Legal
The plain-language version first: we hold your account and billing details, our hosted nodes handle receipt metadata on your behalf, and settlements live on a public blockchain that nobody — including us — can edit. The details follow.
Effective April 21, 2026
velapay, Inc. ("velapay", "we") is the controller of the personal data you give us when you use this website, open an account, or subscribe to a plan. That is the scope of this policy.
The protocol itself is a different matter, and it is worth being precise about. Payment channels are peer-to-peer: a payer signs receipts and sends them directly to a receiver. velapay does not sit in the middle of that traffic and does not see it. Where you run receipts through our hosted node infrastructure, we process receipt metadata on your behalf as a processor, under your instructions and your data processing agreement — not as a controller making our own decisions about it.
We collect three categories, and we try to keep each one as thin as the job allows.
Read this one
When a RAV is redeemed, the settlement is written to a public blockchain. That record — addresses, amounts, timestamps — is replicated across a network no single party operates. Neither velapay nor anyone else can delete or amend it, and no privacy request changes that. If this is a problem for your use case, it is a problem before you settle, not after.
Off-chain receipts are different. They live in your node's store and are retained per your configuration; the default is 90 days after the corresponding RAV is redeemed, after which they are purged.
Under the GDPR, each processing purpose stands on one of four legs: contract performance for providing accounts, hosted nodes, and support; legitimate interests for keeping the platform defended, abuse contained, and aggregate usage understood; legal obligation for tax, accounting, and sanctions screening; and consent for anything optional, like product announcements — which you can withdraw at any time.
Subprocessors that help us run the service — cloud hosting, payment processing, email, and support tooling — each bound by data processing terms at least as protective as this policy. We publish the current list and give account owners 30 days' notice before adding a new one, so you can object before your data moves. We may also disclose data where the law genuinely compels it.
Selling personal data, or feeding it to brokers and ad networks, is something we simply do not do. There is no version of our business model where your counterparty graph is the product.
velapay operates from the United States, and that is where processing happens. Transfers out of the EEA, UK, or Switzerland ride on the EU’s Standard Contractual Clauses (with the UK and Swiss counterparts), backed by encryption on the wire and in storage.
Account data lives as long as your account does, plus a short winding-down window. Node telemetry follows your configured retention (90 days after redemption by default). Billing and settlement records are financial records, and the law requires us to keep some of them for several years; where that applies, we restrict the data to that single purpose first and purge it the moment the retention period ends.
Traffic is encrypted moving and sitting still; API keys are narrowly scoped; audited contracts, and a thawing period that gives disputes somewhere to go before money moves. The full picture — escrow design, key management, and audit posture — is on the security page.
Jurisdiction decides the menu, but it can include: inspecting the personal data we hold, correcting it, taking a copy, fencing off or erasing it, and objecting to particular uses. Write to privacy@velapay.xyz and an answer comes back within 30 days.
One honest caveat: data that has settled on-chain cannot be erased by anyone, so a deletion request cannot reach it. What we can do — and will, on request — is unlink your account metadata from those on-chain addresses in our systems, so the public record no longer connects back to you through us.
We set a session cookie to keep you signed in to the dashboard. For usage measurement we run first-party, cookieless analytics: aggregate page counts, no cross-site tracking, no fingerprinting, nothing to consent-banner you about. There are no third-party advertising or tracking cookies on this site.
When we change this policy in any way that matters, we will email account owners and note the change in the changelog before it takes effect. The effective date at the top always tells you which version you are reading.
Questions, requests, or complaints: privacy@velapay.xyz. velapay, Inc., a Delaware corporation. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.