Privacy Policy
Last updated: September 1, 2026
1. Who this applies to
This Policy describes how Veyit collects and uses personal data when a Merchant operates a Store on the platform, and when a Customer interacts with a Merchant's Telegram bot.
2. What we collect
| From | Data | Why |
|---|---|---|
| Merchant | Name, email, organization details, team member roles | Account creation and access control, via our identity provider |
| Merchant | Telegram bot token, connected payment method details | Operating the Store's bot and matching incoming payments; tokens are stored encrypted and never displayed back in full |
| Customer | Telegram user ID, display name, language preference | Identifying who placed an Order and replying in their language |
| Customer | Order, product, and payment-confirmation records | Fulfilling and recording the transaction |
| Anyone | Standard request logs (IP address, timestamps, error data) | Security, abuse prevention, and debugging |
We do not collect payment card numbers. Payment verification is done by matching a provider transfer (for example, an exchange or on-chain transfer) against an Order, not by processing card details directly.
3. How data is isolated
Each Merchant's data is scoped to that Merchant at the database level — a Merchant cannot read or write another Merchant's Stores, Orders, or Customers, and this is enforced independently of the application code that serves requests.
4. Who we share data with
We use a small number of infrastructure and identity providers to operate the Service:
- a database and storage provider, to host Store and Order data;
- an identity provider, to authenticate Merchant accounts;
- the Telegram Bot API, to deliver and receive messages on behalf of a Merchant's bot;
- payment-network APIs (for example, exchange transfer-history endpoints), to verify that a declared payment actually occurred.
We do not sell personal data, and we do not share it with advertisers.
5. Retention
We retain Order, payment, and audit records for as long as the associated Store remains active and for a reasonable period afterward to satisfy accounting, dispute, and legal obligations. A Merchant closing a Store does not immediately erase historical transaction records that a Customer, tax authority, or dispute process may still need.
6. Your rights
Depending on where you are located, you may have the right to request access to, correction of, or deletion of your personal data. To make a request, contact us at the address below. We will respond within a reasonable time and may need to verify your identity first.
7. Digital goods and stock files
Digital stock content a Merchant uploads for delivery to Customers is stored privately and is never exposed in logs, previews, or administrative interfaces in plaintext. It is decrypted only at the moment of delivery to the Customer who purchased it.
8. Security
We use encryption in transit and at rest for sensitive fields, tenant isolation enforced at the database layer, and audit logging of sensitive actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children
The Service is not directed at children, and we do not knowingly collect personal data from anyone below the age of consent applicable in their jurisdiction.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
11. Contact
Questions about this Policy, or requests regarding your data, can be sent to support@veyit.com.