Skip to content
Verified Everywhere

Legal

Refunds, Cancellations and Acceptable Use

This page explains exactly when you get money back, how either of us can end an engagement, and the work we will not take on. The short version: our own service fee is fully refundable before we start work and pro-rata after that, money you pay directly to a certificate authority or to a platform is governed by their refund rules and not ours, and we do not refund because a platform said no, because our fee buys correct work through official channels rather than a guaranteed outcome. We will decline or stop work if a business is not what it claims to be, if you are not authorized to represent it, or if anyone asks us to misrepresent facts to a platform or a certificate authority.

What this page covers

Verified Everywhere is a trading name of JWC Apps, based in San Diego, California. We are a done-for-you agency. We set up official third-party verification programs for small businesses. We do not issue, sell, or resell certificates or badges, and we never could.

This page covers three things: how refunds work, how either side ends an engagement, and what work we will and will not accept. It applies to every service line we sell. Your signed engagement letter and our Terms of Service also apply. If your engagement letter says something different from this page, the engagement letter wins.

We wrote this in plain English on purpose. This is a category with a lot of scams in it. You should be able to read our refund policy once and know where you stand.

What you are paying for

This is the sentence the rest of the page hangs on. You are paying us to do the work correctly and completely, through each platform's official channel, on the first try wherever that is possible.

You are not paying us for an approval. We cannot sell you one. Google, Meta, Apple, Microsoft, Yahoo, X, LinkedIn and TikTok make their own decisions about badges and listings. DigiCert, GlobalSign and SSL.com make their own decisions about certificates. Nobody at those companies works for us and nobody there owes us a yes.

We say this before you pay, not after you are denied. If a company in this space promises you a verified badge or a blue check as an outcome, they are either misunderstanding how these programs work or lying to you.

The three kinds of money in an engagement

Almost every dispute in this industry comes from mixing these up, so we separate them on every quote and every invoice.

Our service fee is the only money we ever receive. It is what this refund policy governs.

Certificate authority fees and platform subscriptions are paid by you, directly to that company, on their own billing. We never mark them up, we never take a cut, and we never take custody of them. We cannot refund money we never received.

  • Our service fee. Paid to JWC Apps through Stripe. Refundable under the rules below.
  • Certificate authority fees. Paid by you directly to DigiCert, GlobalSign or SSL.com. A Verified Mark Certificate currently runs about $749 to $1,416 per year. A Common Mark Certificate runs about $649 per year. Their refund policy applies, not ours.
  • Platform subscriptions. Paid by you directly to the platform. Meta Verified currently runs $14.99 to $499.99 per month per asset. Google Business Profile verification itself is free. The platform's refund policy applies, not ours.

Refunds on our service fee

Before work begins, our fee is refundable in full, for any reason or no reason. Send one email. You do not have to explain yourself.

After work begins, we refund on a pro-rata basis for work not yet performed. We measure that against the written milestones in your engagement letter, not against hours we claim to have spent. Every engagement lists its milestones up front so the math is visible to you before there is ever an argument about it.

Every engagement starts with a pre-flight review before we do anything substantive. If we determine at pre-flight that you cannot qualify, we refund our fee in full and we tell you why in writing. We would rather give the money back on day two than run up a bill on a file that was never going to clear. Common examples: there is no registered trademark to hang a Verified Mark Certificate on, the legal entity does not exist yet or does not match the domain owner, or the address will not survive a Google Business Profile review.

Refunds by service line

The rules above apply to all lines. Here is how they land on each one, plus the third-party cost sitting next to it.

  • Google Business Profile Verify and Rescue, $300 to $800. No certificate authority fee and no platform subscription. Full refund before we start, pro-rata after. Reinstatement work may be quoted pay-on-success, in which case see the next section.
  • Email Compliance Sprint, SPF, DKIM and DMARC, $497 to $1,497. No certificate fee and no platform subscription. Full refund before we start. After that, pro-rata by milestone: audit, record design, staged rollout, and the monitoring window at the end.
  • Logo in the Inbox, BIMI plus a Common Mark Certificate, $1,500 to $2,500. Our fee follows the standard rule. The Common Mark Certificate fee goes to the certificate authority and stops being refundable once they start validation.
  • Gmail Blue Check, BIMI plus a Verified Mark Certificate, $2,000 to $3,000. Same structure. This line has the strictest pre-flight, because it depends on a registered trademark and on an officer of your company completing the certificate authority identity check personally. If pre-flight says the mark will not support a VMC, you get the full fee back.
  • Meta Verified and social badge setup, $250 to $500. Sold as an add-on only, never on its own. Our setup fee follows the standard rule. The subscription is billed by Meta and only Meta can refund it.
  • Trust Monitoring retainer, $50 to $150 per domain per month. Month to month, no lock-in. Cancel any time and it ends at the close of the month you have already paid for. We do not bill again after that. If you prepaid for a longer term, we refund the unused months in full.

