Skip to content

Privacy Policy

Last updated: June 15, 2026

1. Introduction & scope

This Privacy Policy (the "Policy") describes how VerifiedLawFirms LLC ("VerifiedLawFirms," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information in connection with the website located at verifiedlawfirms.com and any associated subdomains, pages, features, content, and online services that link to or reference this Policy (collectively, the "Service"). This Policy also describes the rights and choices available to individuals with respect to their personal information.

1.1 Who we are

VerifiedLawFirms LLC operates an independent, United States-based online directory of law firms. We are not a law firm, we do not provide legal advice, and we are not affiliated with, endorsed by, or sponsored by any governmental, regulatory, or attorney-licensing authority. The Service enables visitors to browse and search the directory and enables law-firm owners and their authorized representatives to create accounts, submit and claim listings, and upload evidence used in our verification process.

1.2 Scope of this Policy

This Policy applies to personal information that we process as a "business" under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA/CPRA"), and, with respect to certain visitors located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, as a "controller" under the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the United Kingdom General Data Protection Regulation (collectively, the "GDPR").

1.3 Information not covered by this Policy

This Policy does not apply to: (a) information handling practices of any law firm, attorney, vendor, or other third party that operates its own website or service, including those reachable through links appearing on the Service; (b) information you provide directly to a law firm listed in the directory; or (c) information collected through any offline channel not connected to the Service. We encourage you to review the privacy notices of any third party with which you interact.

1.4 Acceptance

By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you should not access or use the Service. Your use of the Service is also governed by our Terms of Service.

2. Information we collect

We collect personal information in three principal ways: (i) information you provide directly to us; (ii) information collected automatically through your use of the Service; and (iii) information we obtain from third parties and publicly available sources.

2.1 Information you provide to us

2.1.1 Account information

When you register for an account, we collect your name, email address, password (stored only in salted, hashed form), and, where applicable, your role or relationship to a law firm. If you enable two-factor authentication, we process information necessary to administer that security feature. We do not store your authentication secret in plaintext.

2.1.2 Firm listing information

When you submit or claim a law-firm listing, we collect business contact details and descriptive content, which may include the firm name, business address, business telephone number, business email address, website, practice areas, jurisdictions, attorney names and professional credentials, bar admission information, biographical content, logos, photographs, and other materials you choose to publish.

2.1.3 Verification evidence and supporting documents

Our verification process is evidence-driven. When you participate in verification, you may upload documents and other materials intended to substantiate a particular check (for example, licensing, standing, or credentialing evidence). These materials may contain personal information and, in some cases, sensitive identifiers. As described in Section 7, uploaded verification documents are treated as confidential, are restricted to authorized administrative personnel, and are not displayed publicly.

2.1.4 Payment information

Paid plans and add-ons are processed by our third-party payment processor, Stripe, Inc. ("Stripe"). Payment card details are collected and processed directly by Stripe in accordance with the Payment Card Industry Data Security Standard (PCI DSS). We do not collect or store full payment card numbers. We receive limited transaction-related information from Stripe, such as the cardholder name, billing contact details, the last four digits and brand of the payment instrument, the transaction amount, and a confirmation status, which we use to administer your subscription and maintain billing records.

2.1.5 Reviews and ratings

The Service permits clients of a law firm to submit reviews and ratings. When you submit a review, we collect the content of the review, any rating you assign, the name and email address you provide, your attestation that you were a client of the firm together with the matter type and engagement period you select, and metadata associated with the submission, such as a hashed record of your network address used to limit abuse. You should not include sensitive personal information or privileged or confidential matter in any review.

2.1.6 Communications and support

When you contact us for support, submit an inquiry, respond to a survey, or otherwise communicate with us, we collect the information contained in your communication, including your contact details and the contents and metadata of the message.

2.2 Information we collect automatically

2.2.1 Log and usage data

When you access the Service, our servers automatically record certain information, which may include your Internet Protocol (IP) address, the date and time of your request, the pages or content you view, the referring and exit pages, the search terms you submit on the Service, and diagnostic or error data.

2.2.2 Device and connection information

We may collect information about the device and software you use to access the Service, including browser type and version, operating system, device type, language preferences, and screen or viewport characteristics.

