Legal
Privacy Policy
Last updated: 18 July 2026
1. Introduction
This Privacy Policy explains how Velcio LTD ("Velcio LTD", "Velcio", "we", "us", or "our") collects, uses, and shares personal information when you use the Velcio website, application, and related services (the "Service"). It should be read together with our Terms of Service.
2. Information we collect
Account and profile data
- Sign-in and identity data from Clerk (for example name, email address, username, and authentication identifiers).
- Your Velcio username, which is a public identifier used for assignment and marketplace discovery.
- Profile and preference data you provide during sign-up and onboarding (buyer/developer mode, optional marketplace profile fields, and email preference choices).
- Marketing email consent: whether you opted in to product updates and offers, and the timestamp of that consent when enabled. Opt-in is optional and off by default unless you enable it during onboarding or in Account settings.
- When a developer opts into the public directory, listed profile fields (for example headline, skills, ratings, completed-project count, website or GitHub links, and avatar) are visible to other users of the Service and may be indexed by search engines.
- Date of birth: collected before or during account setup to verify you meet the minimum age requirement (18+). Stored on your Velcio account record.
- Terms acceptance: the date and Terms of Service version identifier you accepted when completing onboarding (for example a dated version string stored on your account).
- Content reports you submit, and records of moderation actions taken on reported content or accounts.
- User-block relationships you create (who you have blocked), used to limit certain interactions in the Service.
Project and workflow data
- Project details, open listings, proposals, messages, price offers, delivery metadata, deployment status, invites, and audit events related to your use of Velcio.
- Delivery archives (ZIP uploads and GitHub snapshots), build metadata, deployment and runtime logs, and Web ingress metadata (for example assigned
*.velcio.apphostnames). Logs and archives may include third-party data (for example Discord or Telegram identifiers, message content a Worker processes, or request data handled by a Web app). Where that information is personal data about end users of your app, the buyer is typically the controller and Velcio processes it as a processor to provide build, deploy, review, and hosting features (see Section 6). - When you connect the Velcio GitHub App for snapshot import, GitHub may provide installation and repository metadata needed to create a delivery snapshot. Velcio uses that access only to import the selected repository content into the Service.
- Production secrets you submit as a buyer. Secrets are stored encrypted for deployment; Velcio does not display decrypted secret values in the user interface.
Payment data
- Payment and payout records processed through Stripe (for example checkout session IDs, payment intent status, connected account IDs, subscription status). Velcio does not store full card numbers. Stripe may collect additional identity or tax information for Connect onboarding under Stripe's own privacy notice.
Technical and operational data
- Logs, build output, deployment logs, worker health signals, queue/job metadata, and security-related events needed to operate and protect the Service.
- Basic device and usage data from your browser (for example IP address, pages visited, and cookies required for authentication).
- Website analytics: aggregated page views, referrer, coarse location (country or region), browser, and device type via Vercel Web Analytics. Velcio does not receive your name or email from this tool; Vercel uses a short-lived hashed identifier rather than advertising cookies. Analytics loads only if you accept analytics cookies.
Communications data
- Transactional emails about your account and projects (for example invites, funding, delivery, hosting status, and receipts). Some categories can be limited in Account settings where the product offers that control.
- Optional marketing email (product updates and offers) only when you have opted in. We store your opt-in choice and consent timestamp. You can withdraw consent at any time in Account settings. Marketing email is separate from transactional email and is not required to use the Service.
3. Legal bases for processing
Under UK GDPR, we process personal information on the following bases, depending on the activity:
- Contract: to provide the Service, authenticate you, process project funding, captures, payouts, and hosting subscriptions, and to record your acceptance of the Terms of Service.
- Consent: for optional website analytics via our cookie banner, for optional marketing email when you opt in, and for any other processing where we ask for consent. You may withdraw analytics consent by choosing Essential only (or clearing the stored choice and selecting again). You may withdraw marketing email consent in Account settings.
- Legitimate interests: to secure the platform, prevent fraud and abuse, maintain audit logs, verify age eligibility, moderate reported content, and operate error monitoring, where those interests are not overridden by your rights.
- Legal obligation: to meet tax, accounting, and regulatory requirements and to respond to lawful requests.
We do not use solely automated decision-making that produces legal or similarly significant effects about you. In-app dispute outcomes are decided by users or Velcio staff.
Where we rely on legitimate interests, you may object to that processing where applicable law allows. Contact us at support@velcio.dev.
4. How we use information
We use personal information to:
- Provide, maintain, and improve the Service.
- Measure and improve website traffic and usability on public pages (with consent).
- Authenticate users and enforce access controls.
- Process project funding, captures, payouts, and hosting subscriptions.
- Build, deploy, and operate buyer Worker and Web apps on managed infrastructure, including review previews and optional post-accept hosting.
- Send transactional emails (for example invites, status updates, and receipts).
- Send marketing email about product updates and offers when you have given consent.
- Detect fraud, abuse, and security incidents; review content reports.
- Comply with legal obligations and respond to lawful requests.
5. How we share information
We share information only as needed to operate the Service. Subprocessors and categories include (examples; the exact vendors may change as we operate the Service):
- Clerk for authentication and account management.
- Stripe for payments, Connect payouts, and subscriptions.
- Email providers (for example Resend) to deliver transactional and, when you opt in, marketing emails.
- Application hosting (for example Heroku) for the API and background workers.
