashboard and APIs (the “Platform”); and
- the DevizeScore SDKs for Android, iOS, and Web (the “SDK”) integrated into our customers’ applications.
DevizeScore is currently operated by its founding team, pending incorporation of the DevizeScore operating entity. Upon incorporation, this Policy will be automatically assumed by that entity, and references to “DevizeScore”, “we”, “us”, and “our” will refer to it.
If you do not agree with this Policy, please do not use the Website, Platform, or applications that integrate the SDK.
1. Who we are and our roles
DevizeScore is a real-time device intelligence and decisioning platform. We help businesses (“Merchants”) assess device risk, prevent fraud, and make trust, credit, and recovery decisions.
We act in two distinct capacities:
| Context | Our role |
|---|---|
| Website visitors, dashboard users, sales leads | Data Fiduciary / Controller — we decide how and why data is processed |
| Device and behavioral signals collected via the SDK inside a Merchant’s app | Data Processor / Service Provider — we process data on behalf of, and under the instructions of, the Merchant |
Where we act as a processor, the Merchant is responsible for providing notice to and, where required, obtaining consent from its end users. Requests concerning SDK data should be directed to the relevant Merchant; we will support the Merchant in fulfilling them.
2. Information we collect
2.1 Information you provide directly
- Account and dashboard data: name, business email address, organization name, and role, collected when you register for or are invited to the DevizeScore dashboard.
- Sign-in data via Google SSO: if you sign in with Google, we receive your name, email address, and profile picture from your Google account. We do not receive your Google password.
- Contact and lead data: name, email, company, and message contents when you submit our contact form or communicate with us.
- Billing data: invoicing details for paid plans (we do not store full payment card numbers).
2.2 Information collected automatically (Website and Platform)
- IP address, browser type, operating system, referring pages, and usage events;
- cookies and similar technologies used for authentication, security, and analytics (see Section 8).
2.3 Information collected via the SDK (on behalf of Merchants)
When a Merchant integrates the SDK into its application, the SDK collects technical signals used to compute a device fingerprint and risk assessment, which may include:
- Device signals: device model, operating system and version, hardware and configuration attributes, platform identifiers, emulator/root/jailbreak indicators, and installed-application indicators limited to fraud-relevant package checks;
- Network signals: IP address, coarse IP-derived geolocation (country/region), network type, VPN/proxy/TOR indicators, and TLS/HTTP connection characteristics;
- Behavioral signals: interaction patterns such as touch, click, focus, typing cadence, copy/paste and autofill indicators, and motion-sensor characteristics. These signals are used solely to distinguish humans from automation and detect account-takeover patterns — they are not used to read the content of what a user types;
- Merchant-provided identifiers: pseudonymous user or session identifiers supplied by the Merchant.
The SDK does not collect message contents, contact lists, photos, files, or precise GPS location.
3. How we use information
We use the information described above to:
- provide, operate, secure, and improve the Platform and SDK;
- compute device identity, risk, credit, trust, and recovery scores and deliver decisioning outputs to the relevant Merchant;
- detect, investigate, and prevent fraud, abuse, account takeover, and security incidents;
- authenticate dashboard users and manage accounts;
- respond to inquiries and provide customer support;
- send service, security, and administrative communications;
- comply with applicable law, regulation, and lawful requests; and
- produce aggregated or de-identified analytics that do not identify any individual.
We do not sell personal data, and we do not use SDK-collected data for advertising or marketing purposes.
4. Google user data
If you sign in to the DevizeScore dashboard using Google:
- We request only the basic profile scopes: openid, email, and profile.
- We use this data solely to create and authenticate your dashboard account and display your identity within the Platform.
- We do not share Google user data with third parties except as required to operate the Platform (e.g., our authentication provider) or as required by law.
- We do not use Google user data for advertising, and we do not transfer it to data brokers.
DevizeScore’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Legal bases for processing
Depending on your location, we rely on the following legal bases:
- Consent— where required, including under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), obtained by us (for Website/Platform data) or by the Merchant (for SDK data);
- Legitimate uses / legitimate interests — fraud prevention, network and information security, and service operation;
- Contract — to provide the Platform to you or your organization;
- Legal obligation — where processing is required by applicable law.
6. Sharing and disclosure
We share personal data only with:
- Merchants— decisioning outputs relating to sessions originating from that Merchant’s own application;
- Service providers (sub-processors) — cloud hosting and infrastructure, authentication, email delivery, and observability vendors, bound by contractual confidentiality and data-protection obligations;
- Professional advisers and authorities — where required by law, legal process, or to protect our rights, users, or the public;
- Corporate transactions — in connection with a merger, acquisition, or asset sale, subject to this Policy.
A current list of sub-processors is available on request at the contact address below.
7. International transfers
Our infrastructure is hosted with major cloud providers. Where personal data is transferred across borders, we apply appropriate safeguards consistent with applicable law, including contractual protections with our sub-processors.
8. Cookies
The Website and dashboard use:
- Strictly necessary cookies — session authentication, security, and CSRF protection;
- Functional cookies — preferences such as theme;
- Analytics cookies — aggregate usage measurement, where applicable.
You can control cookies through your browser settings; disabling necessary cookies may prevent sign-in.
9. Data retention
- Account data: retained while your account is active and for a reasonable period thereafter as required for legal and audit purposes;
- SDK and decisioning data: retained per our agreement with the relevant Merchant and our fraud-prevention retention schedule; operational event logs are retained on a rolling basis (currently 90 days of hot retention) before archival or deletion;
- Lead and contact data: retained as long as necessary to handle your inquiry and for legitimate business follow-up.
When data is no longer needed, it is deleted or irreversibly de-identified.
10. Security
We employ industry-standard technical and organizational measures, including encryption in transit (TLS) and at rest, mandatory request-level payload encryption for SDK submissions, API authentication with signed requests and replay protection, role-based access controls, network isolation, audit logging with tamper-evidence, and periodic security testing. No system is perfectly secure; we cannot guarantee absolute security.
11. Your rights
Subject to applicable law (including the DPDP Act and, where applicable, the GDPR), you may have the right to:
- access the personal data we hold about you;
- request correction or erasure;
- withdraw consent (where processing is based on consent);
- nominate another individual to exercise your rights (DPDP Act);
- lodge a grievance with us, or a complaint with the Data Protection Board of India or your local supervisory authority.
For SDK data processed on behalf of a Merchant, please contact that Merchant first; we will assist them in responding.
To exercise your rights, contact us at the address in Section 14.
12. Children
Our services are business tools and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified via the Website or by email. The “Last updated” date at the top reflects the latest revision. Continued use after changes take effect constitutes acceptance.
14. Contact and Grievance Officer
DevizeScore
Email: tech@devizescore.com
Grievance Officer (DPDP Act, 2023): Arindam Das, reachable at tech@devizescore.com
We will acknowledge and address grievances within the timelines prescribed by applicable law.