Privacy Policy
This policy explains what personal data Veltor handles, why we use it, and the choices available to you.
Effective September 22, 2026
Data we collect
- Account data: name, email address, linked sign-in providers, organization membership, and account-security settings.
- Customer configuration: benefits, policies, API credentials, team settings, and other information entered in the dashboard.
- Evaluation data: identifiers, network and device signals, benefit history, rules, outcomes, and evidence supplied by a customer when asking Veltor to evaluate a claim.
- Technical data: IP address, browser or client information, request metadata, security events, and diagnostic logs.
- Communications: messages, support requests, recovery submissions, and delivery records for transactional email.
Veltor stores password verifiers rather than plaintext passwords. Authenticator secrets, backup codes, and protected records are encrypted where the service requires them.
How we use data
We use data to operate accounts, evaluate benefit claims, provide API and dashboard features, prevent misuse, secure and troubleshoot the service, send transactional messages, respond to requests, meet legal obligations, and understand service reliability.
Customer-submitted data
When a Veltor customer submits information about its users, that customer decides why the information is processed. Veltor processes it to provide the service under the customer’s instructions. Questions about a customer’s collection or use of that information should first be directed to that customer.
Service providers
We use service providers to host and operate Veltor, including Cloudflare, Supabase, Upstash, Resend, and MaxMind. GitHub, Discord, or Google also process information when you choose their sign-in method. These providers receive only the information needed for their role and operate under their own terms and privacy practices.
When we disclose data
We may disclose data to service providers, at your direction, during a business transaction, to comply with law or valid legal process, or when reasonably necessary to protect Veltor, our customers, users, or the public. We do not sell personal data or use it for third-party behavioral advertising.
Retention
Test data is persistent but bounded. Encrypted original evaluation requests remain for up to 7 days, Test activity and ordinary operational history for up to 30 days, and redacted Test security-administration events for up to 90 days. Active Test configuration remains until it is changed or reset. Live data follows the retention settings and eligibility periods described in the product. Encrypted backups can retain expired copies for up to 7 additional days.
Some account-security, billing, audit, or legal records are outside Test-mode retention and may remain after account deletion when required or reasonably necessary.
Security
We use access controls, encryption in transit, encryption at rest for protected records, restricted credentials, and monitoring intended to protect data. No system can guarantee absolute security.
Your choices
You may update account information, unlink available social sign-in methods, manage sessions and account security, or request access, correction, export, or deletion where applicable. We may need to verify a request before completing it.
International processing
Veltor and its providers may process data in countries other than yours. Where required, we use appropriate safeguards for international transfers.
Children
Veltor is a business service and is not directed to children under 18. We do not knowingly create accounts for children.
Changes to this policy
We may update this policy as Veltor changes. We will post the updated version here, change the effective date, and provide reasonable notice when a change materially affects how we handle personal data.
Contact
Privacy questions and requests can be sent through the Contact page.