Legal

Privacy Policy

Last updated: May 31, 2026

Your privacy matters to us

This policy explains what personal data Veloryn collects through the ChatCart Pro website and product, why we collect it, how we use it, and your rights under applicable laws including GDPR, LGPD, CCPA/CPRA, POPIA, and APA.

1. Data Controller

The data controller responsible for processing your personal data is:

Company: Veloryn

Website: veloryntech.com

Email: support@veloryntech.com

2. Personal Data We Collect

We collect personal data only when necessary and limit collection to what is required for the stated purpose. The categories of data we may collect include:

  • ·Purchase and billing data: Name, email address, billing address, country, and payment reference. We do not store card numbers; payments are handled by Stripe.
  • ·Contact and support data: Name, email address, and any information you voluntarily provide when contacting our support team.
  • ·Usage and analytics data: Aggregated data about how visitors use our website (pages visited, session duration, device type) collected via Google Analytics and Microsoft Clarity, subject to your consent.
  • ·Technical data: IP address, browser type, operating system, and referring URL collected automatically by our hosting infrastructure for security and diagnostic purposes.
  • ·Cookie data: Identifiers stored in your browser via cookies or similar technologies. See our Cookie Policy for full details.

3. Legal Bases for Processing

We process your personal data only where a lawful basis exists:

  • ·Contract performance: Processing your purchase data to fulfil your order, deliver the plugin, and manage your subscription.
  • ·Legitimate interests: Preventing fraud, securing our systems, responding to support requests, and improving our products, where these interests do not override your rights.
  • ·Consent: Loading analytics cookies (Google Analytics, Microsoft Clarity) only after you give explicit consent. You may withdraw consent at any time.
  • ·Legal obligation: Retaining financial records as required by applicable tax and accounting laws.

Under the LGPD (Brazil), processing is based on the equivalent bases in Art. 7, including consent, contract performance, legitimate interest, and legal obligation. Under the CCPA/CPRA (California), we do not “sell” or “share” personal information as defined by those laws.

4. How We Use Your Data

  • ·Process and fulfil your purchase, issue a license, and send order confirmation emails.
  • ·Provide customer support and respond to enquiries.
  • ·Detect, investigate, and prevent fraudulent or unauthorised activity.
  • ·Comply with legal and regulatory obligations (e.g. tax record retention).
  • ·Analyse website usage to improve our products and services (only with your consent).
  • ·Send transactional emails related to your purchase or support request. We do not send marketing emails without your explicit opt-in.

5. Third-Party Service Providers

We share your data with trusted third-party processors only to the extent necessary:

  • ·Stripe: Handles payment card data under PCI-DSS compliance. We receive only a tokenised reference and basic billing data.
  • ·Vercel: Hosts our website and processes request logs containing IP addresses. Vercel is GDPR-compliant.
  • ·Google Analytics: Analytics data sent to Google LLC (US) under Google's Data Processing Terms. Loaded only with your consent. IP anonymisation is enabled.
  • ·Microsoft Clarity: Session recording and heatmap data sent to Microsoft Corporation (US) under Microsoft's Data Processing Terms. Loaded only with your consent.
  • ·Email delivery: Transactional emails may be delivered via a third-party SMTP provider. Your email address is shared only to deliver messages you triggered.

We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes.

6. International Data Transfers

Some of our service providers (Google, Microsoft, Vercel) are based in the United States. Where data is transferred outside the European Economic Area, the United Kingdom, Brazil, or South Africa, we rely on appropriate safeguards such as EU Standard Contractual Clauses (SCCs) or the providers' participation in equivalent approved frameworks.

7. Data Retention

We retain personal data only for as long as necessary:

  • ·Purchase and billing records: 7 years (tax and accounting obligations).
  • ·Support correspondence: up to 3 years after the issue is resolved.
  • ·Analytics data: as configured in Google Analytics (default 14 months); Clarity retains session data for 13 months.
  • ·Cookie consent records: 1 year from the date consent was given or withdrawn.

8. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

  • ·Access: Request a copy of the personal data we hold about you.
  • ·Rectification: Request correction of inaccurate or incomplete data.
  • ·Erasure: Request deletion of your data where there is no compelling reason for continued processing.
  • ·Restriction: Request that we restrict processing of your data in certain circumstances.
  • ·Data portability: Receive your data in a structured, machine-readable format (GDPR / LGPD).
  • ·Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • ·Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • ·Non-discrimination (CCPA/CPRA): Exercise your privacy rights without receiving discriminatory treatment.
  • ·Lodge a complaint: Lodge a complaint with the supervisory authority in your country (e.g. your national DPA in the EU, the ICO in the UK, or the ANPD in Brazil).

To exercise any of these rights, contact us at support@veloryntech.com. We will respond within 30 days (or as required by applicable law) and may need to verify your identity before processing your request.

9. Cookies

We use cookies and similar tracking technologies on this website. For detailed information, please see our Cookie Policy.

10. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), access controls, and periodic security reviews. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

11. Children's Privacy

Our website and products are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Your continued use of our website after changes are posted constitutes acceptance of the updated policy.

13. Contact

For any questions about this policy, to exercise your rights, or to reach our privacy contact point: