Privacy Policy
What we collect, why we collect it, and the control you have over your information.
Last updated 27 September 2026
1. Overview
This policy explains how Velo handles personal information when you use our website and services. We collect only what we need to run your account and deliver your orders, and we never sell your data.
2. Information we collect
You give us
- Account details — your username, email address, and password (stored only as a secure one-way hash).
- Order details — the public links or usernames and quantities you submit for delivery.
- Payment details you enter with our payment partners, such as the phone number used for an M-Pesa prompt.
- Anything you send us in support messages.
Collected automatically
- Basic technical data — IP address, browser type, and timestamps — used for security, fraud prevention, and rate limiting.
- A single essential session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
3. Payment information
Payments are processed by third-party providers (for example IntaSend for M-Pesa and Cryptomus for cryptocurrency). Velo does not see or store your full card numbers, M-Pesa PIN, or wallet keys — those are handled directly by the payment provider under their own privacy terms. We receive only a confirmation and a reference needed to credit your balance.
4. How we use your information
- To create and secure your account and process sign-in;
- To place, deliver, track, and support your orders;
- To credit payments to your balance and keep an accurate ledger;
- To detect and prevent fraud, abuse, and security threats;
- To comply with legal obligations and enforce our Terms.
5. Sharing
We share information only where necessary: with our upstream delivery network (the target link/username required to fulfil an order), with payment providers (to process deposits), and with authorities where the law requires it. We do not sell or rent your personal information to anyone.
6. Retention
We keep account and transaction records for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, and fraud-prevention requirements. You can ask us to delete your account; we will remove or anonymise your data except where we are required to retain it.
7. Security
Passwords are hashed, sessions are protected with secure, HTTP-only cookies, and sensitive actions are rate-limited. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information, and we offer two-factor authentication for your account.
8. Your rights
You may access, correct, or request deletion of your personal information, and object to certain processing. To exercise any of these rights, contact us at [email protected].
9. Children
Velo is not directed to anyone under 18, and we do not knowingly collect information from children.
10. Changes
We may update this policy; the “last updated” date above reflects the latest version. Significant changes will be made clear on this page.
11. Contact
For any privacy question or request, email [email protected] or use our contact page.