2.2.3 Cookies and similar technologies

We and our service providers use cookies, pixels, local storage, and similar technologies to operate, secure, and analyze the Service, as further described in Section 4.

2.2.4 Analytics

We use Google Analytics and Google Tag Manager, provided by Google LLC ("Google"), to understand how visitors interact with the Service. These tools may collect usage and device information and may set or read cookies and identifiers. See Section 4 for additional detail and for information on opting out.

2.3 Information we obtain from third parties and public sources

2.3.1 Public registries and court records

To support the integrity of our directory and verification process, we obtain information from publicly available sources, including public attorney-licensing and bar registries, court dockets and public court records, and other governmental or official records. This information may include attorney names, license status, disciplinary history, and litigation or docket information associated with a firm or attorney.

2.3.2 Service providers and platforms

We receive information from service providers that support the Service, including our payment processor (Stripe), analytics provider (Google), hosting, search, communications, and infrastructure providers, in each case for the purposes described in this Policy.

2.4 Summary table: categories of personal information and purposes

The following table summarizes the categories of personal information we collect, illustrative examples, the categories of sources, and the principal purposes for which each category is used. Where applicable, categories correspond to those enumerated under the CCPA/CPRA (Cal. Civ. Code § 1798.140).

Category of personal information (CCPA/CPRA) Examples Sources Principal purposes
Identifiers Name, email address, account username, IP address, online identifiers You; automatic collection Account creation and authentication; communications; security; fraud prevention
Customer records (Cal. Civ. Code § 1798.80) Billing contact name and address; partial payment instrument data received from Stripe You; payment processor Processing payments and subscriptions; billing records; tax and accounting
Commercial information Plan and add-on purchases; transaction history; products or services obtained You; payment processor Administering subscriptions; account management; record-keeping
Internet or network activity Browsing and search activity on the Service; interaction with content; log data Automatic collection Operating, securing, and improving the Service; analytics
Geolocation data (approximate) Coarse location inferred from IP address Automatic collection Security; fraud prevention; localization; analytics
Professional or employment-related information Firm name, role, attorney credentials, bar admissions, verification evidence You; public registries and court records Listing publication; verification; directory integrity
Audio, electronic, or visual information Uploaded documents, logos, photographs, review content You Listing publication; verification; display of reviews
Inferences Preferences and engagement signals derived from usage Derived Improving and personalizing the Service
Sensitive personal information (CPRA), where provided Account log-in credentials; identifiers that may appear within uploaded verification documents You Authentication and security; verification. We do not use sensitive personal information to infer characteristics, and we do not sell or share it.

We do not knowingly collect Social Security numbers, driver's license numbers, financial account numbers, precise geolocation, or other sensitive identifiers except to the extent such information appears within verification documents that you voluntarily upload, which are handled confidentially as described in Section 7. We do not use or disclose sensitive personal information for purposes other than those permitted under Cal. Civ. Code § 1798.121.

3. How and why we use information (purposes and legal bases)

3.1 Purposes of processing

We use personal information for the following business and commercial purposes:

  1. to provide, operate, maintain, and secure the Service, including authenticating users and administering accounts;
  2. to publish and display law-firm listings and validated reviews submitted through the Service;
  3. to perform our evidence-driven verification process, including reviewing uploaded documents and confirming information against public registries and court records;
  4. to process payments, administer subscriptions and add-ons, and maintain billing and tax records, in conjunction with Stripe;
  5. to communicate with you, including responding to inquiries and sending administrative, transactional, and service-related messages;
  6. to send marketing or promotional communications where permitted, subject to your right to opt out as described in Section 3.3;
  7. to measure, analyze, and improve the performance, content, and usability of the Service;
  8. to detect, investigate, prevent, and address fraud, abuse, security incidents, and other unlawful or prohibited activity;
  9. to comply with applicable laws, regulations, legal process, and our legal obligations, and to establish, exercise, or defend legal claims; and
  10. to effect a corporate transaction as described in Section 6.

