Privacy Policy
Last update: 31 July 2026
Velcio LTD ("Velcio LTD", "Velcio", "we", "us", or "our") is committed to protecting the personal information of people who use the Velcio website, application and related services (the "Service"). Please read this Privacy Policy (this "Policy") carefully to understand how we process personal information. Our registered address is Office 6995, 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ. Company number: 17327605. This Policy should be read together with our Terms of Service.
By creating an account or using the Service, you acknowledge that you have read and understood this Policy. We may update it from time to time. Changes are posted on this page and take effect as of the stated "Last updated" date. Where required by law, we will also take other steps for material changes, including notice through the Service or by email. We recommend checking this Policy periodically.
1. The short version
This summary is for convenience only. The full Policy below is the binding description of our practices.
- Information we collect
- Most information comes from you: account and profile details, date of birth, Terms acceptance, project and dispute records, delivery archives, encrypted secrets, and messages. We also collect technical and operational data (including logs and essential cookies), payment metadata via Stripe and (only with consent) website analytics.
- Legal bases
- We process personal information under UK GDPR on contract, consent (for optional analytics and marketing email), legitimate interests (security, fraud prevention, moderation), and legal obligation.
- How we use it
- To run the Service: authentication, funding and payouts, builds and hosting, in-app disputes (including remediation and admin takeover), transactional email, optional marketing email you opt into, and security and compliance.
- How long we keep it
- Only as long as needed. Profile fields are usually anonymised within 30 days after a verified deletion request (subject to a 30-day grace period). Payment and project records may be kept up to six years where required. Routine build and ops logs are typically kept up to 90 days.
- Sharing
- We use named providers you interact with directly (Clerk, Stripe, and GitHub when you connect it), plus categories of infrastructure processors for hosting, email, storage and (with consent) analytics. We do not sell personal information. We may share project-relevant details with your counterparty and Velcio staff for disputes or security.
- Where we process
- In the UK, EEA, US and other countries via our subprocessors, with UK GDPR transfer safeguards where required (for example IDTA or SCCs with UK addendum).
- Cookies
- Essential cookies for sign-in and security always run. Optional analytics load only if you accept them in the cookie banner. See Section 12.
- Your rights
- You may access, correct, export, or delete much of your data in Account settings, and make other UK GDPR requests by emailing support@velcio.dev. We respond within one month of a verified request (extendable by up to two further months for complex cases).
- Children
- The Service is for users 18+. We do not knowingly collect data from children.
- Contact
- Privacy questions: support@velcio.dev. Full controller details are in Section 15.
2. Information we collect
Account and profile data
- Sign-in and identity data from Clerk (for example name, email address, username, and authentication identifiers).
- Your Velcio username, which is a public identifier used for assignment and marketplace discovery.
- Profile and preference data you provide during sign-up and onboarding (buyer/developer mode, optional marketplace profile fields and email preference choices).
- Platform updates email consent: whether you opted in to emails about significant Velcio features and changes, and the timestamp of that consent when enabled. Opt-in is optional and off by default.
- Marketing email consent: whether you opted in to offers and promotions, and the timestamp of that consent when enabled. Opt-in is optional and off by default unless you enable it during onboarding or in Account settings.
- When a developer opts into the public directory, listed profile fields (for example headline, skills, ratings, completed-project count, website or GitHub links and avatar) are visible to other users of the Service and may be indexed by search engines.
- Date of birth: collected before or during account setup to verify you meet the minimum age requirement (18+). Stored on your Velcio account record.
- Terms acceptance: the date and Terms of Service version identifier you accepted when completing onboarding (for example a dated version string stored on your account).
- Content reports you submit, and records of moderation actions taken on reported content or accounts.
- User-block relationships you create (who you have blocked), used to limit certain interactions in the Service.
Project and workflow data
- Project details, open listings, proposals, messages, price offers, delivery metadata, deployment status, invites, dispute records (including remediation terms, accept windows, developer-remove and admin-takeover timestamps and resolution outcomes), and audit events related to your use of Velcio.
- Project collaboration files you upload (for example reference documents, images, or handoff ZIP archives), including filename, size and scan status metadata. File contents are stored to support collaboration and disputes and are deleted according to our retention and account-deletion processes. After a developer is removed from an open dispute, that developer may only access files created before removal. Buyer and Velcio staff may continue to use later files for resolution and takeover delivery.