- Worker and build infrastructure (for example Hetzner Cloud) for build hosts and runtime agents that run buyer apps.
- GitHub when you use the Velcio GitHub App to import a repository snapshot for delivery.
- Database providers (for example Neon) for application data.
- Redis / job queue providers (for example Upstash) for background jobs and operational caching.
- Object storage and CDN (for example Cloudflare R2) for delivery artifacts, logs, and public assets such as avatars.
- Vercel: hosts the Velcio website and provides privacy-oriented Web Analytics (page views and aggregated visitor metrics) when you consent.
- Sentry (or an equivalent error-monitoring service) for application crash and error diagnostics.
- Counterparties on your projects (for example buyers see developer identity relevant to a project; developers see buyer contact details needed for delivery).
- Velcio staff admins when reviewing disputes, content reports, or security incidents.
We do not sell your personal information. We may disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale with appropriate safeguards.
6. Secrets, end-user data, and buyer responsibilities
Buyers control production secrets for their projects. Secrets are injected into deployment environments at runtime and are not exposed to developers by default. You are responsible for rotating compromised credentials and for ensuring you have the right to provide secrets to Velcio for hosting.
For personal data about end users of your deployed app (for example Discord or Telegram users a Worker interacts with, or visitors to a Web preview URL) that appears in delivery archives, runtime behaviour, or logs, the buyer is typically the data controller. Velcio acts as a processor and processes that information only to operate build, deploy, review, and hosting features on the buyer's instructions (as configured in the Service). Buyers are responsible for having a lawful basis and any notices required for that end-user data. If you need a data processing agreement, contact support@velcio.dev.
If you opt out of the developer marketplace, we will stop listing your public profile for new discovery. Residual copies may remain in caches or backups for a limited period.
7. Marketing email
We send marketing or promotional email (for example product updates and offers) only with your prior opt-in consent, collected during onboarding or in Account settings. Consent is recorded with a timestamp. Marketing email is optional; refusing or withdrawing consent does not affect your ability to use the Service.
You may withdraw marketing consent at any time in Account settings. Where a marketing message includes an unsubscribe link, you may also use that link. We will stop sending marketing email after withdrawal; you may still receive transactional messages needed to operate your account and projects.
We do not sell your email address. We use our email provider to deliver messages you have consented to receive.
8. Retention
We retain personal information only as long as needed for the purposes below:
- Account and profile data: while your account is active. After a verified deletion request, we aim to delete or anonymise account profile fields within 30 days, except where a longer period is required (for example linked payment or dispute records).
- Payment and accounting records: typically up to six or seven years where needed for tax, accounting, or dispute resolution.
- Project audit trails, messages, and offers: for as long as needed to operate the Service, resolve disputes, and meet legal obligations; often aligned with payment retention where records are linked (commonly up to six or seven years for funded projects).
- Build, deploy, and operational logs: typically up to 90 days for routine debugging and abuse prevention, then deleted or aggregated, unless a security or legal investigation requires longer retention.
- Date of birth: retained for the life of the account for age-eligibility and compliance, then deleted or anonymised with the account; not used for marketing.
- Marketing consent records: while your marketing opt-in is active, and for a reasonable period afterward (typically up to two years) to demonstrate lawful consent if needed; cleared or updated when you withdraw consent in Account settings.
- Content reports: retained as needed to handle the report and for a reasonable period afterward for safety and abuse prevention (typically up to two years).
9. Security
We use administrative, technical, and organisational measures designed to protect personal information, including encryption for secrets at rest and access controls on project data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO and affected individuals as required by UK GDPR.
10. Your rights and choices
Under UK GDPR (and similar laws where they apply), you may have the right to:
- access your personal information;
- rectify inaccurate personal information;
- erase personal information in certain circumstances;
- restrict processing in certain circumstances;
- data portability where processing is automated and based on contract or consent;
- object to processing based on legitimate interests, including profiling where relevant;
- withdraw consent where processing is based on consent, without affecting prior lawful processing.
You can update much of your account information in the Service, including marketing email opt-in and other email notification preferences in Account settings. You can also download a copy of your personal data from Account settings (Your data). For other requests, contact us at support@velcio.dev. We aim to respond within one month (or as otherwise required by law).
Account deletion. You can schedule account deletion in Account settings (Your data). Deletion is not immediate: after you confirm, there is a 30-day grace period during which you can cancel. When deletion finalises, we anonymise account profile fields and remove sign-in access, usually within the retention window described above, subject to legal or accounting retention for project and payment records. You may also email support@velcio.dev from the address associated with your account if you need help.
If you are in the UK, you may lodge a complaint with the Information Commissioner's Office (ICO). If you are in the EEA, you may also lodge a complaint with your local data protection authority.
11. International transfers
We and our subprocessors may process data in the United Kingdom, European Economic Area, United States, and other countries (for example when using US-based authentication, payments, hosting, analytics, or error-monitoring providers). Where a transfer requires a safeguard under UK GDPR, we use appropriate mechanisms such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK addendum, or another lawful transfer tool recognised under UK law.
13. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe we have collected information from someone under 18, contact us and we will take appropriate steps to delete it.
14. Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate.
15. Contact
Privacy questions or requests: support@velcio.dev
Velcio LTD is the data controller for personal information processed through the Service (except where we act as a processor for your app's end-user data under Section 6). Registered address: Office 6995, 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ.