Privacy Policy
Effective July 3, 2026 · Version 1.0
01Who We Are
Digital Crossborder, operating the DODA Verify service at dodaverify.com, is responsible for the processing of your personal data. Our operations serve the U.S.–Mexico border corridor, including customers in the United States. Contact: customerservice@dodaverify.com
This Privacy Policy applies to all users of dodaverify.com, including users located in the United States. For users in Mexico, our Aviso de Privacidad (in Spanish) also applies.
02Information We Collect
We collect the following categories of personal information:
- Account information: Name, email address, and profile photo obtained from Google when you sign in with Google OAuth.
- Usage data: DODA document numbers (NI — Número de Integración) you submit for verification, query timestamps, and scan history.
- Alert contact information: If you subscribe to DODA status alerts, we collect your WhatsApp phone number or email address.
- Payment information: Subscription billing is handled by Stripe. We do not store payment card numbers. Stripe's privacy policy governs payment data.
- Technical data: IP address, browser type, device identifiers, cookies, and Firebase Cloud Messaging (FCM) tokens for push notifications.
We do not sell your personal information to third parties.
03How We Use Your Information
- To authenticate you and maintain your account.
- To perform DODA status lookups on the Mexican SAT (Tax Authority) system on your behalf.
- To send you DODA status change alerts via WhatsApp, email, or push notification when you opt in.
- To process subscription payments through Stripe.
- To improve the service, fix bugs, and monitor for abuse.
- To comply with legal obligations in Mexico and the United States.
04Email Communications (CAN-SPAM Act)
If you subscribe to DODA email alerts, you will receive transactional messages related to your tracked shipments. These emails will:
- Identify DODA Verify (customerservice@dodaverify.com) as the sender.
- Include a clear description of the alert content in the subject line.
- Include an unsubscribe mechanism in each message.
To opt out of email alerts at any time, click the unsubscribe link in any alert email, or contact us at customerservice@dodaverify.com. We will process opt-out requests within 10 business days as required by the CAN-SPAM Act.
05California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request a copy of the personal information we have collected about you in the past 12 months.
- Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
- Right to Correct: You may request correction of inaccurate personal information we hold about you.
- Right to Opt Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is required, but you may confirm this at any time by contacting us.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide the service.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
Do Not Sell or Share My Personal Information: DODA Verify does not sell or share your personal information with third parties for their direct marketing purposes.
To exercise your CCPA/CPRA rights, submit a verifiable consumer request to: customerservice@dodaverify.com with subject line "CCPA Rights Request." We will respond within 45 days (extendable by an additional 45 days with notice).
06Data Sharing and Third Parties
We share your data only with infrastructure, authentication, payment, and communications providers necessary to operate the service, under confidentiality agreements. No provider is authorized to use your data for their own purposes. We do not sell, rent, or trade your personal information for marketing or advertising.
07Cookies and Tracking
We use essential cookies for authentication session management (next-auth session cookie). We do not use third-party advertising cookies or tracking pixels.
You may disable cookies in your browser settings, but this will prevent you from signing in to DODA Verify.
08Data Retention
- Account data is retained while your account is active.
- Scan history is retained for up to 2 years for the purpose of providing the history feature.
- Alert subscriptions are deleted when alerts are cancelled or the DODA document reaches a terminal status.
- Upon account deletion request, we will delete your personal data within 30 days, except where retention is required by law.
09Data Security and Breach Notification
We implement industry-standard security measures including HTTPS/TLS encryption, hashed credentials, and access controls on our AWS infrastructure. Payment data is handled exclusively by Stripe (PCI-DSS compliant).
In the event of a data breach that affects your personal information, we will:
- Notify affected U.S. users by email within 72 hours of discovering the breach (consistent with California law requirements), or as soon as reasonably practicable.
- Notify affected Mexican users within 5 business days as required by LFPDPPP Article 20.
- Provide details of what data was affected and recommended protective steps.
10Children's Privacy
DODA Verify is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete such information promptly. If you believe we have collected information from a child under 13, please contact us at customerservice@dodaverify.com.
11Your Privacy Rights — How to Exercise Them
Regardless of your location, you may request access to, correction, or deletion of your personal data at any time by emailing:
customerservice@dodaverify.com
Please include your account email address and the specific request type (access, correction, or deletion). We will respond within 30 days for general requests, or 45 days for CCPA requests.
12Governing Law
This Privacy Policy is governed by the laws of the State of Texas, United States, without regard to conflict of law principles, to the extent applicable to U.S. users. For Mexican users, the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) also applies.
13Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email (to the address associated with your account) and by posting the updated policy on this page with a new effective date. Continued use of DODA Verify after the effective date constitutes acceptance of the updated policy.
También disponible en español: Aviso de Privacidad