- Delivery archives (ZIP uploads and GitHub snapshots), build metadata, deployment and runtime logs, and Web ingress metadata (for example assigned
*.velcio.apphostnames). Logs and archives may include third-party data (for example identifiers or message content a Worker processes, or request data handled by a Web app). Where that information is personal data about end users of your app, the buyer is typically the controller and Velcio processes it as a processor to provide build, deploy, review and hosting features (see Section 6). - When you connect the Velcio GitHub App for snapshot import, GitHub may provide installation and repository metadata needed to create a delivery snapshot. Velcio uses that access only to import the selected repository content into the Service.
- Production secrets you submit as a buyer. Secrets are stored encrypted for deployment; Velcio does not display decrypted secret values in the user interface.
Payment data
- Payment and payout records processed through Stripe (for example checkout session IDs, payment intent status, connected account IDs, subscription status). Velcio does not store full card numbers. Stripe may collect additional identity or tax information for Connect onboarding under Stripe's own privacy notice.
Technical and operational data
- Logs, build output, deployment logs, worker health signals, queue/job metadata, and security-related events needed to operate and protect the Service.
- Basic device and usage data from your browser (for example IP address, pages visited, and cookies required for authentication).
- Website analytics: aggregated page views, referrer, coarse location (country or region), browser and device type via Vercel Web Analytics. Velcio does not receive your name or email from this tool. Vercel uses a short-lived hashed identifier rather than advertising cookies. Analytics loads only if you accept analytics cookies.
Communications data
- Transactional emails about your account and projects (for example invites, funding, delivery, hosting status, dispute remediation or developer-remove notices, and receipts). Some categories can be limited in Account settings where the product offers that control.
- Optional platform-updates email (significant features and changes) and optional marketing email (offers and promotions) only when you have opted in to each. We store your opt-in choice and consent timestamp for each. You can withdraw consent at any time in Account settings. Marketing email is separate from transactional email and is not required to use the Service.
3. Legal bases for processing
Under UK GDPR, we process personal information on the following bases, depending on the activity:
- Contract: to provide the Service, authenticate you, process project funding, captures, payouts and hosting subscriptions and to record your acceptance of the Terms of Service.
- Consent: for optional website analytics via our cookie banner, for optional marketing email when you opt in, and for any other processing where we ask for consent. You may withdraw analytics consent in Account settings (Cookie preferences) or by clearing the stored choice and selecting again. You may withdraw marketing email consent in Account settings.
- Legitimate interests: to secure the platform, prevent fraud and abuse, maintain audit logs, verify age eligibility, moderate reported content and operate error monitoring, where those interests are not overridden by your rights.
- Legal obligation: to meet tax, accounting and regulatory requirements and to respond to lawful requests.
We do not use solely automated decision-making that produces legal or similarly significant effects about you. In-app dispute outcomes (including remediation, developer remove, refund, release to developer and admin takeover) are decided by users or Velcio staff.
Where we rely on legitimate interests, you may object to that processing where applicable law allows. Contact us at support@velcio.dev.
4. How we use information
We use personal information to:
- Provide, maintain and improve the Service.
- Measure and improve website traffic and usability on public pages (with consent).
- Authenticate users and enforce access controls.
- Process project funding, captures, payouts and hosting subscriptions.
- Operate in-app disputes, including remediation windows, freezing developer access after remove, admin takeover delivery, refunds and related payout holds.
- Build, deploy and operate buyer Worker and Web apps on managed infrastructure, including review previews, disputed takeover builds and optional post-accept hosting.
- Send transactional emails (for example invites, status updates and receipts).
- Send platform-updates email about significant features and changes, and marketing email about offers and promotions, when you have given consent for each.
- Detect fraud, abuse and security incidents. Review content reports.
- Comply with legal obligations and respond to lawful requests.
6. Secrets, end-user data and buyer responsibilities
Buyers control production secrets for their projects. Secrets are injected into deployment environments at runtime and are not exposed to developers by default. You are responsible for rotating compromised credentials and for ensuring you have the right to provide secrets to Velcio for hosting.
For personal data about end users of your deployed app (for example from third-party platforms users a Worker interacts with, or visitors to a Web preview URL) that appears in delivery archives, runtime behaviour, or logs, the buyer is typically the data controller. Velcio acts as a processor and processes that information only to operate build, deploy, review and hosting features on the buyer's instructions (as configured in the Service). Buyers are responsible for having a lawful basis and any notices required for that end-user data. If you need a data processing agreement, contact support@velcio.dev.
