Privacy Policy
Effective date: June 2026
This policy explains what data Velora collects, why, and how you can control it.
1. Who We Are
Velora ("we", "us", "our") operates payvelora.com. We provide cryptocurrency payment infrastructure for merchants and non-custodial wallets for individuals. Our registered address is: [YOUR ADDRESS — fill in before publishing].
For GDPR purposes, Velora is the Data Controller. For questions, contact us at privacy@payvelora.com.
2. Data We Collect
| Data | When collected | Why |
|---|---|---|
| Name | Account registration | Personalisation, account identification |
| Email address | Account registration | Account access, important notices |
| Password (hashed) | Registration / password change | Authentication (we store only a bcrypt hash, never the raw password) |
| Wallet address | Wallet creation | Blockchain transactions, balance display |
| Encrypted keystore | Wallet creation | Secure key storage (encrypted client-side; we cannot decrypt it) |
| Transaction history | Blockchain (read-only) | Balance and history display (read from public blockchain) |
| IP address | Every request | Rate limiting, fraud prevention, security logs |
| Browser / device info | Every request | Security anomaly detection |
| Payment metadata | Merchant creates charge | Charge identification and webhook delivery |
3. What We Do NOT Collect
- Private keys — your private key is generated and encrypted in your browser. We never receive it.
- Wallet passwords — your wallet password never leaves your browser.
- Payment card details — card payments via Transak go directly to Transak, not Velora.
- Government ID — we do not currently require identity verification.
- Biometric data — we collect none.
4. How We Use Your Data
- To provide and operate the Velora service
- To authenticate your account and prevent unauthorised access
- To send transactional emails (verification, password reset, payment notifications)
- To detect and prevent fraud and abuse
- To comply with legal obligations
We do not sell your data to third parties. We do not use your data for advertising.
5. Third-Party Services We Use
| Service | Purpose | Data shared |
|---|---|---|
| Railway (hosting) | API server and database hosting | All server-side data (encrypted at rest) |
| Vercel (hosting) | Website hosting | HTTP logs, IP addresses |
| Alchemy | Blockchain data access | Wallet addresses (public blockchain addresses) |
| Resend / SMTP | Transactional email delivery | Email address and email content |
| Transak (optional) | Crypto on-ramp/off-ramp | Wallet address; Transak collects payment data directly |
| Cloudflare | DNS, DDoS protection, CDN | IP address, HTTP metadata |
| Sentry (optional) | Error monitoring | Error traces (no personal data in errors) |
6. Cookies
Velora uses one cookie: a session cookie named token. This is an httpOnly, Secure cookie containing a signed JWT (JSON Web Token) that identifies your logged-in session. It expires after 7 days.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
7. Data Retention
| Data type | Retention period |
|---|---|
| Account data (name, email) | Until account deletion request |
| Payment / charge records | 7 years (financial record legal requirement) |
| Wallet address + keystore | Until account deletion |
| Server access logs | 90 days |
| Email verification tokens | 24 hours (auto-expire) |
| Password reset tokens | 1 hour (auto-expire) |
8. Your Rights (GDPR / CCPA)
Depending on your location, you may have the following rights:
- Access: request a copy of all data we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your account and associated data
- Data portability: receive your data in a machine-readable format
- Objection: object to processing for legitimate interests
- Withdrawal of consent: where processing is consent-based
To exercise these rights, email privacy@payvelora.com. We will respond within 30 days.
9. Data Security
We implement the following security measures:
- All data transmitted over HTTPS/TLS 1.3
- Passwords stored with bcrypt (cost factor 10)
- API keys stored as bcrypt hashes
- Wallet keystores are AES-256-GCM encrypted before reaching our servers
- Database access restricted to the API server only (no public exposure)
- Regular security dependency updates
10. Children's Privacy
Velora is not directed at children under 18. We do not knowingly collect personal information from children. If we become aware that a child has provided personal data, we will delete it promptly.
11. International Transfers
Your data may be processed in the United States (Railway, Vercel, Alchemy) and/or the European Union. Where data is transferred outside your home jurisdiction, we ensure appropriate safeguards are in place (Standard Contractual Clauses for EU data subjects). ← Review this section with a lawyer before publishing in the EU.
12. Changes to This Policy
We may update this Privacy Policy. We will notify you by email for material changes. The effective date at the top will always reflect the latest version.
13. Contact
Data protection questions: privacy@payvelora.com
General contact: hello@payvelora.com