3.2 Legal bases for processing (EEA, UK, and Switzerland)

Where the GDPR applies, we process personal information only when we have a valid lawful basis to do so. The lawful bases on which we rely are:

  • Performance of a contract (Art. 6(1)(b) GDPR): to provide the Service, administer accounts, and process payments and subscriptions you have requested;
  • Legitimate interests (Art. 6(1)(f) GDPR): to operate, secure, and improve the Service, to maintain the integrity of the directory and the verification process, to prevent fraud and abuse, and to conduct analytics, in each case where such interests are not overridden by your fundamental rights and freedoms;
  • Consent (Art. 6(1)(a) GDPR): for non-essential cookies and similar technologies and for certain marketing communications, where required; you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal; and
  • Compliance with a legal obligation (Art. 6(1)(c) GDPR): to satisfy obligations under applicable law, including tax, accounting, and record-keeping requirements, and to respond to lawful requests from public authorities.

Where we process any special categories of personal data under Article 9 GDPR that you voluntarily submit, we do so on the basis of your explicit consent or because the processing relates to personal data you have manifestly made public, or as otherwise permitted by law.

3.3 Marketing communications and CAN-SPAM

Where we send commercial email messages, we do so in accordance with the federal CAN-SPAM Act of 2003 (15 U.S.C. §§ 7701 to 7713) and other applicable laws. Our commercial messages identify the message as an advertisement where required, include a valid physical postal address, and provide a functioning mechanism to opt out of further commercial messages. You may unsubscribe at any time by following the instructions in the message or by contacting us using the details in Section 14. We will honor opt-out requests promptly. Transactional and service-related messages necessary to administer your account or subscription are not promotional and may continue notwithstanding a marketing opt-out.

4. Cookies and tracking technologies

4.1 What we use

We and our service providers use cookies and similar technologies, including pixels, tags, software development kits, and browser local storage, to operate the Service, remember your preferences, authenticate sessions, maintain security, and analyze usage. Cookies may be "session" cookies, which expire when you close your browser, or "persistent" cookies, which remain until they expire or are deleted.

4.2 Categories of cookies

  • Strictly necessary: required to operate the Service, including authentication, load balancing, and security. These cannot be disabled through our preference controls.
  • Functional: remember choices you make, such as language or display preferences.
  • Analytics and performance: help us understand how the Service is used, including through Google Analytics and Google Tag Manager.

4.3 Analytics providers

Google Analytics and Google Tag Manager process information about your use of the Service on our behalf. Google may use this information in accordance with its own policies. You can opt out of Google Analytics across websites by installing the Google Analytics Opt-out Browser Add-on offered by Google, and you may manage cookies through your browser settings as described below.

4.4 Your cookie choices

Most web browsers allow you to refuse or delete cookies through their settings. If you disable certain cookies, some features of the Service may not function properly. Where required by law, we obtain consent before setting non-essential cookies and provide a mechanism to manage your preferences.

4.5 Global Privacy Control and Do Not Track

Some browsers and extensions transmit a "Global Privacy Control" ("GPC") signal. Where required by the CCPA/CPRA, we treat a valid GPC signal received from your browser as a request to opt out of the "sale" or "sharing" of personal information associated with that browser or device. Separately, certain browsers offer a "Do Not Track" ("DNT") setting. Because there is no common industry standard for interpreting DNT signals, we do not currently respond to DNT signals other than as described above with respect to GPC. As stated in Section 5.4, we do not sell personal information.

5. How we share and disclose information

We disclose personal information only as described in this Section and only for the purposes set out in this Policy. We do not sell personal information.

5.1 Service providers and processors

We share personal information with vendors and service providers that perform functions on our behalf, acting as "service providers" or "contractors" under the CCPA/CPRA and as "processors" under the GDPR. These include our payment processor (Stripe), analytics provider (Google), and providers of hosting, infrastructure, search, email, security, and customer-support services. We require such parties by contract to process personal information only on our documented instructions, to maintain appropriate safeguards, and not to retain, use, or disclose the information for any purpose other than performing the services or as otherwise permitted by law.

5.2 Public display of listing and review content

Information you submit for publication (such as firm listing content and validated reviews) is, by design, made available to the public through the directory. Uploaded verification documents are never published; only the name of the check, a plain-English description, the verification status, and the date last checked are displayed, as described in Section 7.

5.3 Legal, compliance, and safety disclosures

We may disclose personal information where we believe in good faith that doing so is necessary to: (a) comply with applicable law, regulation, legal process, subpoena, or governmental request; (b) enforce our Terms of Service and other agreements; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of VerifiedLawFirms, our users, or the public, as required or permitted by law.

