Legal
Privacy Policy
Last update: 13 August 2026
Velcio LTD ("Velcio LTD", "Velcio", "we", "us", or "our") processes personal information for the Velcio website, applications and related products (the "Service"), currently Velcio Marketplace, Velcio Cloud and Matz. Read this Privacy Policy (this "Policy") with our Terms of Service. Registered address: Office 6995, 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ. Company number: 17327605.
Creating an account or using the Service means you acknowledge this Policy. We may update it. Changes take effect on the "Last updated" date on this page. For material changes we may also notify you in the Service or by email.
1. The short version
This summary is for convenience only. The full Policy below controls.
- Information we collect
- Account and profile data are shared across Velcio (via Clerk). Product data is separate: Marketplace projects and disputes, Cloud build/hosting/runtime data, and Matz prompts and workspaces. We also collect logs, essential cookies, Stripe payment metadata and (with consent) website analytics.
- Legal bases
- Under UK GDPR: contract, consent (analytics and marketing email), legitimate interests (security, fraud prevention, moderation) and legal obligation.
- How we use it
- To run the Service (auth, Marketplace payments, Cloud hosting, Matz runs), send transactional email, send optional product-updates or marketing email you opt into, and for security and compliance.
- How long we keep it
- Only as needed. Profile fields are usually anonymised within 30 days after verified deletion (after a 30-day grace period). Payment and project records may be kept up to six years. Routine build and ops logs are typically kept up to 90 days.
- Sharing
- Named providers you use directly (Clerk, Stripe and GitHub when connected), plus infrastructure processors for hosting, email, storage and (with consent) analytics. We do not sell personal information. Marketplace counterparties and Velcio staff may see project details needed for delivery, disputes or security.
- Where we process
- UK, EEA, US and other countries via subprocessors, with UK GDPR transfer tools where required (for example IDTA or SCCs with UK addendum).
- Cookies
- Essential cookies always run. Optional analytics load only if you accept them in the cookie banner. See Section 12.
- Your rights
- Access, correct, export or delete much of your data in Account settings, or email support@velcio.dev for other UK GDPR requests. We respond within one month of a verified request (extendable by up to two months for complex cases).
- Children
- The Service is for users 18+. We do not knowingly collect data from children.
- Contact
- support@velcio.dev. Controller details are in Section 15.
2. Information we collect
Categories depend on the products you use. Account identity is shared across the platform. Marketplace, Cloud and Matz product data are separate and are not fused into one "project" record for privacy purposes.
Account and profile data (shared)
- Sign-in and identity data from Clerk (name, email, username and authentication identifiers). One Velcio account may access more than one product.
- Your Velcio username, a public identifier for assignment and marketplace discovery where those features apply.
- Profile and preference data from sign-up and onboarding (for example Marketplace buyer/developer mode, optional profile fields and email preferences).
- Email consent: whether you opted in to product-updates email for Velcio Marketplace, Velcio Cloud and/or Matz, and to marketing email across Velcio, plus consent timestamps. Each opt-in is optional and off by default unless you enable it in onboarding or Account settings.
- If a developer opts into the public Marketplace directory, listed profile fields (headline, skills, ratings, completed-project count, links and avatar) are visible to other users and may be indexed by search engines.
- Date of birth: collected to verify the 18+ age requirement and stored on your account.
- Terms acceptance: date and Terms of Service version you accepted during onboarding.
- Content reports you submit, moderation records, and user-block relationships you create.
Velcio Marketplace project data
- Project details, listings, proposals, messages, price offers, delivery metadata, invites, dispute records (remediation terms, accept windows, remove/takeover timestamps and outcomes) and related audit events.
- Collaboration files you upload (reference documents, images or handoff ZIPs), including filename, size and scan status. Contents are stored for collaboration and disputes and deleted under retention and account-deletion rules. After a developer is removed from an open dispute, that developer may only access files created before removal. The buyer and Velcio staff may use later files for resolution and takeover.
- When you connect the Velcio GitHub App for Marketplace delivery import, GitHub may provide installation and repository metadata needed to import the selected content.
- Review preview and optional post-accept hosting run on Velcio Cloud. Build, deploy, runtime and hostname data for those workloads are Cloud data.
