The sections above are the plain-language version. This is the same policy
stated the way the GDPR asks for it.
Who is responsible
For visits to this marketing site, Vertexly s. r. o. is the controller.
For data flowing through a connected shop, the shop is the controller and
Velora is the processor acting on its instructions — see the DPA.
Why we may process it
Performance of a contract (Art. 6(1)(b)) for everything needed to run the
service you subscribed to; consent (Art. 6(1)(a)) for analytics cookies on
this site, which you can refuse and withdraw at any time; and legitimate
interests (Art. 6(1)(f)) for keeping the service secure and preventing abuse.
How long we keep it
Raw visit data for 3 years (36 months) from collection, then deleted.
Account and billing records for as long as tax law requires. You can erase a
shop's data sooner at any time from Settings, and it is removed from the
databases, not merely hidden.
Who else sees it
Our hosting provider inside the EU, and the ad platforms you connect — and
those only to read your own campaign cost. We do not sell data, do not share
it with advertisers, and do not use it to train models. The full list is in
the DPA.
Where it is processed
On servers in the European Union. Where a sub-processor transfers data
outside the EEA, that transfer relies on an adequacy decision or on the
Commission's Standard Contractual Clauses.
Your rights
Access, rectification, erasure, restriction, portability, and objection to
processing based on legitimate interests. Where processing rests on consent,
you may withdraw it without affecting what was lawful beforehand. Write to
info@veloraapp.io and we answer within 30 days.
Complaints
You can complain to a supervisory authority — in Slovakia, the Office for
Personal Data Protection (Úrad na ochranu osobných údajov SR), or the
authority in your own EU country of residence.
Automated decisions
None. Velora scores channels and suggests verdicts, but nothing here makes a
decision with legal or similarly significant effect about a person.
Data from your Google account
How Velora accesses Google user data
Only if you choose to connect Google Ads, and only through Google's own OAuth
consent screen. Velora requests one scope —
https://www.googleapis.com/auth/adwords — and no other. Access
begins when you grant it and ends the moment you revoke it.
What we read: the list of Google Ads accounts your login can reach, so you can
choose which one belongs to this shop; and, for the account you choose, the
campaign id and name, daily cost, clicks, impressions, and the account's
currency. We do not read keywords, ad creatives, audiences, customer match
lists, conversion data, billing details, or anything about the people who saw
your ads. Velora calls no write method on the Google Ads API, so nothing in
your account can be created, edited, paused or spent by us.
How Velora uses Google user data
For one purpose: to show you what your advertising cost next to what your shop
earned. Daily cost is combined with the orders your own shop reports, to
produce cost per lead and return per unit of spend, and to say which channel
is worth more than it costs. That is the entire product.
We do not use this data for advertising or ad targeting of any kind, for
credit or lending decisions, or to develop, improve or train generalised
artificial-intelligence or machine-learning models. It is used to provide the
features described here and for nothing else.
How Velora stores Google user data
The access and refresh tokens Google issues are encrypted with AES-256-GCM
before being written to our database and are decrypted only in memory, at the
moment a request is made to Google. The daily cost figures derived from your
account are stored alongside your other analytics data for
3 years (36 months), then deleted.
Everything is held on servers in the European Union. You can delete all of it
sooner: see Deleting your data below.
How Velora shares Google user data
We do not share it. It is not sold, rented, published, pooled with other
customers' data, or passed to advertisers, data brokers or model-training
providers. It is visible only to you and to the people you invite to your own
Velora account.
The only parties that touch it are our infrastructure providers acting on our
instructions — the EU hosting provider that runs our servers and databases —
bound by written processing terms and unable to use it for their own purposes.
They are listed in the DPA. We would disclose data if the
law compelled us to, and would say so unless legally prohibited. If Velora is
ever acquired, data would transfer with prior notice to you.
How we protect it
Traffic to and from Velora is TLS-encrypted end to end. OAuth tokens are
encrypted at rest with AES-256-GCM under a key held outside the database.
Access to a shop's data requires an authenticated session and a role on that
shop; a request for a shop you have no role on is refused. Ingest from the
WordPress plugin is authenticated with a per-site token stored only as a
SHA-256 digest, so a copy of our database cannot be used to impersonate a
shop.
How to revoke access
From either side, with the same effect: Velora's Settings → Connections, or
your Google Account's
third-party access
page. Revoking stops all future reads immediately and the stored tokens stop
working. To also delete the cost figures already stored, erase the shop's data
from Settings, or write to us.
Limited Use
Velora's use and transfer of information received from Google APIs adheres to
the Google API Services User Data Policy,
including its Limited Use requirements.
The same shape, the same limits
If you connect Meta, Velora asks for ads_read and nothing else.
We read the ad accounts your login can reach and, for the one you pick,
campaign id and name, daily spend, clicks, impressions and currency. We do
not read audiences, creatives, page or profile information, messages, or
anything about the people who saw your ads. We never post anything.
Meta issues a long-lived token rather than a refresh token; it is encrypted
the same way, expires on Meta's own schedule, and can be revoked from
Velora's Settings → Connections or from your Facebook
business integrations
settings.
Requests from public authorities
What happens if the police, a court or an agency asks for your data
Every request is reviewed for legal validity before anything is disclosed:
whether the authority has jurisdiction over Vertexly s. r. o., whether the
request takes the form the law requires, and whether it is specific rather
than open-ended. A request that fails that review is challenged or refused,
and we will use the legal remedies available to contest one we consider
unlawful, overbroad, or in conflict with EU law.
Where a request is valid, we disclose the minimum data that satisfies it and
nothing more — we do not hand over a database because one record was asked
for. Every request, the reasoning applied, who was involved and what was
disclosed is recorded in writing and retained. Unless we are legally
prohibited, we tell the affected customer before disclosing data, and where
prohibited, as soon as that prohibition lapses.
To date we have received no such request, from any authority, in any country.
Deleting your data
How to erase everything
In Velora, open Settings → Danger zone and erase the shop's
data. This deletes the shop's visits, orders, customers, team memberships,
settings and stored ad-platform tokens from both databases — it removes
rows, it does not hide them. There is no undo and no backup copy kept for
this purpose.
If you cannot sign in, write to
info@veloraapp.io from the
address on the account and we will erase it for you. We answer within 30
days, usually far sooner.
Disconnecting an ad platform revokes and deletes the stored tokens on its
own, without touching the rest of your analytics.