This Privacy Policy explains how Velos Metrik LLC ("Velos Metrik", "we", "us"), a limited liability company organized under the laws of the State of Colorado, United States, collects, uses, shares and protects personal data in connection with the Velos Sync service and the website at velosmetrikllc.us (together, the "Service").
We are the data controller for personal data described in this policy. You can reach us at [email protected] or by post at Velos Metrik LLC, 2008 Finch Ct, Colorado Springs, CO 80909, United States.
Name, email address, password (stored only as a salted hash), account settings, and support correspondence. We use this to create and secure your account, to provide the Service, and to answer you when you contact us. Legal basis: performance of a contract with you.
Billing name, billing address, plan, invoices and payment status. Card numbers are collected and processed directly by our PCI-compliant payment processor and are never transmitted to or stored on our servers. Legal basis: performance of a contract; compliance with tax and accounting obligations.
When you connect a shop, the marketplace issues us an OAuth access token and refresh token after you approve the connection on the marketplace's own site. We store these encrypted and use them solely to call that marketplace's API on your behalf. We never receive, request or store your marketplace password. Legal basis: performance of a contract with you.
Listings and their content, inventory levels, shop profile, sections, shipping profiles, orders, order line items, order status and totals. We use this to display, edit and synchronize your catalog and to run your order queue. Legal basis: performance of a contract with you.
For each order in a connected shop we receive the buyer's shipping name, shipping address, the items and options ordered, any personalization note, order totals and order status. We use this only so the seller can pick, pack, label and ship the order, and so that shipment status can be written back to the marketplace.
We do not request or store buyer email addresses. We do not send marketing to buyers, do not build buyer profiles, and do not use buyer data for any purpose other than fulfilling the specific order it came from. In this processing we act as a service provider / processor for the seller, who determines the purposes of the processing.
IP address, browser type and version, pages viewed, timestamps, and application error logs. We use this to keep the Service secure and available and to diagnose faults. Legal basis: our legitimate interest in operating a secure and reliable service.
The marketing website you are reading uses no analytics cookies, no advertising cookies and no third-party trackers. The application at app.velosmetrikllc.us sets a single strictly-necessary cookie to keep you signed in and a CSRF-protection token. These are required for the Service to function and cannot be disabled while you are logged in.
We share personal data only with the following categories of recipient, and only to the extent needed to run the Service:
| Recipient | Purpose | Data |
|---|---|---|
| Cloud hosting provider (United States) | Running the application and databases | All Service data, encrypted at rest and in transit |
| Payment processor | Subscription billing | Billing name, email, payment status. Card data goes directly to them, never through us |
| Transactional email provider | Account, security and support emails to sellers | Seller name and email address |
| Error monitoring provider | Diagnosing faults | Technical logs with personal data redacted |
| The marketplaces you connect | Reading and writing your own shop data at your instruction | Only what the requested operation requires |
Each provider is bound by a written agreement limiting them to processing data on our instructions. We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights and safety of our users — and if we are ever compelled to disclose your data by legal process, we will notify you unless legally prohibited from doing so. If the business is sold or merged, data may transfer to the acquirer under the terms of this policy, and we will notify you first.
| Data | Retention |
|---|---|
| Account and settings | While the account is active; deleted within 30 days of closure |
| OAuth tokens | Revoked and deleted immediately on disconnection or account closure |
| Listing and shop data | Deleted within 30 days of the shop being disconnected |
| Order records | Deleted within 30 days of account closure |
| Buyer shipping name and address | Purged 90 days after the order is shipped or cancelled |
| Technical and API logs | 30 days |
| Invoices and tax records | Up to 7 years, where required by US tax law |
| Encrypted backups | 30 days, then overwritten |
Data is transmitted over TLS 1.2 or higher and encrypted at rest. OAuth tokens are encrypted with AES-256 using keys held in a managed secrets store separate from the application database. Administrative access requires multi-factor authentication, is limited to personnel who need it, and is logged. Full detail is on our Data & Security page.
If a breach affects your personal data we will notify affected sellers without undue delay, and regulators where required by law.
The Service is hosted in the United States. If you access it from outside the United States, your data will be transferred to and processed in the United States. Where we transfer personal data of individuals in the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) together with supplementary technical measures including encryption in transit and at rest.
Subject to your location and applicable law, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Sellers can exercise most of these directly in the dashboard — export your data as CSV, edit your account details, disconnect a shop, or close your account.
For anything else, email [email protected]. We will acknowledge within 5 days and respond within 30 days. We do not charge for these requests and we will not discriminate against you for making one.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months.
EEA and UK residents: you have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
Buyers: if you are a buyer and wish to exercise rights over data held in a seller's Velos Sync account, please contact that seller, who is the controller of that data. If you contact us directly we will forward your request to the relevant seller and assist them in responding.
The Service is intended for business use by adults. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it.
If we make a material change we will update the "Last updated" date above and notify account holders by email at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
Velos Metrik LLC
2008 Finch Ct, Colorado Springs, CO 80909, United States
[email protected]