Velcio Cloud build, hosting and runtime data
- App inventory and metadata (names, project types, plan or subscription status, hostnames such as
*.velcio.app). - Delivery archives (ZIP uploads and source-control snapshots), build metadata, deployment and runtime logs, Web ingress metadata and worker health signals.
- Production secrets you submit. Secrets are stored encrypted for deployment. Velcio does not show decrypted secret values in the UI.
- Logs and archives may include third-party or end-user data from apps you deploy. Where that is personal data about your app's end users, you are typically the controller and Velcio is a processor (see Section 6).
- This category covers apps created in Cloud, Marketplace review previews and hosting on Cloud, and Matz deploy or promote flows that use Cloud.
Matz prompts, workspaces and agent events
- Prompts, chat messages, clarifying answers and product or stack decisions in Matz threads.
- Agent run records (status, trigger, billing metadata, errors) and events used to show run progress.
- Workspace archives and related grade or preview metadata.
- Pre-run cancel/revert snapshots and restore metadata, retained as needed to complete or abandon a restore.
- Optional GitHub connection metadata for workspace sync where you connect source control.
- Preview deploy and promote create or update Cloud apps. Those records are Cloud data.
Payment data
- Payment and payout records via Stripe (checkout session IDs, payment intent status, connected account IDs, subscription status, Matz charges). Velcio does not store full card numbers. Stripe may collect identity or tax data for Connect under Stripe's own privacy notice.
Technical and operational data
- Logs, security events, queue or job metadata and infrastructure signals across products.
- Basic device and usage data (for example IP address, pages visited and authentication cookies).
- Website analytics (with consent): aggregated page views, referrer, coarse location, browser and device type via Vercel Web Analytics. Velcio does not receive your name or email from this tool. Vercel uses a short-lived hashed identifier, not advertising cookies.
Communications data
- Transactional emails about your account and product activity (Marketplace invites, funding, delivery and disputes, Cloud hosting status, Matz run or billing notices). Some categories can be limited in Account settings.
- Optional product-updates and marketing email only when you opt in. We store each opt-in and timestamp. You can withdraw consent in Account settings. Marketing email is not required to use the Service.
3. Legal bases for processing
Under UK GDPR we process personal information on these bases:
- Contract: to provide the Service, authenticate you, process Marketplace funding and payouts, Cloud hosting, Matz billing and related features, and to record Terms acceptance.
- Consent: optional analytics, product-updates and marketing email, and other processing where we ask for consent. Withdraw analytics consent in Account settings (Cookie preferences) or by resetting the cookie banner choice. Withdraw email consent in Account settings.
- Legitimate interests: security, fraud and abuse prevention, audit logs, age eligibility, content moderation and error monitoring, where not overridden by your rights.
- Legal obligation: tax, accounting, regulatory duties and lawful requests.
We do not use solely automated decision-making that produces legal or similarly significant effects about you. Marketplace dispute outcomes are decided by users or Velcio staff.
Where we rely on legitimate interests, you may object where law allows. Contact support@velcio.dev.
4. How we use information
We use personal information to:
- Provide, maintain and improve the Service.
- Measure public website traffic and usability (with consent).
- Authenticate users and enforce access controls.
- Operate Velcio Marketplace: funding, captures, payouts, delivery and disputes (including remediation, developer remove, admin takeover, refunds and payout holds).
- Operate Velcio Cloud: build, deploy and host apps, including review previews, takeover builds and optional post-accept hosting.
- Operate Matz: agent workspaces, prompts and events, cancel/revert snapshots and related billing.
- Send transactional email.
- Send product-updates or marketing email when you have consented.
- Detect fraud, abuse and security incidents. Review content reports.
- Comply with legal obligations and respond to lawful requests.
6. Secrets, end-user data and customer responsibilities
You control production secrets for apps you deploy on Velcio Cloud. Secrets are injected at runtime and are not exposed to Marketplace developers by default. You must rotate compromised credentials and have the right to provide secrets to Velcio for hosting.