5.4 No sale or sharing of personal information

VerifiedLawFirms does not sell personal information, and does not "share" personal information for cross-context behavioral advertising, in each case as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding twelve (12) months. Should this practice change, we will update this Policy and provide any opt-out mechanism required by law. We also do not knowingly sell or share the personal information of consumers under sixteen (16) years of age.

5.5 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, personal information may be transferred as part of that transaction, subject to the commitments made in this Policy. We will provide notice as required by applicable law.

5.6 Aggregated and de-identified information

We may create and use aggregated, anonymized, or de-identified information that does not identify any individual. We maintain and use such information only in de-identified form and do not attempt to re-identify it, except as permitted by law.

5.7 Financial privacy

To the limited extent that any provision of the Gramm-Leach-Bliley Act (15 U.S.C. §§ 6801 et seq.) and its implementing regulations may apply to information processed in connection with billing, we maintain administrative, technical, and physical safeguards designed to protect the security and confidentiality of such information and do not disclose it except as permitted by law.

6. Verification documents: handling and confidentiality

6.1 Confidential treatment

Documents and materials uploaded as verification evidence are treated as confidential. Access is restricted to authorized administrative personnel who review evidence as part of our verification process, and access is governed by internal access controls and confidentiality obligations.

6.2 No public display of documents

Uploaded verification documents are never displayed publicly and are not disclosed to other users, to the firms being reviewed beyond the submitting account, or to advertisers. The public-facing verification interface displays only the name of each check, a plain-English description, the verification status, and the date the check was last reviewed.

6.3 Purpose limitation

We use verification documents solely to perform and substantiate the relevant verification checks, to maintain an internal record supporting the published verification status, and to comply with legal obligations. We do not use verification documents for advertising, and we do not sell or share them.

6.4 Storage and security

Verification documents are stored using access-controlled storage and are protected by the safeguards described in Section 8. Where appropriate, we retain only the materials necessary to evidence the applicable check.

7. Data retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. The criteria we use to determine retention periods include: (a) the duration of your account and active use of the Service; (b) the period necessary to provide the Service and administer subscriptions; (c) our legal, tax, accounting, and record-keeping obligations; (d) the need to maintain the integrity of published listings and verification records; and (e) the need to establish, exercise, or defend legal claims. When personal information is no longer required, we will delete, anonymize, or de-identify it using commercially reasonable measures. Backup copies may persist for a limited additional period until they are overwritten or expire in the ordinary course.

8. Data security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction. These measures include encryption of data in transit, access controls and role-based permissions, hashing of authentication credentials, network and application security controls, and the engagement of payment and infrastructure providers that maintain industry-recognized security certifications. We do not store full payment card numbers; card data is handled by Stripe under PCI DSS.

No method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials. In the event of a breach of security affecting personal information, we will investigate and will notify affected individuals and the appropriate authorities as and to the extent required by applicable breach-notification laws, including applicable state breach-notification statutes and, where the GDPR applies, Articles 33 and 34 GDPR, within the timeframes those laws require.

9. Your rights and choices: California (CCPA/CPRA)

This Section applies to California residents and supplements the other provisions of this Policy. It is provided in accordance with the CCPA/CPRA.

9.1 Notice of categories collected, disclosed, sold, or shared

The categories of personal information we collect, the sources of that information, and the purposes for which it is used are described in Section 2, including the summary table in Section 2.4. In the preceding twelve (12) months, we disclosed the categories of personal information identified in Section 2.4 to service providers and contractors for the business purposes described in Section 3. We have not sold or shared personal information, and we have not sold or shared the personal information of consumers under sixteen (16) years of age.

9.2 Your California rights

Subject to certain exceptions and limitations, California residents have the following rights:

  • Right to know / access: to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting it, and the categories of third parties to whom we disclose it;
  • Right to delete: to request that we delete personal information we have collected from you, subject to statutory exceptions;
  • Right to correct: to request that we correct inaccurate personal information we maintain about you;
  • Right to opt out of sale or sharing: to direct us not to sell or share your personal information. As stated in Section 5.4, we do not sell or share personal information; we honor valid GPC signals as described in Section 4.5;
  • Right to limit use of sensitive personal information: we use sensitive personal information only for purposes permitted under Cal. Civ. Code § 1798.121 and do not use it to infer characteristics, so no further limitation right applies; and
  • Right to non-discrimination: we will not discriminate or retaliate against you for exercising any of your privacy rights.

