Terms of Service
These Terms govern your access to VPay's identity verification, royalty allocation, tax onboarding, payout administration, developer, and support services.
1. Agreement and authority
By creating a login, using VPay, or accepting these Terms, you enter a binding agreement with VPay. You also acknowledge the Privacy Notice and any service-specific terms presented when you use a feature. If you act for a company, minor, royalty owner, or other person, you represent that you have legal authority to do so. You must provide complete, current, and accurate information.
2. Eligibility and guardians
An adult may use VPay for themselves or an entity they are authorized to represent. A minor may participate only through a parent or legal guardian who is at least 18 and accepts responsibility for the account. The guardian represents that the beneficiary information is accurate and agrees that control must transfer to the beneficiary at age 18.
3. What VPay provides
VPay provides identity and contact verification, fraud and duplicate-account screening, contractual royalty-allocation records, tax and payout onboarding, manual payout administration, authorized developer identity signals, and related support. VPay is not a bank, deposit account, wallet, escrow service, or general-purpose payment network. VPay does not accept public deposits, transmit money for the public, or permit users to transfer balances to one another. It records and administers allocations and potential payment amounts arising under separate royalty, distribution, client, subscription, or related agreements.
4. Identity and compliance review
VPay may verify email, mobile number, network and device signals, legal profile details, government identity documents, face liveness, face-to-document similarity, duplicate documents, and duplicate faces. Automated checks can flag or block unsupported contact information, prohibited networks, or suspected abuse. VPay may request additional evidence, reject a submission, place a hold, or close an account when information cannot be verified or fraud, sanctions, security, or legal risk is suspected.
5. Identity and royalty accounts
Each login may have one personal identity profile. After identity approval, a user may open or join multiple royalty accounts for themselves or authorized businesses. An account owner may invite another verified VPay user to act as a principal or authorized participant. Invitations and account access do not transfer ownership of another person's identity. You are responsible for obtaining all permissions needed to administer a royalty account or act for another payee.
6. Royalty allocations and ledger records
A VPay royalty balance is a provisional accounting record of allocations made through a recorded source-account path. It is not a cash deposit, stored value, escrowed property, funds held for transmission, or an unconditional promise that every displayed amount is finally payable. Balances are not FDIC insured and do not earn interest.
Each allocation remains subject to the royalty, distribution, client, subscription, recoupment, or other agreement identified by the account that originated that allocation and any agreement governing an earlier step in its allocation path. Those agreements, together with applicable law, determine whether an amount is earned, vested, payable, reversible, recoupable, subject to setoff, or returnable. To the extent the governing agreement and law permit, a balance may be reduced or returned for corrections, duplicate or excess allocations, chargebacks, fraud, rights disputes, advances or recoupment, unpaid subscriptions or service charges, taxes, fees, reserves, dormancy, or another documented contractual adjustment. A source account's instruction does not create rights beyond its agreement or applicable law.
7. Tax and Tipalti onboarding
Royalty payout accounts must complete tax and payout onboarding through Tipalti even when VPay later uses another approved manual payout route. Tipalti may validate tax identifiers, collect tax forms, determine payable status, and provide withholding or payout-method information. VPay does not provide tax advice. You are responsible for accurate tax information and your own filing and payment obligations.
By creating a royalty account you agree to the Tipalti terms of service.
Tax withholding required by law or reported through the applicable tax setup will be deducted from payouts. If no fixed rate is available, VPay may delay payout until the correct amount can be determined.
International accounts are subject to an international account fee of up to $5 per payout update.
8. Payouts
The regular payout cycle is the second Friday of each month. Eligible accounts with at least $10 before payout fees are queued for their full eligible balance; smaller balances roll forward. Identity approval, tax onboarding, payout setup, account holds, and any applicable 72-hour payout-method security hold must be clear before payment.
You may request an early payout for a specific amount, but approval and timing are discretionary and not guaranteed. Any remaining eligible balance stays subject to the next regular cycle. Taxes, withholding, Tipalti charges, bank charges, check, PayPal or Payoneer charges, foreign-exchange costs, intermediary fees, and similar payment costs may be deducted from the payout. Estimates are not guarantees because providers control final rates and charges.
