Privacy Policy
Last updated August 2026
This policy explains what information Velora collects, how we protect it, and who is responsible for what. We built Velora (by Stack85) to be a tool small businesses can trust with real customer information, so we try to keep this in plain language rather than dense legal text.
What we collect
When you sign up and use Velora, we store:
- Your account information: name, email address, and business details you provide.
- The forms you build, including the questions and options you write.
- The leads your forms capture: whatever a visitor types in, plus their explicit consent record and the time they submitted it.
- Basic usage information, like when you log in and which features you use, so we can keep the product working well.
How we protect your data
Your account and lead data are stored with Supabase, using encryption in transit and at rest, and access controls that keep every account's data separated from every other account's data. Sensitive fields, like the password for your own email server if you connect one, are encrypted before they're ever saved. Only you can see your own leads and forms. We don't sell your data to anyone.
Connecting your email account
You can connect a Google Workspace, Microsoft 365, or other SMTP email account so Velorasends replies to your leads from your own address. When you connect a Google or Microsoft account, Velora stores the encrypted authorization tokens needed to send on your behalf, plus a limited record of the email conversations it handles.
What Velora asks for from Google: when you connect a Google account, Velora requests only the Gmail send permission (gmail.send) plus your email address (openid and userinfo.email), so it knows which mailbox you connected. Velora cannot read, list, search, or scan your Gmail mailbox with these permissions. If you sign in with Google instead of a password, Velora receives only your name, email address, and profile picture from Google.
What Velora stores from that connection: the connected email address, the encrypted authorization tokens needed to send on your behalf, and a record of the messages Velora sent. Connecting is optional, Manual SMTP is send-only, and you can disconnect at any time.
A small number of accounts connected before we moved to send only access, and granted a read permission at that time. For those older connections only, Velora reads the specific email threads that Velora itself started, so a lead's reply appears in your inbox. Even then, Velora never lists, searches, or scans the mailbox, and never reads messages outside a conversation it started.
Disconnecting an email account removes its connection record and the encrypted credentials Velora stored for it, and deletes the reply text Velora retrieved from that account's mailbox. The replies you sent through it remain only as your own records of what was sent.
Who we share, transfer, or disclose Google user data with
We do not sell Google user data, and we do not share it for advertising. The only parties that ever receive it are the infrastructure providers below, acting on our instructions to run the service, and only to the extent needed for the purpose listed:
- Google LLC, through the Gmail API, when Velora sends a message you approved from your connected address.
- Supabase Inc., our database and authentication provider, which stores your connected email address, the encrypted Google authorization tokens, and, for the older read-enabled connections described above, the reply text retrieved from those threads.
- Amazon Web Services, Inc., which hosts the servers that run Velora and process this data in memory while handling your requests.
- Cloudflare, Inc., which proxies and secures traffic to Velora, so the data passes through it in transit.
Beyond that, Google user data is disclosed only if we are legally required to do so by a valid legal process, or if Velora is ever acquired or merged, in which case the acquiring party is bound by this same policy and you would be notified first.
Specifically, Google user data is neverpassed to our billing provider (PayPal), our alert email provider (Resend), any Meta Pixel, Google Analytics, or Google Ads tag, or any advertising, data broker, or analytics company. It is never used to develop, train, or improve generalised artificial intelligence or machine learning models, ours or anyone else's, and no human at Stack85 reads it except where you specifically ask us to for support, or where we must to resolve a security issue or comply with the law.
Google API Services User Data Policy
Velora's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who is responsible for what
Stack85 is responsible for protecting the data held on Velora's systems, meaning the account information and lead data stored in our database. We take that responsibility seriously and follow standard security practices to keep it safe.
However, once a lead is captured through your form, what you do with that person's information is your responsibility, not ours. Veloragives you the tool to collect leads and reply to them, but we don't control, review, or take responsibility for how an individual account contacts, stores outside our platform, or otherwise uses the leads they collect. Each account is responsible for following the laws that apply to their own business and location, including rules about consent and unwanted contact.
Who we share, transfer, or disclose your data with
We do not sell your data or your leads' data, and we never share it with advertisers or data brokers. We rely on a small number of providers to run Velora, each of which receives only what it needs to do its job:
- Supabase Inc., database and authentication. Stores your account, forms, leads, templates, and connected email credentials in encrypted form.
- Amazon Web Services, Inc., hosting. Runs the servers that process your requests.
- Cloudflare, Inc., network and security. Traffic to Velora passes through it.
- Resend, alert delivery. Receives your own contact address and the new lead alerts sent to you, not your lead database.
- PayPal, billing. Handles your subscription and card details directly. We never see or store your card number, and PayPal never receives your leads or email data.
- Google LLC and Microsoft Corporation, only if you connect an email account, and only to send the replies you approve. See the Google section above for exactly what is shared.
We also disclose data where we are legally required to by valid legal process, and, if Velorais ever acquired or merged, to the acquiring party under this same policy. If you add a Meta Pixel, Google Analytics, or Google Ads ID in your settings, that tool works the same way any website advertising pixel does, and that is your own configuration. We don't add any tracking on your behalf that you haven't set up yourself.
Your rights
You can view, edit, or delete your account and its data at any time from your dashboard, or by emailing us. Deleting your account removes your forms, leads, and templates from our systems.
Cookies
We use basic session cookies to keep you logged in. We don't use tracking cookies of our own for advertising purposes.
Changes to this policy
If we make a meaningful change to this policy, we'll update the date at the top of this page. We encourage you to check back occasionally.
Questions
If you have any questions about this policy or how your data is handled, reach out to us at [email protected].