Privacy Policy

v3.2

How we collect, use, and protect your data across the VELO platform.

Effective:

January 15, 2026

Last updated:

February 10, 2026

Image

01

Overview

VELO Protocol, Inc. ("VELO," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payment infrastructure platform, APIs, dashboards, websites, and related services (collectively, the "Services").


By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Services immediately.


Note: This policy applies to data we process as a data controller. When we process data on behalf of our customers (merchants, platforms), our Data Processing Agreement (DPA) governs that relationship.

02

Information We Collect

We collect information in three categories:


Information you provide directly. Account registration details (name, email, company), payment instrument details processed through our tokenization infrastructure, KYC/KYB documentation submitted during onboarding, and communications you send to us.


Information collected automatically. Device and browser information, IP addresses, usage patterns, API call logs, session data, and performance telemetry. We use this to maintain service reliability and detect anomalies.


Information from third parties. Identity verification data from KYC/KYB providers, fraud risk scores from our detection partners, business registration data from public registries, and data from analytics services that help us improve the platform.


Data Type

Account data

Transaction data

KYC/KYB documents

Usage analytics

API logs

Purpose

Service delivery

Payment processing, compliance

Identity verification

Product improvement

Debugging, security

Retention

Duration of account + 5 years

7 years (regulatory)

5 years post-verification

2 years

90 days

Data Type

Account data

Transaction data

KYC/KYB documents

Usage analytics

API logs

Purpose

Service delivery

Payment processing, compliance

Identity verification

Product improvement

Debugging, security

Retention

Duration of account + 5 years

7 years (regulatory)

5 years post-verification

2 years

90 days

03

How We Use Your Information

We use collected information to:


  • Provide, maintain, and improve the Services, including payment processing, settlement, and reconciliation

  • Verify your identity and comply with KYC/AML/CTF regulations in applicable jurisdictions

  • Detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities

  • Send transactional communications (payment confirmations, security alerts, service updates)

  • Respond to support requests and troubleshoot technical issues

  • Analyze usage patterns to improve API performance, developer experience, and product reliability

  • Comply with legal obligations, regulatory requirements, and law enforcement requestsEnforce our Terms of Service and protect the rights and safety of our users and the public


We do not sell your personal information. We do not use your payment data for advertising purposes.

04

How We Share Your Information

We share information only in the following circumstances:


Service providers. We work with vetted third-party providers for infrastructure hosting (AWS, GCP), KYC/KYB verification, fraud detection, analytics, and customer support. All providers are contractually bound to process data only as instructed.


Financial partners. Banks, card networks, and payment processors that facilitate transactions. Data shared is limited to what is strictly necessary for payment execution.


Regulatory and legal. When required by law, regulation, or legal process. When necessary to protect against fraud, security threats, or enforce our rights.


Business transfers. In connection with a merger, acquisition, or sale of assets, with prior notice to affected users where practicable.


With your consent. When you explicitly authorize us to share your information with a designated third party.

05

Data Security

Depending on your jurisdiction, you may have the following rights regarding your personal data:


  • AES-256 encryption at rest and TLS 1.3 for data in transit

  • Multi-party computation (MPC) for cryptographic key management

  • 24/7 security monitoring with automated anomaly detection

  • Regular penetration testing by independent third-party firms

  • Role-based access control with mandatory multi-factor authentication

  • Immutable audit logs for all data access and modification events


Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly notifying affected users and regulators of any breach in accordance with applicable law.

06

Your Rights

We implement industry-leading security measures to protect your data, including:



To exercise any of these rights, email privacy@veloprotocol.com. We will respond within 30 days. For EU/EEA residents, you also have the right to lodge a complaint with your local data protection authority.

07

International Data Transfers

VELO operates globally. Your data may be transferred to and processed in countries outside your jurisdiction, including the United States and Singapore. When we transfer data internationally, we rely on:


  • Standard Contractual Clauses (SCCs) approved by the European Commission

  • Adequacy decisions where available

  • Binding Corporate Rules for intra-group transfers

  • Your explicit consent where required


All transfers are subject to appropriate safeguards to ensure your data receives a level of protection equivalent to that provided under your home jurisdiction's laws.

08

Children's Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@veloprotocol.com.

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account), post a notice on our website, and update the "Last Updated" date above. Your continued use of the Services after notification constitutes acceptance of the updated policy. We encourage you to review this page periodically.

The payment backbone behind

thousands of businesses.

0
1
2
3
4
,
0
1
2
0
0
+

Volume Processed

$
0
1
2
.
0
1
2
3
4
5
6
7
8
B

Avg. Finality

0
1
0
1
2
3
4
0
+

Uptime SLA

0
1
2
3
4
5
6
7
8
9
0
1
2
3
4
5
6
7
8
9
.
0
1
2
3
4
5
6
7
8
9
0
1
2
3
4
5
6
7
8
9

%

Cta Image
Cta Image
Cta Image
Cta Image
Logo Image
Cta Image
Cta Image
Cta Image
Cta Image

The payment backbone behind

thousands of businesses.

0
1
2
3
4
,
0
1
2
0
0
+

Volume Processed

$
0
1
2
.
0
1
2
3
4
5
6
7
8
B

Avg. Finality

0
1
0
1
2
3
4
0
+

Uptime SLA

0
1
2
3
4
5
6
7
8
9
0
1
2
3
4
5
6
7
8
9
.
0
1
2
3
4
5
6
7
8
9
0
1
2
3
4
5
6
7
8
9

%

The payment backbone behind

thousands of businesses.

0
1
2
3
4
,
0
1
2
0
0
+

Volume Processed

$
0
1
2
.
0
1
2
3
4
5
6
7
8
B

Avg. Finality

0
1
0
1
2
3
4
0
+

Uptime SLA

0
1
2
3
4
5
6
7
8
9
0
1
2
3
4
5
6
7
8
9
.
0
1
2
3
4
5
6
7
8
9
0
1
2
3
4
5
6
7
8
9

%

Create a free website with Framer, the website builder loved by startups, designers and agencies.