The government site doesn't have to know anything about you either, other than you requested a beer token.
That's the 7th beer token you've requested this week, citizen. For your own good, we've denied your request.
Gov might require that on each sale, company re-verify identity (just like they demand you check ID on each sale).
That results in a network request to `proof.verificationMethod` on each sale, which contain a URL to the age verification for that one user.
Done. Gov now have records on how many times you bought beer. They might also request that the number/description of items be included on the verification request. but that is not necessary since credit cards are already being replaced with central bank issued payment systems (see india, brazil, etc)
You say decentralized, yet that Verifiable Data Registry seems like a central component to checking whether you are you. How is that not able to see that you checked your ID?
Also, the ID in the VC is not something that can easily be used to identify you. It may be in basic implementations, but it shouldn't. The W3C spec recommends using DID[1]... A DID is a random ID, basically, which is stored in the "distributed ledger" where others can find your current keys and other metadata (none of which containing personal data)... you can have as many DIDs as you want, e.g. one for each usage you make of your VCs, making it impossible to track you around... you should look at the W3C spec if you really want to understand how DIDs and VCs are supposed to work, the Auth0 website is a much lighter , pre-digested and somewhat more centralized version of things that make it much easier to get started (Which is a great thing, but hopefully you shouldn't judge VCs from only what they're pushing).
[1] https://www.w3.org/TR/vc-data-model/#dfn-decentralized-ident...