9. Electronic records and tax forms
VPay may send security, account, allocation, payout, support, and legal notices electronically to your verified email or secure VPay account. You must maintain a working email address and review notices promptly.
Electronic tax-form consent is required to open a VPay account. If you consent, it applies to all applicable tax years until you withdraw it, VPay ends electronic delivery, or your account closes. Tax forms will be provided as PDF files through a secure account link or verified email notice. You need internet access, a current browser, software capable of opening PDF files, and the ability to save or print them. VPay will notify you when a form is available and will keep a posted form available through at least October 15 of the year it is due.
If you do not wish to electronically receive tax forms, please speak with your VPay partner to do an alternate payout solution.
If you wish to withdraw electronic form consent you can do so by contacting VPay support. Doing so will close your account and any remaining forms from your account open period will be mailed. Withdrawal applies prospectively and does not affect forms already furnished or records VPay must retain. Tell VPay Support if your contact information changes or you cannot access the delivery format.
10. Developer applications and OAuth
A developer application receives VPay identity signals only after the user sees the requested permissions and authorizes that application. Depending on the scopes approved, signals may include legal name, identity status, country, age, verification age, boolean email, phone, network or device risk flags, and a user-selected royalty account identifier for payment coordination. Developer applications do not receive identity documents, face images or templates, addresses, tax information, bank details, balances, transactions, or royalty-account access through the identity API.
You can remove an application's access. Until removal or token expiration, an approved application may refresh or poll the authorized signals. The developer operates its own service and is responsible for its privacy notice, security, and use of information after receiving it. VPay is not responsible for an application's independent acts, promises, or services.
11. Account security
You must use a unique password, protect verification codes and recovery material, use required multifactor authentication, and notify VPay promptly of suspected compromise. You may not share a login or evade security controls. VPay may invalidate sessions, require re-verification, or temporarily restrict activity to protect users and the platform.
12. Prohibited conduct
You may not use VPay for fraud, impersonation, sanctions evasion, unlawful payments, money laundering, infringement, harassment, malware, automated abuse, credential attacks, scraping, reverse engineering of security controls, or interference with the service. You may not submit another person's identity, face, document, phone, tax information, or payout destination without lawful authority and informed permission.
13. Holds, rejection, suspension, and closure
VPay may hold payouts, reject evidence, require resubmission, suspend features, or close a login or account when reasonably necessary for security, fraud prevention, contract enforcement, sanctions, legal compliance, provider requirements, or protection of another person. A closure for suspected fraud may prevent reuse of associated email, phone, identity document, or face identifiers. For platform security, accounts closed for suspected fraud are unable to receive exact closure details. Closure does not erase amounts that remain finally payable under a governing agreement or records that VPay must preserve. Actions against your account may be appealed to VPay support within 10 business days.
14. Dormant amounts and unclaimed property
VPay measures dormancy separately for each allocation from the date the allocation is recorded as received. On the third anniversary of that date, any portion that remains unpaid and is not already reserved for a pending payout becomes eligible for dormancy review. Reaching three years does not cause an automatic payout, forfeiture, or transfer. After a dormancy review account balances may be remitted as unclaimed property or returned in the manner outlined in the associated agreements to the royalty allocations.
Unclaimed-property, escheat, tax, court-order, and other mandatory legal requirements control over these Terms and any client agreement. VPay or another holder may be required to preserve, report, or remit an amount to the appropriate government rather than return it to a source account. A contractual deadline or limitation does not eliminate any reporting, delivery, record-retention, or owner-protection duty that applicable law imposes.
15. Third-party services
VPay relies on independent providers for tax onboarding, identity infrastructure, communications, abuse prevention, hosting, and payout rails. Provider availability, eligibility, exchange rates, settlement timing, and terms may affect VPay features. Your use of a provider-facing form or selected payout method may also be governed by that provider's terms. VPay is not responsible for a provider outage or an act outside VPay's reasonable control, but VPay remains responsible for its own obligations under applicable law.