Pay-on-success reinstatement work

Some Google Business Profile reinstatements are quoted pay-on-success. Where we agree to that in writing, we bill only if the listing is reinstated. If it is not reinstated, you owe us nothing for that work.

We do not offer pay-on-success on certificate work or on email authentication work. Those have real third-party costs and long validation queues attached, and pricing them on outcome would push us toward exactly the kind of corner-cutting this business exists to avoid.

Pay-on-success is never automatic. If your quote does not say pay-on-success, it is not pay-on-success.

Money you pay to a certificate authority

Certificate authority fees are non-refundable once validation begins. That is the certificate authority's rule and it is close to universal in the industry. Validation is the expensive part for them: they check your legal entity, your domain control, your trademark registration, and they put an officer of your company on a live identity check.

So the moment matters. Before the certificate authority starts validating, you can usually still walk away. After they start, assume the fee is spent.

We will always tell you which side of that line you are on before you authorize the order. If you want to pause and think, tell us before we submit and we will hold. Nobody at our end benefits from you ordering early.

Money you pay to a platform

Platform subscriptions are billed by the platform and refundable only under that platform's own policy, which they change without telling us.

As a general shape, at the time of writing: Meta does not pro-rate a canceled subscription, but it does refund the initial payment if the verification review fails. Do not rely on that summary. Read the current policy on the platform's own help pages before you subscribe, and ask us if you want help finding it.

We are not a party to your subscription. We cannot cancel it for you, we cannot appeal it for you, and we cannot refund it. If a platform owes you money, you have to ask the platform.

When a platform says no

We do not refund our fee because a platform or a certificate authority denied an application.

We want to be blunt about it rather than bury it. Our fee buys correct, complete work through official channels. It does not buy an outcome, because the outcome is not ours to sell. A denial can come from a policy change, a reviewer's judgment call, a trademark office record we do not control, or an address history from before you hired us.

What you get instead of a guarantee is this: we tell you exactly why we think it was denied, we tell you whether it is fixable, and we tell you honestly if it is not. Where the denial has a real appeal or resubmission path, we quote that work separately and clearly. We do not sell you the same application twice and call it new.

When we get it wrong

The flip side of the paragraph above is that we do guarantee our own work.

If an application fails because we made an error, filed the wrong thing, missed a required field, published a broken DNS record, or misread a requirement, we redo the work at our cost. That includes rebuilding the submission and walking it back through the process.

If our error cannot be undone, we refund our fee for the affected work in full. If our error caused you to spend money with a certificate authority or a platform that you would not otherwise have spent, tell us and we will deal with it in good faith rather than hiding behind the fact that we did not receive that money.

How to request a refund

Email us and say what you want refunded and why. There is no form and no queue. A named person will answer you.

We aim to decide within 5 business days and to send approved refunds within 10 business days. Refunds go back through Stripe to the original payment method. Stripe processes our payments, so how fast the money lands after that is between Stripe and your bank.

If you think we owe you money, please ask us before filing a chargeback. A chargeback freezes the conversation and replaces it with a form. We would rather just fix it.

Ending an engagement

Either of us can end an engagement at any time, in writing. There is no cancellation fee and no notice period. You do not have to give a reason.

We may end an engagement for a short list of reasons, and we will tell you which one applies. Those reasons are: the work would breach the acceptable use section below, an invoice has gone unpaid after we have asked twice, we cannot get the delegated access we need to do the job, or you are unable or unwilling to complete the steps that only you can complete.

That last one is worth expanding, because it is the most common. Some steps legally or practically require you in person. An officer of your company has to sit the certificate authority identity check on a live video call with their ID, or in front of a notary. The Google Business Profile verification video has to be recorded by the owner, on site, live in their own app. Platform subscriptions have to be paid on your own payment method. Your own two-factor prompts have to be approved by you. We cannot do any of these for you, and we would not want the kind of access that would let us try.

What happens to work in progress

When an engagement ends, we stop work that day. We do not keep billing a file that is closing.

Within 5 business days we send you a written status of everything in flight. That means the exact DNS record values we designed, the DMARC policy stage you are currently at, any application or case reference numbers, any certificate order numbers, and the documents you gave us at intake.

Certificate orders in flight belong to you, not to us. You are the certificate subject and it is your company on the order. We transfer control of the order to you and we do not cancel it unless you tell us to. We settle the pro-rata refund on our fee at the same time, so the file closes with one number rather than a running argument.

Giving access back, and the access register

We relinquish all access within 7 business days of termination. That covers every path we were given: the Manager role on your Google Business Profile, Meta partner access, DNS delegation at your registrar, and the dedicated admin user in your Google Workspace or Microsoft 365 tenant. Your Letter of Authorization is void from the moment the engagement ends, and we stop acting on it immediately, not at the end of the 7 days.

