Velora.Privacy Policy

Privacy Policy

Effective date: June 2026

This policy explains what data Velora collects, why, and how you can control it.

1. Who We Are

Velora ("we", "us", "our") operates payvelora.com. We provide cryptocurrency payment infrastructure for merchants and non-custodial wallets for individuals. Our registered address is: [YOUR ADDRESS — fill in before publishing].

For GDPR purposes, Velora is the Data Controller. For questions, contact us at privacy@payvelora.com.

2. Data We Collect

DataWhen collectedWhy
NameAccount registrationPersonalisation, account identification
Email addressAccount registrationAccount access, important notices
Password (hashed)Registration / password changeAuthentication (we store only a bcrypt hash, never the raw password)
Wallet addressWallet creationBlockchain transactions, balance display
Encrypted keystoreWallet creationSecure key storage (encrypted client-side; we cannot decrypt it)
Transaction historyBlockchain (read-only)Balance and history display (read from public blockchain)
IP addressEvery requestRate limiting, fraud prevention, security logs
Browser / device infoEvery requestSecurity anomaly detection
Payment metadataMerchant creates chargeCharge identification and webhook delivery

3. What We Do NOT Collect

  • Private keys — your private key is generated and encrypted in your browser. We never receive it.
  • Wallet passwords — your wallet password never leaves your browser.
  • Payment card details — card payments via Transak go directly to Transak, not Velora.
  • Government ID — we do not currently require identity verification.
  • Biometric data — we collect none.

4. How We Use Your Data

  • To provide and operate the Velora service
  • To authenticate your account and prevent unauthorised access
  • To send transactional emails (verification, password reset, payment notifications)
  • To detect and prevent fraud and abuse
  • To comply with legal obligations

We do not sell your data to third parties. We do not use your data for advertising.

5. Third-Party Services We Use

ServicePurposeData shared
Railway (hosting)API server and database hostingAll server-side data (encrypted at rest)
Vercel (hosting)Website hostingHTTP logs, IP addresses
AlchemyBlockchain data accessWallet addresses (public blockchain addresses)
Resend / SMTPTransactional email deliveryEmail address and email content
Transak (optional)Crypto on-ramp/off-rampWallet address; Transak collects payment data directly
CloudflareDNS, DDoS protection, CDNIP address, HTTP metadata
Sentry (optional)Error monitoringError traces (no personal data in errors)

6. Cookies

Velora uses one cookie: a session cookie named token. This is an httpOnly, Secure cookie containing a signed JWT (JSON Web Token) that identifies your logged-in session. It expires after 7 days.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

7. Data Retention

Data typeRetention period
Account data (name, email)Until account deletion request
Payment / charge records7 years (financial record legal requirement)
Wallet address + keystoreUntil account deletion
Server access logs90 days
Email verification tokens24 hours (auto-expire)
Password reset tokens1 hour (auto-expire)

8. Your Rights (GDPR / CCPA)

Depending on your location, you may have the following rights:

  • Access: request a copy of all data we hold about you
  • Rectification: correct inaccurate data
  • Erasure: request deletion of your account and associated data
  • Data portability: receive your data in a machine-readable format
  • Objection: object to processing for legitimate interests
  • Withdrawal of consent: where processing is consent-based

To exercise these rights, email privacy@payvelora.com. We will respond within 30 days.

9. Data Security

We implement the following security measures:

  • All data transmitted over HTTPS/TLS 1.3
  • Passwords stored with bcrypt (cost factor 10)
  • API keys stored as bcrypt hashes
  • Wallet keystores are AES-256-GCM encrypted before reaching our servers
  • Database access restricted to the API server only (no public exposure)
  • Regular security dependency updates

10. Children's Privacy

Velora is not directed at children under 18. We do not knowingly collect personal information from children. If we become aware that a child has provided personal data, we will delete it promptly.

11. International Transfers

Your data may be processed in the United States (Railway, Vercel, Alchemy) and/or the European Union. Where data is transferred outside your home jurisdiction, we ensure appropriate safeguards are in place (Standard Contractual Clauses for EU data subjects). ← Review this section with a lawyer before publishing in the EU.

12. Changes to This Policy

We may update this Privacy Policy. We will notify you by email for material changes. The effective date at the top will always reflect the latest version.

13. Contact

Data protection questions: privacy@payvelora.com
General contact: hello@payvelora.com