16. Service and agreement changes
VPay may change or discontinue features for security, legal, operational, or business reasons. We may update these Terms prospectively. Material changes will be posted with a new effective date and, when appropriate, sent by email or presented for renewed acceptance. Changes do not retroactively alter an amount already finally determined payable under its governing agreement.
17. Disclaimers
To the maximum extent permitted by law, VPay and its services are provided "as is" and "as available." VPay disclaims implied warranties of merchantability, fitness for a particular purpose, non-infringement, and uninterrupted or error-free operation. Identity and risk checks reduce risk but do not guarantee that a person, document, destination, developer, or transaction is legitimate. Nothing in these Terms excludes a warranty that cannot lawfully be excluded.
18. Limitation of liability
To the maximum extent permitted by law, VPay will not be liable for indirect, incidental, special, exemplary, punitive, or consequential damages, or lost profits, data, goodwill, or opportunities, arising from the service. Except for an undisputed amount finally determined payable under its governing agreement, confidentiality or data-protection obligations that cannot lawfully be limited, fraud, willful misconduct, gross negligence, or another liability that law prohibits us from limiting, VPay's aggregate liability arising from the service will not exceed the greater of $100 or the fees you paid directly to VPay during the 12 months before the event giving rise to the claim.
19. Indemnity
To the extent permitted by law, you will defend and indemnify VPay and its officers, employees, and agents from third-party claims, losses, and reasonable costs arising from your unlawful use, material breach of these Terms, false information, lack of authority to act for another person or entity, or infringement of another person's rights. This does not require you to indemnify VPay for VPay's own negligence or unlawful conduct.
20. Governing law and disputes
Delaware law governs these Terms without regard to conflict-of-law rules, except where mandatory consumer law provides otherwise. Before filing a claim, the parties will try in good faith for 30 days to resolve it through VPay Support. Subject to any mandatory right to bring a claim elsewhere, state and federal courts located in Delaware have exclusive jurisdiction. You may still bring an eligible matter in small-claims court.
21. General terms
These Terms, the Privacy Notice, and feature-specific disclosures are the entire agreement about VPay's service unless a separate signed agreement applies. If one provision is unenforceable, the remaining provisions remain effective. Failure to enforce a provision is not a waiver. You may not assign your agreement without VPay's written approval; VPay may assign it as part of a merger, reorganization, or transfer of the service, subject to applicable privacy law. Provisions that by their nature should survive termination will survive.
Privacy Notice
This Notice explains what VPay collects, why it is used, when it is disclosed, and the choices available to you. VPay does not sell personal information or use it for targeted advertising.
1. Scope and controller
VPay is the controller of personal information processed through the service. This Notice covers VPay websites, accounts, identity verification, royalty administration, support, and developer authorization. A royalty client, developer application, Tipalti, or payout provider may separately control information it collects for its own service.
2. Information we collect
| Category | Examples |
|---|---|
| Account and contact | Email address, mobile number, password hash, verification status, notification and tax-delivery choices. |
| Legal identity | Legal name, date of birth, age, country, residential address, citizenship or residency details, guardian and beneficiary information. |
| Business identity | Legal business name, entity type, registration and address details, principal, owner, and authorized representative information. |
| Government and tax verification | Government ID images or PDFs, document fields and authenticity signals, Tipalti payee and form references, form type, TIN-validation status, payable status, and withholding settings. Tax identifiers. |
| Biometric and visual evidence | Face-liveness images or frames, an ID portrait, face similarity results, and mathematical face templates used for matching and duplicate detection. |
| Royalty and payout | Royalty account identifiers, allocations, balances, ledger entries, holds, payout requests, methods, provider status, fees, withholding, payment references, and settlement history. |
| Device, network, and security | IP address, coarse country or risk result, proxy or VPN signal, temporary-email result, phone validity and line type, user agent, session and CSRF records, login and MFA activity, captcha result, and hashed lookup or abuse-prevention identifiers. |
| Communications | Support tickets, replies, account notices, consent records, and other communications with VPay. |
| Developer | Developer profile, application details, redirect URLs, credentials, requested scopes, authorization history, and API security events. |
3. Sources
We collect information from you; a parent, guardian, principal, or authorized account participant; royalty allocation systems and the royalty account that records an allocation; service providers that verify or process information; and security signals generated when you use VPay. We do not buy consumer profiles from data brokers.
