Privacy Policy
v3.2
How we collect, use, and protect your data across the VELO platform.
Effective:
January 15, 2026
Last updated:
February 10, 2026

On this page
01
Overview
VELO Protocol, Inc. ("VELO," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payment infrastructure platform, APIs, dashboards, websites, and related services (collectively, the "Services").
By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Services immediately.
Note: This policy applies to data we process as a data controller. When we process data on behalf of our customers (merchants, platforms), our Data Processing Agreement (DPA) governs that relationship.
02
Information We Collect
We collect information in three categories:
Information you provide directly. Account registration details (name, email, company), payment instrument details processed through our tokenization infrastructure, KYC/KYB documentation submitted during onboarding, and communications you send to us.
Information collected automatically. Device and browser information, IP addresses, usage patterns, API call logs, session data, and performance telemetry. We use this to maintain service reliability and detect anomalies.
Information from third parties. Identity verification data from KYC/KYB providers, fraud risk scores from our detection partners, business registration data from public registries, and data from analytics services that help us improve the platform.
03
How We Use Your Information
We use collected information to:
Provide, maintain, and improve the Services, including payment processing, settlement, and reconciliation
Verify your identity and comply with KYC/AML/CTF regulations in applicable jurisdictions
Detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities
Send transactional communications (payment confirmations, security alerts, service updates)
Respond to support requests and troubleshoot technical issues
Analyze usage patterns to improve API performance, developer experience, and product reliability
Comply with legal obligations, regulatory requirements, and law enforcement requestsEnforce our Terms of Service and protect the rights and safety of our users and the public
We do not sell your personal information. We do not use your payment data for advertising purposes.
04
How We Share Your Information
We share information only in the following circumstances:
Service providers. We work with vetted third-party providers for infrastructure hosting (AWS, GCP), KYC/KYB verification, fraud detection, analytics, and customer support. All providers are contractually bound to process data only as instructed.
Financial partners. Banks, card networks, and payment processors that facilitate transactions. Data shared is limited to what is strictly necessary for payment execution.
Regulatory and legal. When required by law, regulation, or legal process. When necessary to protect against fraud, security threats, or enforce our rights.
Business transfers. In connection with a merger, acquisition, or sale of assets, with prior notice to affected users where practicable.
With your consent. When you explicitly authorize us to share your information with a designated third party.
05
Data Security
Depending on your jurisdiction, you may have the following rights regarding your personal data:
AES-256 encryption at rest and TLS 1.3 for data in transit
Multi-party computation (MPC) for cryptographic key management
24/7 security monitoring with automated anomaly detection
Regular penetration testing by independent third-party firms
Role-based access control with mandatory multi-factor authentication
Immutable audit logs for all data access and modification events
Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly notifying affected users and regulators of any breach in accordance with applicable law.
06
Your Rights
We implement industry-leading security measures to protect your data, including:

To exercise any of these rights, email privacy@veloprotocol.com. We will respond within 30 days. For EU/EEA residents, you also have the right to lodge a complaint with your local data protection authority.
07
International Data Transfers
VELO operates globally. Your data may be transferred to and processed in countries outside your jurisdiction, including the United States and Singapore. When we transfer data internationally, we rely on:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions where available
Binding Corporate Rules for intra-group transfers
Your explicit consent where required
All transfers are subject to appropriate safeguards to ensure your data receives a level of protection equivalent to that provided under your home jurisdiction's laws.
08
Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@veloprotocol.com.
09
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account), post a notice on our website, and update the "Last Updated" date above. Your continued use of the Services after notification constitutes acceptance of the updated policy. We encourage you to review this page periodically.