If you opt out of the developer marketplace, we will stop listing your public profile for new discovery. Residual copies may remain in caches or backups for a short period (typically up to 30 days) while those systems refresh.
7. Marketing email
We send platform-updates email (for example significant feature launches) and marketing or promotional email only with your prior opt-in consent for each category, collected during onboarding or in Account settings. Consent is recorded with a timestamp per category. Both are optional. Refusing or withdrawing consent does not affect your ability to use the Service.
You may withdraw platform-updates or marketing consent at any time in Account settings. Where a marketing message includes an unsubscribe link, you may also use that link. We will stop sending marketing email after withdrawal. You may still receive transactional messages needed to operate your account and projects.
We do not sell your email address. We use our email provider to deliver messages you have consented to receive.
8. Retention
We retain personal information only as long as needed for the purposes below:
- Account and profile data: while your account is active. After a verified deletion request, we aim to delete or anonymise account profile fields within 30 days, except where a longer period is required (for example linked payment or dispute records).
- Payment and accounting records: typically up to six years (or longer where a specific legal or regulatory requirement applies) for tax, accounting, or dispute resolution.
- Project audit trails, messages, offers and dispute records (including remediation terms and remove/takeover timestamps): for as long as needed to operate the Service, resolve disputes and meet legal obligations, often aligned with payment retention where records are linked (commonly up to six years for funded projects).
- Build, deploy and operational logs: typically up to 90 days for routine debugging and abuse prevention, then deleted or aggregated, unless a security or legal investigation requires longer retention.
- Date of birth: retained for the life of the account for age-eligibility and compliance, then deleted or anonymised with the account. Not used for marketing.
- Platform-updates and marketing consent records: while the relevant opt-in is active, and for a reasonable period afterward (typically up to two years) to demonstrate lawful consent if needed. Cleared or updated when you withdraw consent in Account settings.
- Content reports: retained as needed to handle the report and for a reasonable period afterward for safety and abuse prevention (typically up to two years).
9. Security
We use administrative, technical and organisational measures designed to protect personal information, including encryption for secrets at rest and access controls on project data. No method of transmission or storage is completely secure. We cannot guarantee absolute security.
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO and affected individuals as required by UK GDPR.
10. Your rights and choices
Under UK GDPR (and similar laws where they apply), you may have the right to:
- access your personal information;
- rectify inaccurate personal information;
- erase personal information in certain circumstances;
- restrict processing in certain circumstances;
- data portability where processing is automated and based on contract or consent;
- object to processing based on legitimate interests, including profiling where relevant;
- withdraw consent where processing is based on consent, without affecting prior lawful processing.
You can update much of your account information in the Service, including marketing email opt-in and other email notification preferences in Account settings. You can also download a copy of your personal data from Account settings (Your data). For other requests (access, rectification, erasure, restriction, portability, objection, or withdrawal of consent), email support@velcio.dev from the address associated with your account so we can verify your identity. Under UK GDPR we will respond without undue delay and within one month of receiving a verified request. Where a request is complex or you make several, we may extend that period by up to two further months and will tell you within the first month if we need to do so. A response may confirm the outcome, explain any lawful refusal, or ask for information we reasonably need to complete the request.
Account deletion. You can schedule account deletion in Account settings (Your data). Deletion is not immediate: after you confirm, there is a 30-day grace period during which you can cancel. When deletion finalises, we anonymise account profile fields and remove sign-in access, usually within the retention window described above, subject to legal or accounting retention for project and payment records. You may also email support@velcio.dev from the address associated with your account if you need help.
If you are in the UK, you may lodge a complaint with the Information Commissioner's Office (ICO). If you are in the EEA, you may also lodge a complaint with your local data protection authority.
11. International transfers
We and our subprocessors may process data in the United Kingdom, European Economic Area, United States and other countries (for example when using US-based authentication, payments, hosting, analytics, or error-monitoring providers). Where a transfer requires a safeguard under UK GDPR, we use appropriate mechanisms such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK addendum, or another lawful transfer tool recognised under UK law.
13. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe we have collected information from someone under 18, contact us and we will take appropriate steps to delete it.
14. Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate.
15. Contact
Privacy questions or requests: support@velcio.dev
Velcio LTD is the data controller for personal information processed through the Service (except where we act as a processor for your app's end-user data under Section 6). Registered address: Office 6995, 58 Peregrine Road, Hainault, Ilford, Essex, IG6 3SZ. Company number: 17327605.