4. Why we process information
We use personal information to create and secure logins; verify email, phone, legal identity, documents, liveness, and account uniqueness; review fraud and compliance signals; administer contractual royalty allocations, tax onboarding, withholding, and payouts; operate user-authorized OAuth connections; provide support; maintain audit and accounting records; investigate abuse; enforce agreements; and comply with tax, court, sanctions, and other legal obligations.
Where the GDPR or UK GDPR applies, our legal bases are performance of a contract, compliance with legal obligations, legitimate interests in security, fraud prevention, accounting, service administration, and legal claims, and consent for processing that requires it, including biometric processing, electronic tax delivery, SMS requests, and user-directed OAuth disclosure. We do not use consent where another legal basis is more appropriate.
5. When information is disclosed
We disclose only what is reasonably needed to:
- Infrastructure and security providers for hosting, encryption, identity processing, abuse prevention, and service protection.
- Communications provider and telecommunications carriers, for email, requested verification texts, and phone intelligence.
- Tipalti and a selected bank, PayPal, Payoneer, check, or other approved payout provider for tax onboarding and manual payment administration.
- Authorized VPay staff and professional advisers who need information for identity, tax, payout, support, security, audit, or legal work.
- A developer application only when you authorize specific OAuth scopes, as described below.
- Courts, regulators, law enforcement, tax authorities, or other parties when required by law or reasonably necessary to protect rights, safety, and the service.
- A successor in a merger, financing, reorganization, or sale, subject to this Notice and applicable law.
Service providers may use information only for contracted services and their lawful operational obligations. VPay does not sell or rent personal information. VPay does not share personal information for cross-context behavioral advertising and does not use personal information for targeted advertising.
6. User-authorized developer disclosure
An OAuth consent screen identifies the developer application and each requested scope. With your authorization, VPay may disclose legal name, identity status, country, age, verification age, boolean risk flags, and a selected royalty account identifier. The identity API does not disclose your email, phone number, IP address, exact birth date, street address, identity evidence, face data, tax information, payout details, balance, or transaction history. You can remove an application from VPay; the developer may still retain information it lawfully received under its own disclosed retention policy.
7. Security
VPay encrypts sensitive profile fields using AES-256-GCM and uses TLS in transit, Argon2id password hashing, encrypted provider storage, restricted credentials, multifactor authentication, session controls, audit records, malware scanning, and staff access controls. Sensitive identifiers are often replaced with keyed hashes for matching. No system is perfectly secure, and you should report suspected unauthorized access promptly.
8. Retention
We keep information only as long as needed for the purposes described, legal obligations, disputes, security, and enforceable recordkeeping. The following schedule states current maximum targets unless a shorter period is required or a documented legal hold, court order, tax obligation, fraud investigation, or active dispute requires longer retention:
| Record | Retention rule |
|---|---|
| Account, legal profile, royalty, payout, tax, ledger, consent, and audit records | While the account or an associated allocation or payout remains active, then generally up to 7 years after account deletion. VPay requires open payouts and nonzero royalty balances to be resolved under their governing agreements before staff completes account deletion. |
| Government identity documents and non-biometric review evidence | While needed to maintain or defend identity approval, then no more than 5 years after account deletion unless preservation is legally required. |
| Biometric identifiers and biometric information | Destroyed when the initial verification, duplicate-prevention, and fraud-review purpose has been satisfied or within 3 years after your last biometric interaction with VPay, whichever occurs first, unless preservation is legally required. |
| Incomplete identity capture and temporary mobile handoff data | Temporary handoff credentials expire within 20 minutes; abandoned or failed evidence is reviewed for deletion within 90 days unless needed for fraud investigation. |
| Routine network, session, and security telemetry | Usually no more than 2 years, with shorter technical expiration for live sessions and rate limits. |
| Support communications | Usually 3 years after the ticket closes, or longer when tied to a transaction, complaint, or legal obligation. |
| Backups | Removed through the encrypted backup rotation, generally within 90 days after deletion from active systems. |
9. International processing
VPay is operated from the United States and uses providers that may process information in the United States, Germany, and other countries where they operate. Those countries may have different privacy laws. Where required, VPay uses contractual and technical safeguards for international transfers and will provide information about an applicable safeguard on request.