For personal data about end users of your Cloud-hosted app (for example from third-party platforms a Worker uses, or visitors to a preview or hosting URL) that appears in archives, runtime behaviour or logs, you are typically the data controller. Velcio acts as a processor and processes that data only to operate build, deploy, review and hosting on your instructions in the Service. You need a lawful basis and any required notices for that end-user data. For a data processing agreement, contact support@velcio.dev.
Matz prompts and workspace content are processed to provide the builder. Do not submit content you are not entitled to use. Apps promoted from Matz follow the Cloud controller/processor rules above for their end users.
If you leave the Marketplace developer directory, we stop listing your profile for new discovery. Residual copies may remain in caches or backups for a short period (typically up to 30 days).
7. Marketing email
We send product-updates email only with your prior opt-in for that product, and marketing or promotional email only with shared marketing opt-in (onboarding or Account settings). Consent is timestamped per category. Opt-in is optional and does not affect access to the Service.
Withdraw consent any time in Account settings, or via an unsubscribe link where provided. We stop marketing email after withdrawal. Transactional messages needed to run your account may continue. We do not sell your email address.
8. Retention
We keep personal information only as long as needed:
- Account and profile data: while the account is active. After a verified deletion request we aim to delete or anonymise profile fields within 30 days, except where linked payment or dispute records require longer.
- Payment and accounting records: typically up to six years (or longer if a specific legal requirement applies).
- Marketplace project records (messages, offers, disputes, remediation and remove/takeover timestamps): as needed to operate the Service, resolve disputes and meet legal duties, often aligned with payment retention (commonly up to six years for funded projects).
- Cloud build, deploy and operational logs: typically up to 90 days, then deleted or aggregated, unless a security or legal matter needs longer.
- Matz prompts, events and workspace archives: while the project is active and for a reasonable period afterward for billing, support, cancel/revert and abuse prevention, then deleted or anonymised with account or project deletion unless a longer legal retention applies.
- Matz cancel snapshots: as needed to complete or abandon restore, then removed under cleanup rules.
- Date of birth: for the life of the account for age eligibility, then deleted or anonymised with the account. Not used for marketing.
- Email consent records: while the opt-in is active, and typically up to two years afterward to demonstrate lawful consent. Updated when you withdraw consent.
- Content reports: as needed to handle the report and typically up to two years afterward for safety and abuse prevention.
9. Security
We use administrative, technical and organisational measures designed to protect personal information, including encryption for secrets at rest and access controls on project and workspace data. No method of transmission or storage is completely secure.
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO and affected individuals as required by UK GDPR.
10. Your rights and choices
Under UK GDPR (and similar laws where they apply), you may have the right to:
- access your personal information
- rectify inaccurate personal information
- erase personal information in certain circumstances
- restrict processing in certain circumstances
- data portability where processing is automated and based on contract or consent
- object to processing based on legitimate interests, including profiling where relevant
- withdraw consent where processing is based on consent, without affecting prior lawful processing
Update account information, email preferences and download a copy of your personal data in Account settings (Your data). For other requests, email support@velcio.dev from the address on your account so we can verify identity. Under UK GDPR we respond within one month of a verified request. For complex or multiple requests we may extend by up to two further months and will tell you within the first month if we need to.
Account deletion. Schedule deletion in Account settings (Your data). After you confirm there is a 30-day grace period during which you can cancel. When deletion finalises we anonymise profile fields and remove sign-in access, subject to legal or accounting retention for project and payment records. Email support@velcio.dev if you need help.
In the UK you may complain to the Information Commissioner's Office (ICO). In the EEA you may also complain to your local data protection authority.
11. International transfers
We and our subprocessors may process data in the United Kingdom, European Economic Area, United States and other countries. Where UK GDPR requires a transfer safeguard, we use tools such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK addendum, or another lawful transfer tool recognised under UK law.
13. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal information. If you believe we have, contact us and we will delete it.
14. Changes
We may update this Policy. Revised text is posted on this page with an updated "Last updated" date. Material changes may also be communicated in the Service or by email.
15. Contact
Privacy questions or requests: support@velcio.dev
Velcio LTD is the data controller for personal information processed through the Service (except where we act as a processor for your Cloud app's end-user data under Section 6). Registered address: Office 6995, 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ. Company number: 17327605.