At handoff you get an access register. It is a written list of every access we held, when it was granted, when it was removed, and who at our end used it. It also lists anything that only you can revoke on your side, because some of these systems will not let a third party remove itself cleanly. We flag those explicitly so nothing is left quietly open.

If you want your intake documents back or deleted, say so and we will do it. We keep only what we are required to keep for tax and business records, and we will tell you what that is.

Acceptable use: who we will work with

We work with real businesses that are what they say they are, run by people authorized to speak for them.

That is the whole test. It sounds obvious. It is also the thing that most often ends an engagement in this industry, because verification programs exist specifically to catch businesses that fail it.

Before we start, we require a scope-limited Letter of Authorization naming the domains and record types we may touch, signed by someone with actual authority to sign it. If you are an agency, a consultant, or an employee acting for a client or an employer, we need authorization from the business itself, not just from you.

Work we will decline or stop

We will decline an engagement, or stop one already underway, in any of these situations. If we stop mid-engagement, we still send the status pack and the access register described above.

We do not do this to be difficult. Every item on this list is something that platforms and certificate authorities are actively looking for, and helping you slip one past them would put your domain, your listing and your business at risk long after our invoice was paid.

  • The business is not what it claims to be. Wrong sector, a front for something else, or an entity that does not really operate.
  • You do not own the business, or you are not authorized to represent it. Verifying someone else's business without their authority is not a gray area.
  • The listing relies on a fake address, or on a virtual office or mailbox address presented as a real place of business, or on a business name stuffed with keywords rather than the name you actually trade under.
  • Anyone asks us to misrepresent facts to a platform or a certificate authority. That includes altered utility bills, backdated documents, a trademark you do not own, someone described as an officer who is not one, or another person sitting the identity check in an officer's place.
  • Anyone asks us to obtain a badge outside official channels. There is no insider, no reseller who can promise approval, and no legitimate way to buy a check mark. If someone has offered you one, they are selling you a problem.
  • Anyone asks us to use the verification or reporting systems against a competitor. We set up your own credentials. We do not file complaints about anyone else.

Misrepresentation to a certificate authority

This one gets its own section because the stakes are different and people do not always realize it.

A certificate authority is not a social platform moderating a badge. It is issuing a cryptographic credential that binds your legal identity and your registered trademark, under audited procedures, with an officer of your company making statements on the record during a live identity check. False statements in that process are a serious matter. They can void the certificate, they can get your organization refused by every participating authority, and depending on the facts they can carry consequences well beyond a rejected application.

We will not participate in any part of it. Not the document, not the phrasing, not the coaching, not the workaround. If we find out mid-engagement, we stop that day and we will not resubmit a tidied-up version of the same false claim under a new order number.

We do ask first. Records go stale, addresses change, an old registration lists a director who left years ago. Most of what we flag turns out to be an honest gap, and we will give you the chance to correct it and carry on. What we will not do is submit something we know to be wrong. That is the entire reason this company exists.

Never send us passwords, ID documents or card numbers

We never accept or store client passwords, government-issued ID documents, or payment card numbers. This is a hard policy and it is not waivable, even if you offer.

We work only through each platform's official delegated-access flow. That means a Manager role in Google Business Profile Manager, partner access in Meta, DNS delegation at your registrar, and a dedicated admin user in your Google Workspace or Microsoft 365 tenant. Every one of those can be granted without a password and revoked without our help, which is exactly why we use them.

We do collect business documents at intake: business registration, licenses, utility bills, bank statements, EIN letters, trademark certificates, logo artwork and storefront photos. Those are business records, not personal credentials, and applications genuinely require them.

If you send us a password, an ID document or a card number anyway, we will delete it, tell you we deleted it, and ask you to rotate the credential. Payments run through Stripe, so we never see or store your card number either.

What we tell platforms about you

We report nothing about you to platforms or certificate authorities beyond what the application itself requires.

We do not volunteer background information. We do not tip anyone off. We do not pass your intake documents to anyone other than the specific application they belong to. If we decline an engagement or stop one for the reasons above, we simply stop. We do not report you to Google, to Meta, or to a certificate authority on our way out.

Two limits on that, stated honestly rather than buried. We will not make a false statement to a platform or a certificate authority to protect a client, including by omission where the application asks a direct question. And we will comply with valid legal process if we ever receive it, and we will tell you about it unless we are legally barred from doing so.

We are an independent agency. We are not affiliated with, endorsed by, or sponsored by any platform or certificate authority we work with.

Questions about this document

Email hello@verifiedeverywhere.com. If something here is unclear or seems unfair, we would rather hear it than have you sign it uneasily.