10. Children and guardians
VPay is not directed to children acting independently. A minor's information may be processed only through an adult parent or legal guardian who provides authority and consent where required. At age 18, VPay restricts the guardian-led identity until the beneficiary supplies their own information and completes verification. A guardian may exercise applicable privacy rights for the minor until legal control transfers.
11. Changes and contact
We will post changes with a new effective date and provide additional notice or request renewed consent when required. To exercise privacy rights or contact VPay, Submit a privacy request, open VPay Support while signed in, or email [email protected].
Biometric Data Notice and Retention Policy
This section is VPay's public biometric collection, use, disclosure, retention, and destruction policy.
Data collected
When you begin camera verification, VPay collects face-liveness images or video frames and generates liveness results. VPay may extract the portrait from your government ID, compare it with the liveness reference image, and create mathematical face geometry or a face template for duplicate-account searches. A template is a numerical representation and is not used to reconstruct a photograph.
Purpose and use
VPay uses this information only to confirm that a live person is present, compare the person with their identity document, detect duplicate or fraudulent identities, support staff review and appeals, secure royalty payouts, and comply with applicable law. We do not use face data to infer emotion, health, ethnicity, religion, or unrelated personal traits.
Disclosure and profit prohibition
Biometric data is available only to authorized VPay identity reviewers and contracted infrastructure or identity processors as needed for these purposes. It is not exposed through the developer API. VPay does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information and does not disclose them for advertising.
Consent
Before a camera session begins, VPay presents a separate consent checkbox linking to this Notice and records the notice version, time, account, identity attempt, and protected request evidence. By accepting, you authorize the collection, storage, use, and processor disclosure described here. If you act as a guardian or authorized representative, you confirm that you may provide this consent for the person being verified.
Retention and permanent destruction
VPay permanently destroys biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years after the individual's last biometric interaction with VPay, whichever occurs first. Starting or completing a new face-liveness verification resets that outside deadline. VPay may preserve particular evidence when required by a valid warrant, subpoena, court order, applicable law, or a documented legal hold. When the preservation requirement ends, the ordinary destruction schedule resumes. VPay requires processors to delete or return biometric data consistently with applicable contracts and law.
Protection and withdrawal
VPay protects biometric data using at least the same care used for other confidential and sensitive information, including encryption, access restrictions, short-lived provider credentials, logging, and review controls. You may withdraw consent for future biometric processing by contacting VPay Support. Withdrawal does not invalidate prior lawful processing and may prevent VPay from approving or continuing an identity-dependent service. A deletion request remains subject to legal and security retention exceptions.
SMS Terms and Privacy Notice
VPay uses text messages only for user-requested mobile-number verification. VPay does not send SMS marketing, security alerts, or identity-document links.
Message request and frequency
When you enter a mobile number, accept these SMS Terms, and select Create Account, you request one automated text containing a verification code. Another message is sent only when you request a new code or change an unverified number. Message frequency therefore depends on your requests. Standard message and data rates may apply.
Your responsibility
You represent that you are the subscriber or customary user of the number and are authorized to request messages at it. Consent to a verification text is not consent to marketing. Mobile verification is required to activate a VPay login; if you do not want a text, do not submit the request and contact Support about availability of an alternative.
Stopping messages and help
Reply STOP to opt out from the sender or HELP for help. Because VPay sends only one-time codes on request, opting out may prevent phone verification and account use. You can also contact [email protected]. Carriers are not liable for delayed or undelivered messages, and delivery is not guaranteed in every country or on every carrier.
SMS privacy
VPay uses your mobile number, consent record, code status, carrier and line-type information, and protected request metadata to verify the number, prevent abuse, and document compliance. VPay provides necessary data to telecommunications carriers and service providers acting for VPay. VPay does not sell mobile information or share text-message originator opt-in data or consent with third parties or affiliates for their marketing or promotional purposes.
