Privacy Policy
Last updated: 2026-05-19
This Privacy Policy explains what data Velantio ("we", "us") collects, how we use it, and the choices you have. It applies to velantio.com, the embed bundle served at velantio.com/v1/e.js, and the Velantio WordPress plugin.
What we collect
Account data
When you sign up, we store your email address and a salted-and-hashed password. We do not have access to your plaintext password. We may store an optional display name you provide.
Amazon credentials you connect
If you connect your Amazon Creators API credentials, we store:
- Your Amazon Credential ID (the OAuth client identifier)
- Your Credential Secret, encrypted at rest with AES-256-GCM
- Your Amazon Associates partner tag and chosen marketplace
The encryption key never leaves our server and is not accessible to our employees in plaintext via any UI. We never log credential values.
Your tables and product data
We store the configurations of any tables you create, including names, theme choices, column toggles, and product entries (ASINs, titles, prices, images, URLs, ratings — all data fetched from Amazon under your credentials, plus any manual entries).
Analytics events from your published tables
When a visitor views or clicks a product in a table you've embedded, we record:
- The table ID
- The event type (view or click)
- The product ASIN (clicks only)
- A salted SHA-256 hash of the visitor's IP address
- A truncated user-agent string
- The timestamp
The IP salt rotates every 24 hours. We do not store raw IP addresses. We do not set cookies on visitors' browsers. We do not associate analytics events with any user identity.
Billing data
Stripe processes our payments. When you purchase, Stripe collects your name, email, billing address, and payment method details. We receive only:
- A Stripe Customer ID
- The email used at purchase
- Subscription / purchase status events via webhook
We never see your full card number or CVV.
Logs and operational data
We collect standard web-server logs (request timestamps, paths, response codes, user-agent strings) for security and operational debugging. These are retained for 30 days unless an incident requires longer retention.
What we don't collect
- We don't track you across the web.
- We don't sell or share your data with advertising networks.
- We don't use third-party analytics like Google Analytics or Facebook Pixel inside the dashboard.
- We don't read or store the contents of Amazon API responses beyond what's required to populate your tables.
How we use what we collect
We use your data to:
- Operate the Service (sign you in, render your dashboard, serve your embeds)
- Send transactional emails (password resets, billing receipts, account alerts)
- Maintain operational security and prevent abuse
- Aggregate anonymous usage statistics to improve the product
We do not use your data for behavioral advertising or marketing emails without your explicit consent.
Third-party services we share data with
- Supabase — provides our authentication and database. Subject to Supabase's Privacy Policy.
- Stripe — processes payments. Subject to Stripe's Privacy Policy.
- Cloudflare — provides CDN and DNS for velantio.com. Subject to Cloudflare's Privacy Policy.
- Amazon — when you connect Amazon credentials, your API requests go directly from our server to Amazon. We do not share data with Amazon beyond what's required by their PA-API protocol.
We do not share data with any other third party except as required by law.
Cookies
Velantio uses session cookies for authentication on the dashboard at velantio.com/dashboard. These are first-party, secure, HTTP-only cookies. We do not use tracking cookies.
The public embed at velantio.com/v1/e.js does not set cookies on visitors' browsers.
Data retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion.
- Tables and products: same as account data.
- Analytics events: retained per your plan's retention window (7 days on the free plan, 90 days on the paid Tables plan). Older events are deleted by a daily cron job.
- Billing data: retained for 7 years for tax and accounting compliance, per applicable regulations.
- Logs: retained for 30 days.
Your rights
If you're in the EU, UK, or California, you have:
- Right to access — request a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — delete your account and data
- Right to data portability — export your data
- Right to object — to processing based on legitimate interest
To exercise any of these, email hello@velantio.com from the address associated with your account. We respond within 30 days.
You can also delete your account directly from /dashboard/settings.
Children
Velantio is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from minors. If we learn that a minor has created an account, we delete it.
International transfers
We are based in Slovenia. Your data may be processed in any region where our infrastructure providers operate (typically EU and US). Standard contractual clauses are in place with all subprocessors.
Security
We use industry-standard practices: HTTPS everywhere, AES-256-GCM encryption for sensitive credentials, salted password hashing, least-privilege access for our team, regular dependency updates, and short-lived session tokens.
No system is 100% secure. If a breach occurs that affects your data, we'll notify you within 72 hours per applicable law.
Changes
We may update this policy. Material changes are announced via email and posted here with a new "Last updated" date.
Contact
Privacy questions: hello@velantio.com.
For EU/UK users: this email is also our designated GDPR contact. We do not currently have an external Data Protection Officer.