9.3 How to exercise your California rights

You may submit a request to know, delete, or correct by emailing privacy@verifiedlawfirms.com. We will verify your identity before fulfilling a request, which may require us to confirm certain information associated with your account or your relationship to the personal information at issue. We will respond within the timeframes required by the CCPA/CPRA.

9.4 Authorized agents

You may use an authorized agent to submit a request on your behalf. We may require the authorized agent to provide proof of authorization, and we may require you to verify your own identity directly with us or to confirm that you have provided the agent permission to submit the request.

9.5 Appeals

Where required by applicable law, if we decline to take action on your request, you may appeal our decision by contacting us at privacy@verifiedlawfirms.com with the subject line "Privacy Rights Appeal."

10. Your rights and choices: EEA, UK, and Switzerland (GDPR)

If you are located in the EEA, the UK, or Switzerland, you have the following rights with respect to personal information that we process as a controller, subject to the conditions and exceptions set out in the GDPR:

  • Access: to obtain confirmation of whether we process your personal data and a copy of that data (Art. 15);
  • Rectification: to have inaccurate personal data corrected and incomplete data completed (Art. 16);
  • Erasure: to request deletion of your personal data in certain circumstances (Art. 17);
  • Restriction: to request that we restrict processing in certain circumstances (Art. 18);
  • Data portability: to receive certain personal data in a structured, commonly used, machine-readable format and to transmit it to another controller (Art. 20);
  • Objection: to object to processing based on our legitimate interests and to object at any time to processing for direct marketing (Art. 21); and
  • Withdrawal of consent: to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.

The lawful bases on which we rely are described in Section 3.2. To exercise any of these rights, contact us at privacy@verifiedlawfirms.com. We will respond within the timeframes required by the GDPR. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). Where we have not designated a representative or Data Protection Officer, requests may be directed to the contact in Section 14.

11. International data transfers

We are based in the United States, and we process and store personal information in the United States and in other jurisdictions where we or our service providers operate. If you access the Service from outside the United States, you understand that your personal information may be transferred to, stored in, and processed in a country that may not provide the same level of data protection as your home jurisdiction.

Where we transfer personal data subject to the GDPR from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, we implement appropriate safeguards as required by Chapter V of the GDPR, including the European Commission's Standard Contractual Clauses ("SCCs") and the UK International Data Transfer Addendum, together with supplementary measures where appropriate. You may request a copy of the relevant transfer mechanism by contacting us using the details in Section 14.

12. Children's privacy (COPPA)

The Service is intended for businesses and adults and is not directed to children. Consistent with the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501 to 6506) and its implementing regulations, we do not knowingly collect personal information from children under thirteen (13) years of age. Consistent with the GDPR and the CCPA/CPRA, we also do not knowingly collect personal information from individuals under sixteen (16) years of age. If you are under the applicable age of consent, please do not use the Service or provide any personal information. If we learn that we have collected personal information from a child below the applicable age without appropriate consent, we will take reasonable steps to delete that information promptly. A parent or guardian who believes a child may have provided personal information may contact us at privacy@verifiedlawfirms.com.

13. Third-party links and services

The Service may contain links to, or content from, third-party websites and services, including the websites of listed law firms and our service providers. We do not control and are not responsible for the privacy practices or content of those third parties. The inclusion of a link does not imply endorsement. We encourage you to review the privacy notice of any third party before providing personal information to it.

14. How to contact us and submit a request

If you have questions about this Policy or wish to exercise any of your privacy rights, you may contact us:

  • By email: privacy@verifiedlawfirms.com
  • By mail: VerifiedLawFirms LLC, Attn: Privacy, [Mailing Address]

VerifiedLawFirms LLC is the entity responsible for the processing of personal information described in this Policy. To help us respond efficiently, please indicate the nature of your request and the jurisdiction in which you reside. We will verify your identity before fulfilling certain requests as described in Sections 9 and 10.

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the effective date displayed with this Policy and, where required by law, provide additional notice or obtain your consent. Material changes will be communicated through the Service or by other appropriate means. Your continued use of the Service after the effective date of a revised Policy constitutes your acknowledgment of the updated Policy to the extent permitted by law.