Consent evidence
VPay records the exact disclosure and version, time, purpose, confirmation label, hashed destination, and protected network and user-agent evidence.
GDPR, California, Delaware, and Other Regional Rights
Privacy rights vary by residence and by whether a law applies to VPay. We will honor applicable rights and generally extend the request process below even when a particular statute does not require it.
EEA, United Kingdom, and Switzerland
Where applicable, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent at any time; and complain to the data-protection authority where you live or work. You may object to processing based on legitimate interests, and VPay will stop unless it demonstrates compelling lawful grounds or needs the information for legal claims. VPay does not make final identity or tax approval decisions solely through automated processing. Because VPay is established in the United States, information may be transferred outside your country as described in the Privacy Notice.
California notice
The categories collected during the preceding 12 months are the categories listed in the Privacy Notice: identifiers and contact data; customer and account records; protected classification information such as age and nationality; commercial and royalty records; internet and device activity; approximate geolocation derived from network data; audio, electronic, and visual identity evidence; professional or business information; sensitive personal information such as government identifiers, account access credentials, precise identity details, and biometric information; and inferences limited to fraud, verification, and security status.
VPay collects and uses those categories for the business purposes described in the Privacy Notice and discloses them to the provider and recipient categories listed there. VPay has not sold personal information, shared it for cross-context behavioral advertising, or used sensitive personal information to infer unrelated characteristics. VPay does not offer a financial incentive for personal information.
Subject to applicable exceptions, California residents may request to know, access, correct, or delete information and may receive equal service for exercising a right. A right to opt out of sale or sharing and a right to limit sensitive-information use do not require a separate VPay opt-out because VPay does not sell or share for behavioral advertising and uses sensitive information only for requested services, security, compliance, and other permitted purposes.
Delaware and other US states
Residents of Delaware and other states with applicable comprehensive privacy laws may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal data, opt out of sale, targeted advertising, or certain profiling, and appeal a denied request. VPay does not sell personal data or use it for targeted advertising. Nevada residents may submit a sale opt-out request, though VPay does not sell covered information. State biometric rights are addressed in the Biometric Data Notice.
Submitting a request
Use the privacy request form, open VPay Support while signed in, or email [email protected] with the subject "Privacy Request." Describe the right and account involved. VPay will verify your identity without asking for more information than reasonably necessary. An authorized agent may submit a request where permitted, but VPay may require proof of authority and direct identity confirmation. If VPay denies a request, the response will explain the reason and any available appeal process. You may appeal by replying with "Privacy Appeal." VPay will not discriminate against you for exercising a privacy right.
When staff approves account deletion, sign-in, sessions, connected applications, and affected account access are disabled immediately. Government identity evidence is scheduled for destruction after 5 years and remaining linked account and financial records after 7 years, subject to the exceptions below. Append-only accounting and security-integrity records may remain in de-identified form after their direct account mapping is destroyed.
Deletion and access rights have legal exceptions. VPay may retain or withhold information needed to resolve contractual royalty allocations and payouts, maintain tax and accounting records, protect account security, detect fraud, comply with law, or establish and defend legal claims. VPay will not disclose full passwords, government numbers, financial credentials, or information that would compromise another person's privacy or platform security.
Accessibility
VPay aims to make its website and services usable by people with disabilities and uses WCAG 2.2 Level AA as its current accessibility target. Accessibility is an ongoing effort, and this statement is not a claim that every page or third-party iframe currently conforms.
VPay supports keyboard navigation, visible focus, semantic headings and labels, text alternatives for functional icons, responsive layouts, status announcements, and browser zoom. Third-party identity, captcha, and tax interfaces may have their own accessibility support.
If a VPay feature, identity step, document, tax form, or support channel is difficult to use, contact [email protected] or open a VPay Support ticket. Include the page or task, assistive technology and browser if relevant, and the accommodation or alternate format that would help. VPay will consider reasonable alternatives that preserve identity, security, tax, and payout requirements.
Contact
Questions about these terms, privacy, biometrics, SMS, cookies, or accessibility can be sent to [email protected]. Signed-in users may also open a ticket through VPay Support.