V Velos Sync

Data & Security

What we hold, where, and for how long

Velos Sync operates on shop data belonging to the sellers who connect their own shops. That is a responsibility we would rather over-explain than under-explain.

Authorization and tokens

  • We never handle your marketplace password. Connecting a shop happens entirely on the marketplace's own domain via its official OAuth 2.0 authorization flow. We receive only an access token and refresh token.
  • Tokens are encrypted at rest with AES-256 using keys held in a managed secrets store, separate from the application database. They are never written to logs, never sent to a browser, and never shared with any third party.
  • Tokens are used only to make API calls on behalf of the shop that issued them, for the features described on this site.
  • Disconnecting a shop in Velos Sync revokes the token with the marketplace and deletes our stored copy. Revoking access from your marketplace account has the same effect from our side: all syncing for that shop stops.

What we cache, and for how long

We cache the minimum required to render your dashboard quickly and to avoid hammering marketplace APIs. We honour each marketplace's published caching and data-retention rules, and where a marketplace's terms are stricter than the table below, the marketplace's terms govern.

DataWhy we hold itRetention
Listing content (title, description, photos, tags, variations, price, quantity) To show and edit your catalog, and to detect drift between channels Refreshed on change; deleted within 30 days of shop disconnection
Order records (order id, items, options, totals, status, timestamps) To run the order queue and produce your own sales history Retained while your account is active; deleted within 30 days of account closure
Buyer shipping name and address Solely to print labels and packing slips for orders you must ship Purged 90 days after the order is marked shipped or cancelled
Shop profile, sections, shipping profiles To create listings that match your existing shop settings Refreshed on change; deleted on disconnection
API call logs (endpoint, status code, timing — no payload bodies) Debugging, rate-limit compliance, abuse detection 30 days, then deleted

We do not request or store buyer email addresses. We do not store payment card data of any kind — subscription billing is handled by a PCI-compliant payment processor and card details never reach our servers.

Boundaries we hold ourselves to

  • No scraping. All marketplace data is obtained through official public APIs. We do not screen-scrape, crawl storefronts, or reverse-engineer private endpoints.
  • No cross-seller aggregation. Your data is used to operate your account and nothing else. We do not pool it into market datasets, trend reports, competitor dashboards, or any product sold to anyone.
  • No resale of data. We do not sell, rent, license or trade marketplace data or personal data. Ever, to anyone, under any commercial arrangement.
  • No off-platform diversion. Velos Sync does not contact buyers, does not promote external storefronts to them, and does not interfere with any marketplace's checkout, fees or payment flow. Sales stay where they were made.
  • No AI training on your data. Your listings, orders and buyer data are not used to train machine-learning models, ours or anyone else's.

Infrastructure

  • Hosted on US-based cloud infrastructure. All traffic to and from the application is served over TLS 1.2 or higher; HTTP is redirected to HTTPS.
  • Databases are encrypted at rest and are not publicly reachable; access is limited to the application's private network.
  • Administrative access requires multi-factor authentication and is restricted to personnel who need it to operate the service. Access is logged.
  • Encrypted backups are retained for 30 days and are subject to the same deletion commitments as live data.

Rate limits and good citizenship

Every integration runs behind a queue with per-shop throttling and exponential backoff, so Velos Sync stays within each marketplace's published rate limits even during bulk operations. Bulk edits are paced rather than burst. If a marketplace signals that we are going too fast, we slow down rather than retry aggressively.

Compliance

Velos Sync operates in accordance with the API Terms of Use and developer policies of every marketplace it connects to, including Etsy's API Terms of Use and Trademark Policy. Where this page and a marketplace's terms conflict, the marketplace's terms govern and we will change our behaviour to match.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. We will acknowledge within two business days and will not pursue legal action against good-faith researchers who give us reasonable time to fix an issue before disclosing it.